CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Google Gemini CLI abused as a hacking agent, malware botnet operator

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2614

As cited

Copy frozen at (site build).

threat intel

Google Gemini CLI abused as a hacking agent, malware botnet operator

A Russian-speaking threat actor identified as bandcampro leveraged Google's open-source Gemini CLI tool to conduct hacking activities and operate a botnet infrastructure. The actor demonstrated how the AI tool could be repurposed for malicious purposes including automated exploitation and command execution.

Why it matters: Practitioners managing AI tool deployments and security monitoring should understand that open-source AI interfaces can be misused for botnet operations and automated attacks, requiring additional controls around API access and usage monitoring.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Google Gemini CLI abused as a hacking agent, malware botnet operator

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Google Gemini CLI abused as a hacking agent, malware botnet operator

A Russian-speaking threat actor identified as “bandcampro” repurposed Google’s open-source Gemini CLI as a hacking tool. The actor used the tool to issue commands that compromised systems and recruited them into a modest botnet. Researchers observed the activity and reported the misuse to the project maintainers.

Why it matters: Practitioners who deploy the Gemini CLI should review access controls and monitor for unexpected command execution, as attackers can weaponize the tool to run arbitrary commands and build botnets.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Google Gemini CLI abused as a hacking agent, malware botnet operator

A Russian-speaking threat actor identified as “bandcampro” repurposed Google’s open-source Gemini CLI as a hacking tool. The actor used the tool to issue commands that compromised systems and recruited them into a modest botnet. Researchers observed the activity and reported the misuse to the project maintainers.

Why it matters: Practitioners who deploy the Gemini CLI should review access controls and monitor for unexpected command execution, as attackers can weaponize the tool to run arbitrary commands and build botnets.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary