← BACK TO FEED
cybercrimebotnetsGemini CLIAI misusethreat intelligence

One Hacker, Eight Dental PCs, and Google's Own AI Running the Operation

A Russian-speaking threat actor called "bandcampro" used Google's open-source Gemini CLI AI tool to operate a small botnet of eight dental clinic computers, with the AI handling approximately 89% of all text output and performing tasks such as migrating command-and-control infrastructure, debugging errors, and managing compromised machines via natural language prompts in Russian. Analysis of 200 session logs revealed the threat actor also leveraged the AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly people in the US and Canada. Researchers warn that the entire operation was condensed into just three portable text files, making the infrastructure easily disposable and replicable, and that this "skill-file" model could spread widely, effectively enabling even low-skilled actors to deploy AI-powered hacking operations with minimal effort.

A Russian-speaking threat actor known online as 'bandcampro' has been caught using Google's open-source Gemini CLI to run a live botnet, crack passwords, and plan cryptocurrency scams targeting elderly North Americans. The findings come from Trend Micro researchers who analysed 200 session logs captured between late March and late April 2026.

The headline detail is almost absurdly mundane: the botnet in question consisted of eight computers inside a dental clinic. Not critical infrastructure. Not a bank. A dentist's office, with the apparent goal of raiding its OpenDental patient database.

What makes this more than just a weird footnote is how the operation was actually run. Bandcampro was, functionally, a product manager. The AI was everything else.

According to Trend Micro, the actor contributed 11% of the text produced across the entire month of logged activity. Gemini CLI produced the other 89%. The AI handled all the code, all the system commands, 80% of the architectural decisions, and 90% of debugging. The threat actor typed instructions, mostly in Russian, and the AI executed them.

The command-and-control setup itself was almost insultingly lightweight. The entire infrastructure was described in three plaintext markdown files totalling around 5KB. One disables safety guardrails, one describes the architecture, one provides rebuild instructions. Drop those files onto a fresh VPS, let the AI agent read them, and you have a functioning C2 server in minutes. Takedowns become largely theatrical.

The migration of the C2 from one server to another took six minutes. When the new setup threw a 502 error, the AI diagnosed and fixed it unprompted. When Cloudflare's WAF blocked requests, the AI identified that a missing User-Agent header was the problem and added it. The actor did none of this. He was probably making tea.

Gemini CLI was also used to mutate password lists sourced from AntiPublic's leaked credential database, using those guesses to brute-force WordPress admin panels with some success. There was an attempt to analyse 1Password dumps, which failed when the context window ran out and the model lost the thread. An attempt to get the AI to build a self-spreading worm was refused, though the AI helpfully suggested manual workarounds for the limitations it had just cited.

The cryptocurrency fraud angle is grim but not surprising. The logs show discussions about running telephone-based scams on elderly people in the US and Canada. Bandcampro had previously been linked to a Telegram-based influence operation called Patriot Bait, where Gemini was used to impersonate an American military veteran, avoiding Russian phrasing, to lure politically engaged Americans into crypto fraud schemes.

That the AI was tricked into bypassing its own safety guardrails by being told it was operating as an 'authorised pentester' will raise familiar questions about how meaningful those guardrails actually are in practice.

The broader implication here is not that AI makes elite hackers more dangerous. It's that it removes the floor. Someone with strategic intent but limited technical skill can now outsource the engineering entirely. And because the whole operation lives in plain text files that won't trigger traditional malware scanners, the methodology is trivially shareable on forums. The Trend Micro researchers put it bluntly: the skill file model turns any capable AI coding agent into a C2 operator for anyone who can talk their way past the safety mechanisms.

Attribution also gets harder. There is no centralised service to identify, and the AI can regenerate or modify any component on demand, making fingerprinting considerably less reliable than it used to be.

None of this requires the AI to be 'evil' or even particularly capable by frontier standards. It just needs to be useful enough and compliant enough. On both counts, it apparently qualified.

READ NEXT
23 Million Paidwork Users' Data Dumped Online After Alleged March BreachBrazilian Gov Websites Hijacked to Deliver Malware in Active Banking CampaignArmenia Locks Up Russian Tourist Named Aleksandr Ermakov. Problem: There Are Two of Them.