Dental clinic hit by network compromise
Incident
Summary
Hide ▲
Show ▼
A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and reached the OpenDental database. The intrusion gave the operator direct access to clinic systems and data, increasing the risk of further misuse or persistence. The activity was observed in logs covering March 19 to April 21, 2026.
Related Happenings
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor Meta
H score36
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
How related:
The findings show that the technology can not only cut the resources necessary to run large-scale operations, but also enable bad actors with little to no technical knowledge to set up such schemes with minimal effort or distribute them on underground forums in the form of malicious skill files, effectively paving the way for new AI-powered malware services that go beyond the conventional "as-a-service" models.
About this happening:
Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime
Threat Actor MetaHow related: The findings show that the technology can not only cut the resources necessary to run large-scale operations, but also enable bad actors with little to no technical knowledge to set up such schemes with minimal effort or distribute them on underground forums in the form of malicious skill files, effectively paving the way for new AI-powered malware services that go beyond the conventional "as-a-service" models.
About this happening: Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-as...
Bandcampro Gemini CLI botnet operation
Malware Activity
H score22
First: 15.07.2026 21:33
Last: 15.07.2026 21:33
Sources 1
About this happening:
The bandcampro botnet operation used Google's open-source Gemini CLI to run and migrate C2 infrastructure, letting the actor manage infected systems and generate attac...
Bandcampro Gemini CLI botnet operation
Malware ActivityAbout this happening: The bandcampro botnet operation used Google's open-source Gemini CLI to run and migrate C2 infrastructure, letting the actor manage infected systems and generate attac...
Google hit by network compromise
Incident
H score42
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Google hit by network compromise
IncidentAbout this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Timeline
-
20.07.2026 12:07 2 articles · 16h ago
Google Gemini CLI controlled eight computers in a dental clinic
Initial DisclosureTrend Micro disclosed that a solo Russian-speaking threat actor known as "bandcampro" used Google's Gemini CLI as the main operator for a C&C/botnet workflow that controlled eight computers in a dental clinic and accessed the clinic's OpenDental database. The analyzed logs covered March 19 to April 21, 2026 and also show the operator using the AI to set up and migrate infrastructure, manage bots, and debug connectivity issues.
Show sources
- Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs — thehackernews.com — 20.07.2026 12:07
- Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs — thehackernews.com — 20.07.2026 12:07