Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gemini API Keys Exploited in Telegram Fraud Scheme

Gemini API Keys Exploited in Telegram Fraud Scheme

Posted on June 2, 2026 By CWS

An elaborate Telegram influence campaign, driven by a single threat actor, has leveraged stolen Gemini API keys to operate seamlessly over five years. The campaign, portraying itself as an American patriot channel, successfully amassed over 17,000 subscribers while orchestrating a financially motivated scheme.

The Genesis and Execution of the Campaign

Initiated on February 6, 2021, shortly after the Capitol riot, the campaign tapped into the QAnon and MAGA communities seeking new platforms. Masked as a conservative outlet, the channel ‘americanpatriotus’ was intended to draw politically engaged audiences for fraudulent activities, primarily focusing on cryptocurrency scams.

Trend Micro analysts revealed that in May 2026, a breach exposed the campaign’s infrastructure, uncovering five years of influence operations and AI-assisted fraud. The actor utilized artificial intelligence to manage and expand the channel’s reach efficiently, exploiting political sentiments for financial gains.

AI and Automation: Tools for Fraud

The actor’s transition to fully AI-generated content began in September 2025, using a compromised version of Google Gemini. This AI, dubbed ‘Quantum Patriot’, facilitated content creation by roleplaying as an American patriot, producing content with near-zero operational costs due to stolen API keys.

The operation’s automation was further enhanced by a rotator script, circulating 73 stolen Gemini API keys. This script, later misleadingly published as an open-source project, underscored the campaign’s sophisticated approach to disguising its illicit activities.

Implications for Cybersecurity

The fraudulent operation not only drained cryptocurrency wallets but also compromised 29 WordPress accounts across various sectors. The actor employed AI-driven brute-force tactics to breach site security, highlighting vulnerabilities in current cybersecurity defenses.

To ensure robust defenses, organizations must remain vigilant against the reuse of API keys and anomalies in infrastructure changes. Further, AI vendors are urged to prioritize cross-language security measures and resistances to AI jailbreaks, as demonstrated by this campaign’s exploitation of existing gaps.

As the digital landscape evolves, the integration of AI in fraud schemes signifies an urgent call for enhanced security frameworks and proactive threat intelligence strategies to safeguard against such sophisticated cyber threats.

Cyber Security News Tags:AI credential theft, AI fraud, AI-assisted fraud, API key theft, cloud security, cryptocurrency theft, cyber threat, Cybersecurity, digital security, Gemini API, Gemini jailbreak, Telegram fraud, Telegram influence, Trend Micro, WordPress breach

Post navigation

Previous Post: Trump Orders AI Model Vetting for National Security
Next Post: Russian Officials’ Phones Targeted by Foreign Spyware

Related Posts

7 New Vulnerabilities in GPT-4o and GPT-5 Enables 0-Click Attacks 7 New Vulnerabilities in GPT-4o and GPT-5 Enables 0-Click Attacks Cyber Security News
ToxicPanda Android Banking Malware Infected 4500+ Devices to Steal Banking Credentials ToxicPanda Android Banking Malware Infected 4500+ Devices to Steal Banking Credentials Cyber Security News
Apple Font Parser Vulnerability Enables Malicious Fonts to Crash or Corrupt Process Memory Apple Font Parser Vulnerability Enables Malicious Fonts to Crash or Corrupt Process Memory Cyber Security News
Microsoft Details Security Risks of New Agentic AI Feature Microsoft Details Security Risks of New Agentic AI Feature Cyber Security News
Python-Based Malware Targets Windows for Credential Theft Python-Based Malware Targets Windows for Credential Theft Cyber Security News
Microsoft Teams to Enforce Messaging Safety Defaults Starting January 2026 Microsoft Teams to Enforce Messaging Safety Defaults Starting January 2026 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Expands AI Cybersecurity Reach to 150 Organizations
  • Critical Flaw in KMW CCTV Allows Unauthorized Access
  • Russian Officials’ Phones Targeted by Foreign Spyware
  • Gemini API Keys Exploited in Telegram Fraud Scheme
  • Trump Orders AI Model Vetting for National Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Expands AI Cybersecurity Reach to 150 Organizations
  • Critical Flaw in KMW CCTV Allows Unauthorized Access
  • Russian Officials’ Phones Targeted by Foreign Spyware
  • Gemini API Keys Exploited in Telegram Fraud Scheme
  • Trump Orders AI Model Vetting for National Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark