🟡 Medium | Source: The Hacker News
A solo Russian-speaking threat actor known as ‘bandcampro’ has been using Google’s open-source Gemini CLI AI tool to automate botnet operations, including password cracking, against a small network of eight compromised dental clinic PCs. Analysis of 200 Gemini CLI session logs spanning March to April 2026 revealed the actor offloading operational tasks to the AI assistant. This case marks an early real-world example of a threat actor integrating a publicly available AI CLI tool directly into their attack workflow.
Security Architect’s Take: Review your organisation’s policies around AI CLI tools such as Gemini CLI and ensure they cannot be introduced into production or sensitive environments without authorisation; additionally, monitor for anomalous use of open-source AI tooling in your CI/CD pipelines or developer endpoints, as these tools may be weaponised to automate reconnaissance or credential attacks against cloud resources.
Original advisory: Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs