Bandcampro Patriot Bait AI-assisted fraud campaign targeting politically engaged American audiences
Campaign
Summary
Hide ▲
Show ▼
The Patriot Bait campaign tied to bandcampro ran AI-assisted fraud and credential-theft operations against politically engaged American audiences, creating a scalable path for account abuse and cryptocurrency scams. The operation used a Telegram channel and Google Gemini CLI to support impersonation, password cracking, botnet management, and C&C migration. It also extended to planning phone-based cryptocurrency fraud against elderly people in the U.S. and Canada and to abusing infrastructure against WordPress merchants and a dental clinic network.
Related Happenings
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor Meta
H score36
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
How related:
The findings show that the technology can not only cut the resources necessary to run large-scale operations, but also enable bad actors with little to no technical knowledge to set up such schemes with minimal effort or distribute them on underground forums in the form of malicious skill files, effectively paving the way for new AI-powered malware services that go beyond the conventional "as-a-service" models.
About this happening:
Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor MetaHow related: The findings show that the technology can not only cut the resources necessary to run large-scale operations, but also enable bad actors with little to no technical knowledge to set up such schemes with minimal effort or distribute them on underground forums in the form of malicious skill files, effectively paving the way for new AI-powered malware services that go beyond the conventional "as-a-service" models.
About this happening: Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Google civil lawsuit against Outsider Enterprise
Regulatory/Legal Action
H score55
First: 14.06.2026 17:36
Last: 14.06.2026 17:36
Sources 1
About this happening:
Google filed a civil lawsuit against Outsider Enterprise, adding legal pressure to a major phishing infrastructure operation that sent fraudulent texts at scale. T...
Google civil lawsuit against Outsider Enterprise
Regulatory/Legal ActionAbout this happening: Google filed a civil lawsuit against Outsider Enterprise, adding legal pressure to a major phishing infrastructure operation that sent fraudulent texts at scale. T...
FBI takedown of Outsider Enterprise phishing service
Law Enforcement
H score63
First: 14.06.2026 17:36
Last: 14.06.2026 17:36
Sources 1
About this happening:
The FBI and partners dismantled Outsider Enterprise, a phishing-as-a-service operation tied to thousands of phishing websites and large-scale credential theft....
FBI takedown of Outsider Enterprise phishing service
Law EnforcementAbout this happening: The FBI and partners dismantled Outsider Enterprise, a phishing-as-a-service operation tied to thousands of phishing websites and large-scale credential theft....
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score69
First: 12.06.2026 21:59
Last: 12.06.2026 21:59
Sources 1
About this happening:
The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Outsider Enterprise-Outsider-Chinese cybercrime alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: The Outsider Enterprise is a Chinese phishing-as-a-service operation that used Telegram, AI, and distributed phishing kits to run large-scale brand-impersonation c...
Outsider Telegram-run smishing campaign targeting Americans
Campaign
H score53
First: 12.06.2026 21:59
Last: 12.06.2026 21:59
Sources 1
About this happening:
The Outsider Enterprise happening is a phishing-as-a-service campaign tied to a Chinese cybercrime network that used AI and distributed phishing kits to impersonat...
Outsider Telegram-run smishing campaign targeting Americans
CampaignAbout this happening: The Outsider Enterprise happening is a phishing-as-a-service campaign tied to a Chinese cybercrime network that used AI and distributed phishing kits to impersonat...
Latest development: 14.06.2026 17:36
The FBI, working with Google and Black Lotus Labs, dismantled Outsider Enterprise, a Chinese phishing-as-a-service operation that used AI and distributed phishing kits to impersonate trusted brands in texts sent through AT&T, T-Mobile and Verizon. The takedown included seizures of administration servers, a Shopify e-commerce storefront, a testing account, around $100,000 USDT and a Telegram bot linked to the service, while Google pursued civil action and coordinated with carriers to block fraudulent messages.
Timeline
-
20.07.2026 12:07 2 articles · 16h ago
Trend Micro details bandcampro's Gemini CLI botnet workflow
Technical Analysis UpdateTrend Micro said the Russian-speaking actor known as bandcampro used Google's Gemini CLI as the primary operator for a C&C and botnet workflow, including migrating infrastructure in six minutes, controlling eight computers in a dental clinic, accessing an OpenDental database, setting up Cloudflare tunnels and a residential proxy, cracking passwords, probing WordPress merchants, and planning cryptocurrency fraud aimed at people in the U.S. and Canada.
Show sources
- Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs — thehackernews.com — 20.07.2026 12:07
- Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs — thehackernews.com — 20.07.2026 12:07