Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor Meta
Summary
Hide ▲
Show ▼
Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-assisted model. The setup let the actor migrate infrastructure in six minutes, manage bots, and support password cracking and WordPress compromise tasks. The workflow was portable through plaintext and markdown skill files, which can be shared on underground forums. That lowers the skill barrier for cybercrime and makes takedowns less effective across the March–April 2026 log window.
Related Happenings
Reproduced cross-vendor sandbox escapes in AI coding agents
Technical Analysis
H score22
First: 21.07.2026 00:14
Last: 21.07.2026 00:14
Sources 1
About this happening:
Researchers reproduced sandbox-escape bypasses across Cursor, Codex, Gemini CLI, and Antigravity, showing that agentic coding tools can cross the sandbox bound...
Reproduced cross-vendor sandbox escapes in AI coding agents
Technical AnalysisAbout this happening: Researchers reproduced sandbox-escape bypasses across Cursor, Codex, Gemini CLI, and Antigravity, showing that agentic coding tools can cross the sandbox bound...
Bandcampro Patriot Bait AI-assisted fraud campaign targeting politically engaged American audiences
Campaign
H score35
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
How related:
Details of "bandcampro" first emerged in late May 2026 in connection with a campaign dubbed Patriot Bait that used AI-assisted information operation (IO) techniques to run a Telegram channel, targeting politically engaged American audiences for cryptocurrency fraud and AI-assisted credential theft.
About this happening:
The Patriot Bait campaign tied to bandcampro ran AI-assisted fraud and credential-theft operations against politically engaged American audiences, creating a scalable...
Bandcampro Patriot Bait AI-assisted fraud campaign targeting politically engaged American audiences
CampaignHow related: Details of "bandcampro" first emerged in late May 2026 in connection with a campaign dubbed Patriot Bait that used AI-assisted information operation (IO) techniques to run a Telegram channel, targeting politically engaged American audiences for cryptocurrency fraud and AI-assisted credential theft.
About this happening: The Patriot Bait campaign tied to bandcampro ran AI-assisted fraud and credential-theft operations against politically engaged American audiences, creating a scalable...
Dental clinic hit by network compromise
Incident
H score12
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
How related:
Specifically, the threat actor is said to have abused Google Gemini CLI to deploy and operate a C&C infrastructure to control eight computers in a dental clinic and access their OpenDental database.
About this happening:
A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and r...
Dental clinic hit by network compromise
IncidentHow related: Specifically, the threat actor is said to have abused Google Gemini CLI to deploy and operate a C&C infrastructure to control eight computers in a dental clinic and access their OpenDental database.
About this happening: A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and r...
Bandcampro Gemini CLI botnet operation
Malware Activity
H score22
First: 15.07.2026 21:33
Last: 15.07.2026 21:33
Sources 1
About this happening:
The bandcampro botnet operation used Google's open-source Gemini CLI to run and migrate C2 infrastructure, letting the actor manage infected systems and generate attac...
Bandcampro Gemini CLI botnet operation
Malware ActivityAbout this happening: The bandcampro botnet operation used Google's open-source Gemini CLI to run and migrate C2 infrastructure, letting the actor manage infected systems and generate attac...
UNC5221 Brickstorm, Plenet, and AgentPSD access-maintenance malware activity
Malware Activity
H score16
First: 05.06.2026 21:09
Last: 05.06.2026 21:09
Sources 1
About this happening:
The Brickstorm malware set enabled UNC5221 / VerdantBamboo to keep long-term access inside victim infrastructure, including Microsoft 365, raising the risk of stealthy...
UNC5221 Brickstorm, Plenet, and AgentPSD access-maintenance malware activity
Malware ActivityAbout this happening: The Brickstorm malware set enabled UNC5221 / VerdantBamboo to keep long-term access inside victim infrastructure, including Microsoft 365, raising the risk of stealthy...
Timeline
-
20.07.2026 12:07 2 articles · 16h ago
Trend Micro details bandcampro’s Gemini CLI-run disposable C&C operation
Initial DisclosureTrend Micro identified a solo Russian-speaking threat actor known as "bandcampro" using Google’s open-source Gemini CLI as the main operator for a C&C and botnet workflow. The actor used the AI to migrate infrastructure in six minutes, set up a new VPS, configure Cloudflare tunnels, manage bots, debug connectivity problems, crack passwords, and control eight computers in a dental clinic while accessing their OpenDental database. The same session window also showed the actor planning credential theft and cryptocurrency fraud, with the AI generating most of the code and command execution.
Show sources
- Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs — thehackernews.com — 20.07.2026 12:07
- Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs — thehackernews.com — 20.07.2026 12:07