A solo Russian-speaking threat actor known as “bandcampro” has been observed using Google’s open-source Gemini CLI AI to control a botnet of eight computers in a dental clinic, according to Trend Micro researchers. The analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, revealed the actor using AI to crack passwords, set up a residential proxy, compromise WordPress merchants, and plan a phone-based cryptocurrency fraud scheme targeting elderly individuals in the U.S. and Canada.
The threat actor abused Google Gemini CLI to deploy and operate a command-and-control (C&C) infrastructure, accessing the clinic’s OpenDental database. The AI served as the primary hacking agent, handling 80% of architectural design, 100% of coding and system command execution, and 90% of problem diagnosis and debugging. The entire C&C operation fits in three plaintext files totaling roughly 5 KB, making it highly replicable and disposable.
Key activities included migrating the C&C server in six minutes, managing botnet tasks via natural language instructions in Russian, and using the AI as a credential mutation engine for password cracking. The actor also attempted to build a self-spreading “agent-bomb,” which the AI refused. The findings highlight how AI can lower the barrier for cybercrime, enabling disposable infrastructure and complicating attribution.
Attack groups: bandcampro
Companies: Google, Trend Micro, Cloudflare, OpenDental, WordPress, AntiPublic
Products: Google Gemini CLI, Cloudflare
Original source: thehackernews.com