Skip to content

Russian Attacker Uses Google Gemini CLI to Control Dentist Botnet

In Brief: Attackers are using Gemini CLI to automate botnet operations, demonstrating a new attack vector in which threat actors leverage public AI tools.

A Russian-speaking attacker named “bandcampro” has used Google’s open-source Gemini CLI tool to control an active botnet consisting of eight dental clinic computers. Analysed session logs show systematic use of AI for password cracking and network setup between March and April 2026.

Analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026 documents the systematic use of Google’s tool by threat actor “bandcampro”. The attacker used the AI interface to crack passwords and configure residential infrastructure for his botnet, among other activities.

The compromised network comprised eight PC systems from dental practices. The use of Gemini CLI enabled the attacker to automate time-consuming routine tasks and thus reduce the operational effort required for botnet management. This highlights a growing risk: threat actors adapt publicly available AI tools for their infrastructure faster than traditional methods are blocked by new security mechanisms.

For CISOs, this case presents an additional monitoring dimension. While most security teams focus their attention on dedicated hacking tools, major AI platforms are being abused as operational tools. The session logs were accessible – an indication that attackers also expect their AI usage to be traceable, but rate the operational benefit higher than obfuscation risks.


Source: thehackernews.com · Published July 20, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: