logo

Google Gemini CLI abused as a hacking agent, malware botnet operator

ID: 2a5cf773-c59a-5445-92ad-0e7f2bf7f882

STIX ID: report--2a5cf773-c59a-5445-92ad-0e7f2bf7f882

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Bill Toulas

...
...

A Russian-speaking actor dubbed "bandcampro" used Google’s open-source Gemini CLI as an AI-powered hacking agent to deploy and manage a small botnet that controlled eight systems at a dental clinic and accessed an OpenDental database. Trend Micro analysis shows the AI processed C2 migration guides, prepared server and payload bundles, launched C2 infrastructure, and assisted with troubleshooting and operational tasks; the malware itself was technically simple (in-memory Python HTTP server, PowerShell agents, persistence via scheduled tasks/WMI/registry), but the AI automation significantly sped up setup and migration. The report highlights the novel abuse of an AI agent for hands-on offensive operations, password guessing, and credential handling, with documented logs of over 200 sessions and multiple automated actions by Gemini.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.