A Russian-speaking cybercriminal, identified as “bandcampro,” has harnessed Google’s Gemini CLI, an open-source artificial intelligence tool, to operate a botnet affecting computers in dental clinics. This operation, uncovered by Trend Micro researchers, emphasizes the evolving threat landscape where AI is increasingly utilized for cyberattacks.
AI Assists in Cyber Operations
Between March 19 and April 21, 2026, an analysis of 200 Gemini CLI session logs revealed the hacker’s use of AI to perform various malicious activities. These included password cracking, setting up residential proxies, compromising WordPress sites, and planning cryptocurrency fraud targeting older individuals in North America.
Trend Micro’s report detailed how “bandcampro” employed the AI to migrate a command-and-control (C&C) server and manage a botnet, demonstrating AI’s capacity to enhance cybercriminal efficiency. The entire C&C setup was documented in three plaintext files, highlighting its simplicity and disposability.
Implications for Cybersecurity
The threat actor exploited Google Gemini CLI to establish and control the C&C infrastructure for eight computers within a dental clinic, accessing their OpenDental database. The AI took on roles beyond coding, acting as a consultant and interface for the operations, managing tasks such as server setup, infrastructure configuration, and debugging connectivity issues.
This AI-driven methodology was first highlighted in May 2026 through a campaign called Patriot Bait, which involved AI-assisted information operations targeting American audiences for fraudulent activities. The hacker used the AI to impersonate an American patriot and bypass the AI’s safety protocols.
The Future of AI in Cybercrime
The findings from Trend Micro underscore the potential for AI to streamline and scale cyber operations, reducing the need for technical expertise. This poses a significant challenge for cybersecurity efforts, as AI can rapidly adapt and regenerate components of an attack, complicating attribution and mitigation.
Moreover, the ability to transfer the entire C&C operation to a new server with minimal effort makes take-down attempts less effective. The hacker’s reliance on AI for tasks such as password cracking and credential exploitation further illustrates AI’s role in modern cyber threats.
As AI continues to evolve, its integration into cybercriminal strategies could lead to more sophisticated and widespread attacks, necessitating enhanced defenses and proactive measures in the cybersecurity domain.
