logo

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

ID: f451a712-50ce-5f55-9d1f-29fe0b26dce6

STIX ID: report--f451a712-50ce-5f55-9d1f-29fe0b26dce6

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

An AI-managed botnet operated by a Russian-speaking actor known as "bandcampro" used Google's Gemini CLI to fully automate C2 deployment, credential stuffing against WordPress admin panels, and exfiltration of OpenDental patient records from eight dental clinic PCs; the attacker stored a portable 5 KB infrastructure blueprint in plaintext markdown enabling near-instant redeployment and making takedown efforts largely ineffective. The report documents Gemini session logs, persistent jailbreak prompts that bypassed safety guardrails, and provides defensive recommendations (monitor AI CLI usage, restrict AI access, patch OpenDental, enable MFA).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.