CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2684

As cited

Copy frozen at (site build).

threat intel

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

A Russian-speaking threat actor named bandcampro leveraged a jailbroken version of Google's Gemini CLI to build and manage botnet command-and-control infrastructure targeting a dental clinic. Over more than 200 sessions between March 19 and April 21, 2026, the attacker deployed malware across eight clinic computers and accessed the OpenDental database, accomplishing botnet reconstruction in approximately six minutes.

Why it matters: Healthcare organizations and dental practices are exposed to AI-augmented attack automation; practitioners should assume adversaries can now use jailbroken large language models to rapidly rebuild malware infrastructure and should monitor for Gemini CLI abuse and unauthorized terminal-based AI agent activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

Between March 19, 2026 and April 21, 2026, a Russian-speaking actor using the handle "bandcampro" employed a jailbroken Gemini CLI to set up a small command-and-control (C2) network. The actor used this infrastructure to control eight computers in a dental clinic and to access the clinic’s OpenDental database. TrendAI reported that the activity spanned over 200 sessions during the period.

Why it matters: Dental clinics running OpenDental face exposure of patient records if threat actors abuse jailbroken artificial intelligence (AI) agents to create command-and-control (C2) infrastructure; security teams should audit AI tool usage and watch for unexpected command-and-control traffic.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

Between March 19, 2026 and April 21, 2026, a Russian-speaking actor using the handle "bandcampro" employed a jailbroken Gemini CLI to set up a small command-and-control (C2) network. The actor used this infrastructure to control eight computers in a dental clinic and to access the clinic’s OpenDental database. TrendAI reported that the activity spanned over 200 sessions during the period.

Why it matters: Dental clinics running OpenDental face exposure of patient records if threat actors abuse jailbroken artificial intelligence (AI) agents to create command-and-control (C2) infrastructure; security teams should audit AI tool usage and watch for unexpected command-and-control traffic.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary