← BACK TO FEED
TAG

gemini cli1 articles

One Hacker, Eight Dental PCs, and Google's Own AI Running the Operation

A Russian-speaking threat actor called "bandcampro" used Google's open-source Gemini CLI AI tool to operate a small botnet of eight dental clinic computers, with the AI handling approximately 89% of all text output and performing tasks such as migrating command-and-control infrastructure, debugging errors, and managing compromised machines via natural language prompts in Russian. Analysis of 200 session logs revealed the threat actor also leveraged the AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly people in the US and Canada. Researchers warn that the entire operation was condensed into just three portable text files, making the infrastructure easily disposable and replicable, and that this "skill-file" model could spread widely, effectively enabling even low-skilled actors to deploy AI-powered hacking operations with minimal effort.

21 Jul 2026