ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Artificial Intelligence

Bandcampro uses Google Gemini CLI sessions to manage a dental PC botnet

Source headline: Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

Threat level High
Signal strength 74/100
Source confidence 1 source
Published 16 hours ago

Intelligence Summary

A solo threat actor tracked as bandcampro is reported to have used Google’s Gemini CLI to run parts of botnet operations. The activity was analyzed from 200 Gemini CLI session logs spanning late March to mid-April 2026. The botnet reportedly included eight PCs belonging to a dental clinic. The actor used AI-assisted capabilities alongside other techniques such as password cracking and remote control. This matters because it shows AI tooling can be integrated into real-world command and control workflows, increasing the risk of compromise and lateral movement.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#botnet #ai #remote-control #credential-access #gemini-cli
Original reporting The Hacker News Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
Open original source