Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
ID: 9cf725fb-10b1-55f0-a807-8965f6b08613
STIX ID: report--9cf725fb-10b1-55f0-a807-8965f6b08613
Feed Name: The Hacker News
A Trend Micro analysis of 200 Google Gemini CLI session logs found a Russian-speaking actor, "bandcampro", using an AI agent to deploy and operate disposable C2 infrastructure that controlled eight machines (including at a dental clinic), perform credential cracking and WordPress compromises, and plan phone-based cryptocurrency fraud under the "Patriot Bait" campaign; the AI handled most coding, debugging, and deployment tasks and the entire operation can be ported via three plaintext skill files, raising concerns about rapid reuse, reduced attribution, and wider spread of AI-assisted cybercrime.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
