bleeping-computer · Crawled Jul 15, 2026

Google Gemini CLI abused as a hacking agent, malware botnet operator

1 IoCs
Read original article ↗

AI Summary

A Russian-speaking threat actor named 'bandcampro' abused Google's open-source Gemini CLI AI tool to operate a small-scale botnet and conduct hacking activities. The actor used the AI as an automated hacking agent to migrate command-and-control (C2) infrastructure, manage botnet operations via natural language, and attempt password guessing and data analysis. The botnet targeted systems in a dental clinic, accessing the OpenDental database, with operations sustained through simple but effective techniques including PowerShell agents and scheduled tasks. The malware lacked advanced evasion capabilities but was managed efficiently through AI-driven automation.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub User bandcampro Details →