← BACK TO FEED
TAG

botnets3 articles

One Hacker, Eight Dental PCs, and Google's Own AI Running the Operation

A Russian-speaking threat actor called "bandcampro" used Google's open-source Gemini CLI AI tool to operate a small botnet of eight dental clinic computers, with the AI handling approximately 89% of all text output and performing tasks such as migrating command-and-control infrastructure, debugging errors, and managing compromised machines via natural language prompts in Russian. Analysis of 200 session logs revealed the threat actor also leveraged the AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly people in the US and Canada. Researchers warn that the entire operation was condensed into just three portable text files, making the infrastructure easily disposable and replicable, and that this "skill-file" model could spread widely, effectively enabling even low-skilled actors to deploy AI-powered hacking operations with minimal effort.

21 Jul 2026

HalluSquatting: How AI Coding Assistants Could Be Turned Into Botnet Recruitment Tools

Researchers have discovered a new AI attack called **HalluSquatting**, which exploits the tendency of large language models (LLMs) to hallucinate incorrect resource locations — such as repository URLs — up to 92% of the time for recently published content. Attackers can predict these hallucinated locations in advance, register them, and plant malicious code (such as reverse shells) that AI coding assistants like Cursor, GitHub Copilot, and Gemini CLI will automatically retrieve and execute. Unlike previous prompt injection attacks that required targeting individuals one by one, HalluSquatting scales massively, potentially enabling large botnets, DDoS attacks, and ransomware campaigns with minimal attacker effort.

13 Jul 2026

Meet CAI: The Cloud Worm That Mugs Other Malware Before Robbing You

A new cloud-targeting botnet called Cloud AI Infrastructure Attack Framework (CAI) has emerged, designed to steal credentials and mine cryptocurrency while actively eliminating competing malware like TeamPCP and PCPJack from compromised systems. It targets cloud-native tools such as Docker, Kubernetes, and Redis, using a centralized command-and-control structure and showing signs of LLM-assisted development. Security researchers warn that CAI's emergence alongside rival threat actors signals a growing and increasingly competitive landscape of malicious actors targeting cloud infrastructure and developer secrets.

13 Jul 2026