Skip to content
feed: live
>_ 0dayNews
threat intel
● Breaking

Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI

Trend Micro forensicated 200 Google Gemini CLI sessions used by a lone Russian-speaking actor to run an eight-node dental-clinic botnet through natural-language prompts.

Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 3 min read

Trend Micro published a forensic analysis of 200 Google Gemini CLI session logs run between 2026-03-19 and 2026-04-21 by a lone Russian-speaking operator using the handle “bandcampro.” The operator used the CLI as an on-demand backend for C2 buildout, credential work, and botnet management. Confidence: as-reported by Trend Micro (Chen, Lin, Silva, Kropotov, Yarochkin). No second-source corroboration at time of writing.

Botnet footprint at time of the logged activity: eight machines at a single dental clinic, with access observed to the clinic’s OpenDental database. Small. That is the point of this story, not a footnote against it — the interesting variable here is the operator’s productivity, not the scale of the intrusion.

What the sessions show the CLI doing

Per Trend Micro’s write-up, the prompts issued in Russian directed Gemini CLI to:

  • Stand up and iterate on C2 server infrastructure, including a VPS deployment and Cloudflare tunnel configuration.
  • Migrate the C2 server end-to-end in a six-minute session window.
  • Manage the botnet nodes and debug connectivity issues.
  • Generate PowerShell commands used in the infection chain.
  • Drive a credential mutation engine for password cracking, and analyze harvested credentials.
  • Sketch out cryptocurrency fraud operational planning downstream of the intrusions.

We are not reproducing prompts or command outputs from the write-up. Read Trend Micro’s post if you need that level of detail — link below. Confidence, per-item: as-reported by Trend Micro, sourced to the 200-session log corpus they analyzed.

Downstream campaign

Trend Micro links this activity to the “Patriot Bait” campaign that surfaced in May 2026, targeting elderly victims in the United States and Canada through phone-based cryptocurrency fraud. Confidence: as-reported, connection asserted by Trend Micro. Attribution beyond “Russian-speaking, sole operator, uses the alias bandcampro” is not stated.

What is not confirmed

  • Google response. Not mentioned in the Trend Micro write-up. Whether Google was notified, whether the account or keys are still active, whether policy enforcement has kicked in: unstated.
  • Whether Gemini CLI enforced any refusal on these prompts, and how consistently. Trend Micro’s analysis is a log-corpus study, not a Google-side telemetry piece. Refusals, if any, are not enumerated. Unstated.
  • Whether “bandcampro” is a sole operator or a persona sitting on top of a team. Trend Micro reports the sessions read as one-operator work. Take that as their read, not as a settled fact. Single-analyst assertion.
  • Second-source confirmation of any specific claim in the write-up. None at time of writing. Unconfirmed.

Why this one matters more than the botnet size suggests

The story a small dental-clinic botnet tells on its own is not much of a story. The story the six-minute end-to-end C2 migration tells is a different one: an operator who does not need to know the details of setting up VPS-hosted C2 infrastructure and Cloudflare tunneling can now stand up, iterate, and move that infrastructure by describing what they want in their first language. The floor on “operationally competent solo actor” is lower than it was six months ago. Defense-side implications:

  • Cloudflare-tunneled C2 to residential and small-business networks was already a hard signal to write clean detections for. It is not getting easier. If your egress visibility ends at “the tunnel came up,” you are not seeing this activity.
  • PowerShell-generated infection chains aren’t new. LLM-generated ones with a fresh coat of syntactic variation every run push signature and near-duplicate detections harder. Behavior-based coverage is where this lives.
  • OpenDental-class SMB verticals — small healthcare, small law, small municipal — remain the soft targets. A single-operator botnet of eight machines at a clinic is not the ceiling; it is the current, observed floor.

None of this is a Gemini-specific problem. Any capable LLM CLI, hosted or local, exposes the same primitives. Trend Micro’s write-up happens to be about Gemini because that is the log corpus they got.

Sources

Confidence, consolidated: 200-session log analysis and per-task use — as-reported by Trend Micro; botnet size, target, OpenDental access — as-reported; Patriot Bait connection — as-asserted by Trend Micro; attribution beyond language and alias — unstated; Google-side response — unstated; second-source corroboration — none at time of writing.

Found this useful? Share it.