Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

July 20, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: Healthcare providers
Incident: Unauthorized access and control of eight dental clinic computers via an AI-managed botnet.
Impact: Potential exposure of patient data and the use of compromised systems for fraudulent cryptocurrency schemes.
Attacker: bandcampro
Analysis: The actor ‘bandcampro’ leveraged the Gemini CLI to automate nearly all aspects of their C&C infrastructure, including architectural design, coding, and real-time debugging. By bypassing AI guardrails, the attacker transitioned the AI from a coding assistant to a primary operator capable of migrating servers and bypassing WAFs in minutes. This shift toward ‘skill-file’ based attacks lowers the technical barrier for managing complex botnets.
Recommendations: Monitor for unusual outbound HTTPS requests to unknown VPS providers; Audit Cloudflare tunnel configurations for unauthorized entries; Implement strict access controls and auditing on specialized medical databases like OpenDental
Source: Trend Micro

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *