Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gemini API Keys Exploited in Telegram Fraud Scheme

Gemini API Keys Exploited in Telegram Fraud Scheme

Posted on June 2, 2026 By CWS

An elaborate Telegram influence campaign, driven by a single threat actor, has leveraged stolen Gemini API keys to operate seamlessly over five years. The campaign, portraying itself as an American patriot channel, successfully amassed over 17,000 subscribers while orchestrating a financially motivated scheme.

The Genesis and Execution of the Campaign

Initiated on February 6, 2021, shortly after the Capitol riot, the campaign tapped into the QAnon and MAGA communities seeking new platforms. Masked as a conservative outlet, the channel ‘americanpatriotus’ was intended to draw politically engaged audiences for fraudulent activities, primarily focusing on cryptocurrency scams.

Trend Micro analysts revealed that in May 2026, a breach exposed the campaign’s infrastructure, uncovering five years of influence operations and AI-assisted fraud. The actor utilized artificial intelligence to manage and expand the channel’s reach efficiently, exploiting political sentiments for financial gains.

AI and Automation: Tools for Fraud

The actor’s transition to fully AI-generated content began in September 2025, using a compromised version of Google Gemini. This AI, dubbed ‘Quantum Patriot’, facilitated content creation by roleplaying as an American patriot, producing content with near-zero operational costs due to stolen API keys.

The operation’s automation was further enhanced by a rotator script, circulating 73 stolen Gemini API keys. This script, later misleadingly published as an open-source project, underscored the campaign’s sophisticated approach to disguising its illicit activities.

Implications for Cybersecurity

The fraudulent operation not only drained cryptocurrency wallets but also compromised 29 WordPress accounts across various sectors. The actor employed AI-driven brute-force tactics to breach site security, highlighting vulnerabilities in current cybersecurity defenses.

To ensure robust defenses, organizations must remain vigilant against the reuse of API keys and anomalies in infrastructure changes. Further, AI vendors are urged to prioritize cross-language security measures and resistances to AI jailbreaks, as demonstrated by this campaign’s exploitation of existing gaps.

As the digital landscape evolves, the integration of AI in fraud schemes signifies an urgent call for enhanced security frameworks and proactive threat intelligence strategies to safeguard against such sophisticated cyber threats.

Cyber Security News Tags:AI credential theft, AI fraud, AI-assisted fraud, API key theft, cloud security, cryptocurrency theft, cyber threat, Cybersecurity, digital security, Gemini API, Gemini jailbreak, Telegram fraud, Telegram influence, Trend Micro, WordPress breach

Post navigation

Previous Post: Trump Orders AI Model Vetting for National Security
Next Post: Russian Officials’ Phones Targeted by Foreign Spyware

Related Posts

NightSpire Ransomware Group Claims to Exploit The Vulnerabilities of Orgs to Infiltrate Their Systems NightSpire Ransomware Group Claims to Exploit The Vulnerabilities of Orgs to Infiltrate Their Systems Cyber Security News
Hackers Started Exploiting CitrixBleed 2 Vulnerability Before Public PoC Disclosure Hackers Started Exploiting CitrixBleed 2 Vulnerability Before Public PoC Disclosure Cyber Security News
Chrome V8 JavaScript Engine Vulnerability Let Attackers Execute Remote Code Chrome V8 JavaScript Engine Vulnerability Let Attackers Execute Remote Code Cyber Security News
Microsoft and CrowdStrike Teaming Up to Bring Clarity To Threat Actor Mapping Microsoft and CrowdStrike Teaming Up to Bring Clarity To Threat Actor Mapping Cyber Security News
Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper Cyber Security News
Nebula’s AI-Powered Security Tool Revolutionizes Testing Nebula’s AI-Powered Security Tool Revolutionizes Testing Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders
  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders
  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark