Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gemini API Keys Exploited in Telegram Fraud Scheme

Gemini API Keys Exploited in Telegram Fraud Scheme

Posted on June 2, 2026 By CWS

An elaborate Telegram influence campaign, driven by a single threat actor, has leveraged stolen Gemini API keys to operate seamlessly over five years. The campaign, portraying itself as an American patriot channel, successfully amassed over 17,000 subscribers while orchestrating a financially motivated scheme.

The Genesis and Execution of the Campaign

Initiated on February 6, 2021, shortly after the Capitol riot, the campaign tapped into the QAnon and MAGA communities seeking new platforms. Masked as a conservative outlet, the channel ‘americanpatriotus’ was intended to draw politically engaged audiences for fraudulent activities, primarily focusing on cryptocurrency scams.

Trend Micro analysts revealed that in May 2026, a breach exposed the campaign’s infrastructure, uncovering five years of influence operations and AI-assisted fraud. The actor utilized artificial intelligence to manage and expand the channel’s reach efficiently, exploiting political sentiments for financial gains.

AI and Automation: Tools for Fraud

The actor’s transition to fully AI-generated content began in September 2025, using a compromised version of Google Gemini. This AI, dubbed ‘Quantum Patriot’, facilitated content creation by roleplaying as an American patriot, producing content with near-zero operational costs due to stolen API keys.

The operation’s automation was further enhanced by a rotator script, circulating 73 stolen Gemini API keys. This script, later misleadingly published as an open-source project, underscored the campaign’s sophisticated approach to disguising its illicit activities.

Implications for Cybersecurity

The fraudulent operation not only drained cryptocurrency wallets but also compromised 29 WordPress accounts across various sectors. The actor employed AI-driven brute-force tactics to breach site security, highlighting vulnerabilities in current cybersecurity defenses.

To ensure robust defenses, organizations must remain vigilant against the reuse of API keys and anomalies in infrastructure changes. Further, AI vendors are urged to prioritize cross-language security measures and resistances to AI jailbreaks, as demonstrated by this campaign’s exploitation of existing gaps.

As the digital landscape evolves, the integration of AI in fraud schemes signifies an urgent call for enhanced security frameworks and proactive threat intelligence strategies to safeguard against such sophisticated cyber threats.

Cyber Security News Tags:AI credential theft, AI fraud, AI-assisted fraud, API key theft, cloud security, cryptocurrency theft, cyber threat, Cybersecurity, digital security, Gemini API, Gemini jailbreak, Telegram fraud, Telegram influence, Trend Micro, WordPress breach

Post navigation

Previous Post: Trump Orders AI Model Vetting for National Security
Next Post: Russian Officials’ Phones Targeted by Foreign Spyware

Related Posts

Cybercriminals Exploit RMM Tools in Phishing Scams Cybercriminals Exploit RMM Tools in Phishing Scams Cyber Security News
Chinese Cybersecurity Firm Data Breach Exposes State-Sponsored Hackers Cyber Weapons and Target List Chinese Cybersecurity Firm Data Breach Exposes State-Sponsored Hackers Cyber Weapons and Target List Cyber Security News
FIN7 Hackers Using Windows SSH Backdoor to Establish Stealthy Remote Access and Persistence FIN7 Hackers Using Windows SSH Backdoor to Establish Stealthy Remote Access and Persistence Cyber Security News
CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide CloudEyE MaaS Downloader and Cryptor Infects 100,000+ Users Worldwide Cyber Security News
New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads Cyber Security News
Google Passkey System Reveals New Security Concerns Google Passkey System Reveals New Security Concerns Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark