A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.
The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential proxy, compromise WordPress merchants, and plan a phone-based cryptocurrency fraud scheme aimed at elderly people in the U.S. and Canada.
"The logs documented how the threat actor used an AI agent to migrate a command-and-control (C&C) server, and to control a small-scale botnet, among other hacking activities," Trend Micro researchers Joseph C Chen, Philippe Lin, Lucas Silva, Vladimir Kropotov, and Fyodor Yarochkin said.
"The entire C&C operation fits in three plaintext files totaling roughly 5 KB, making it highly replicable and effectively disposable. The AI was also observed to proactively (unprompted) propose improvements 59 times without being asked."
Specifically, the threat actor is said to have abused Google Gemini CLI to deploy and operate a C&C infrastructure to control eight computers in a dental clinic and access their OpenDental database. Besides writing code snippets, the AI served as the "primary hacking agent, consultant, and interface" to the entire operation.
This included setting up the server, deploying it on a new virtual private server (VPS), configuring the infrastructure, setting up Cloudflare tunnels, managing the bots, and debugging connectivity issues.
Details of "bandcampro" first emerged in late May 2026 in connection with a campaign dubbed Patriot Bait that used AI-assisted information operation (IO) techniques to run a Telegram channel, targeting politically engaged American audiences for cryptocurrency fraud and AI-assisted credential theft.
Trend Micro has described the threat actor as a Russian speaker who used Google Gemini to "impersonate an American veteran patriot and to avoid Russian phrasing," while tricking the AI agent into bypassing its guardrails by assuming the role of an "authorized pentester."

The threat actor is said to have run prompts to study the old C&C infrastructure where the victim machines connected using Cloudflare tunnels and migrate it to a new architecture within six minutes. The architecture involves victims issuing outbound requests to a C&C server over HTTPS to pull and run PowerShell commands staged by the threat actor on the server.
