Find notable cyber news and cases, enriched with sources, timelines, and signals.

Bandcampro Patriot Bait AI-assisted fraud campaign targeting politically engaged American audiences

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

The Patriot Bait campaign tied to bandcampro ran AI-assisted fraud and credential-theft operations against politically engaged American audiences, creating a scalable path for account abuse and cryptocurrency scams. The operation used a Telegram channel and Google Gemini CLI to support impersonation, password cracking, botnet management, and C&C migration. It also extended to planning phone-based cryptocurrency fraud against elderly people in the U.S. and Canada and to abusing infrastructure against WordPress merchants and a dental clinic network.

Related Happenings

Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime

Threat Actor Meta
H score36 First: 20.07.2026 12:07 Last: 20.07.2026 12:07 Sources 1

How related: The findings show that the technology can not only cut the resources necessary to run large-scale operations, but also enable bad actors with little to no technical knowledge to set up such schemes with minimal effort or distribute them on underground forums in the form of malicious skill files, effectively paving the way for new AI-powered malware services that go beyond the conventional "as-a-service" models.

About this happening: Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...

Google civil lawsuit against Outsider Enterprise

Regulatory/Legal Action
H score55 First: 14.06.2026 17:36 Last: 14.06.2026 17:36 Sources 1

About this happening: Google filed a civil lawsuit against Outsider Enterprise, adding legal pressure to a major phishing infrastructure operation that sent fraudulent texts at scale. T...

FBI takedown of Outsider Enterprise phishing service

Law Enforcement
H score63 First: 14.06.2026 17:36 Last: 14.06.2026 17:36 Sources 1

About this happening: The FBI and partners dismantled Outsider Enterprise, a phishing-as-a-service operation tied to thousands of phishing websites and large-scale credential theft....

Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score69 First: 12.06.2026 21:59 Last: 12.06.2026 21:59 Sources 1

About this happening: The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...

Outsider Telegram-run smishing campaign targeting Americans

Campaign
H score53 First: 12.06.2026 21:59 Last: 12.06.2026 21:59 Sources 1

About this happening: The Outsider Enterprise happening is a phishing-as-a-service campaign tied to a Chinese cybercrime network that used AI and distributed phishing kits to impersonat...

Latest development: 14.06.2026 17:36

The FBI, working with Google and Black Lotus Labs, dismantled Outsider Enterprise, a Chinese phishing-as-a-service operation that used AI and distributed phishing kits to impersonate trusted brands in texts sent through AT&T, T-Mobile and Verizon. The takedown included seizures of administration servers, a Shopify e-commerce storefront, a testing account, around $100,000 USDT and a Telegram bot linked to the service, while Google pursued civil action and coordinated with carriers to block fraudulent messages.

Timeline

  1. 20.07.2026 12:07 2 articles · 16h ago

    Trend Micro details bandcampro's Gemini CLI botnet workflow

    Technical Analysis Update

    Trend Micro said the Russian-speaking actor known as bandcampro used Google's Gemini CLI as the primary operator for a C&C and botnet workflow, including migrating infrastructure in six minutes, controlling eight computers in a dental clinic, accessing an OpenDental database, setting up Cloudflare tunnels and a residential proxy, cracking passwords, probing WordPress merchants, and planning cryptocurrency fraud aimed at people in the U.S. and Canada.

    Show sources