Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes
ID: b7fb9c69-4876-5939-8ebe-1a533edafc1f
STIX ID: report--b7fb9c69-4876-5939-8ebe-1a533edafc1f
Feed Name: GBHackers
TrendAI analyzed March–April 2026 Gemini CLI session logs from a Russian-speaking actor dubbed “bandcampro” and found the operator used an AI coding agent to rebuild and migrate a lightweight HTTPS-based C2 for a small botnet (eight systems at a dental clinic, including OpenDental access). The AI performed architecture, code generation, deployment, troubleshooting (fixing 502 errors and Cloudflare issues), and operational recommendations, enabling the actor to restore control within minutes; the operation used PowerShell beacons, WMI/scheduled task/registry persistence, credential/WordPress attacks, and data-exfiltration/fraud planning, highlighting automation-driven resilience and the need for behavioral detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
