Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet

https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-2560-80.jpg
  • Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic
  • The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles
  • The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools

A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.

Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's Gemini AI models directly from a terminal.

Scouring through a month’s worth of session logs (between April 21 and...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more