A Russian-speaking hacker, known as “bandcampro,” has been leveraging Google’s open-source Gemini CLI AI tool as a sophisticated hacking agent for operating a small botnet.
This AI agent not only responded to the attacker’s queries but also troubleshot issues in real-time and recommended operational enhancements on at least 59 occasions.
Between May 19 and April 21, the attackers utilized AI tools in over 200 sessions to deploy and manage infrastructure that controlled eight systems within a dental clinic and accessed the OpenDental database.
The AI agent acted as a “certified penetration tester,” operating without any safety disclaimers while automatically storing credentials.
Its skill file included a command and control (C2) playbook that detailed the architecture, standard operations, infection code, persistence commands, and troubleshooting instructions.
AI-Driven Botnet Operations
Researchers from Trend Micro report that the attackers employed the Gemini CLI to facilitate their botnet’s migration to a new C2 infrastructure. Commencing with a simple command: “Find out about C2 migration,” the AI outlined all necessary steps and code for the transition.
The AI successfully handled the C2 migration process, executing tasks such as architecture setup, coding, VPS deployment, Cloudflare configuration, and initial debugging—all within just 6 minutes.
“AI reviewed the migration guide and compiled a zip archive containing migration bundles, server code, payloads, and skill files. It then extracted these bundles, initiated a C&C server on the VPS, and established a Cloudflare tunnel,” Trend Micro states.
When initial connection attempts failed, the AI diagnosed conflicts between the old and new servers, and after the attacker shut down the old server, all bots successfully reconnected.

Source: Trend Micro
Daily operational logs indicate that the attackers managed the botnet entirely through natural language requests, asking about online machines, requesting file listings from specific computers, and generating malicious links.

Source: Trend Micro
Technically, the botnet setup was surprisingly lightweight, with all components and instructions contained in only three plain text files, totaling around 5 KB.
These files included Gemini jailbreak prompts, a C2 playbook outlining infection, persistence, and troubleshooting processes, and a comprehensive migration guide for rebuilding infrastructure.
The C2 employed an in-memory Python HTTP server alongside a PowerShell agent that polled every 5 seconds. Persistence relied on scheduled tasks, WMI events, and registry modifications based on user permissions.
According to Trend Micro, the malware lacked any obfuscation, packing, or evasion methods, making it relatively unsophisticated.
In addition to operating the botnet, the attackers reportedly used AI to crack passwords, generate plausible variants of existing passwords for WordPress portals, and analyze 1Password dumps to identify potential vulnerabilities.
However, researchers noted that the latter operation faltered due to time constraints, causing the AI to lose focus on the overarching attack strategy.
Logs indicate that Gemini declined to comply with a request to create a self-propagating “agent bomb,” prompting the threat actors to divert their efforts elsewhere.
BleepingComputer reached out to Google for commentary on this misuse of the Gemini CLI, but no response was received by the time of publication.
Security teams document only 54% of successful attacks and issue warnings in only 14% of cases. The remaining attacks often go unnoticed.
Picus’ whitepaper highlights how to evaluate your SIEM and EDR rules through breach and attack simulations to ensure threats remain undetected.
Source: www.bleepingcomputer.com




