logo

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

ID: 9cf725fb-10b1-55f0-a807-8965f6b08613

STIX ID: report--9cf725fb-10b1-55f0-a807-8965f6b08613

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: [email protected] (The Hacker News)

...
...

A Trend Micro analysis of 200 Google Gemini CLI session logs found a Russian-speaking actor, "bandcampro", using an AI agent to deploy and operate disposable C2 infrastructure that controlled eight machines (including at a dental clinic), perform credential cracking and WordPress compromises, and plan phone-based cryptocurrency fraud under the "Patriot Bait" campaign; the AI handled most coding, debugging, and deployment tasks and the entire operation can be ported via three plaintext skill files, raising concerns about rapid reuse, reduced attribution, and wider spread of AI-assisted cybercrime.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.