Bandcampro uses Google Gemini CLI sessions to manage a dental PC botnet
Source headline: Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
Intelligence Summary
A solo threat actor tracked as bandcampro is reported to have used Google’s Gemini CLI to run parts of botnet operations. The activity was analyzed from 200 Gemini CLI session logs spanning late March to mid-April 2026. The botnet reportedly included eight PCs belonging to a dental clinic. The actor used AI-assisted capabilities alongside other techniques such as password cracking and remote control. This matters because it shows AI tooling can be integrated into real-world command and control workflows, increasing the risk of compromise and lateral movement.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.