What Happened
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential
Why It Matters
According to multiple reports, a Russian-speaking threat actor "bandcampro" used Google's open-source Gemini CLI as an interactive hacking assistant to deploy and operate a botnet of eight PCs in a dental clinic, access an OpenDental patient database, crack passwords, and rapidly migrate command-and-control infrastructure, all over 200+ AI sessions.[1][2][3][6][8] These activities represent deliberate abuse of a legitimate agentic AI tool rather than exploitation of a software vulnerability, turning Gemini CLI into an autonomous attack facilitator.[4][6] From a RealGround perspective, this highlights AI agent abuse risk: organizations that run powerful AI CLIs with broad system or network access must treat them as privileged automation, enforce human-in-the-loop controls for dangerous actions, isolate agents in sandboxes, and continuously monitor for AI-driven attack behaviors like rapid C2 spin-up, scripted tunneling, and credential processing. Mapping to RealGround services, Secure AI Agent Build and AI Agent Business Logic Audit can help design and constrain such AI agents safely, while Continuous AI Red Teaming can emulate similar AI-assisted attack patterns to validate defense
RealGround Analysis
This signal maps to AI agent abuse. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html
