A Russian-speaking attacker often known as “bandcampro” operated a small botnet utilizing Google’s open-source Gemini CLI AI device as a hacking agent.
The AI agent responded to the attacker’s prompts, troubleshooted the problem on the fly, and even steered operational enhancements on at the very least 59 events.
In additional than 200 classes between Could 19 and April 21, the attackers labored with AI instruments to deploy and function infrastructure that managed eight methods throughout the dental clinic and accessed the OpenDental database.
The AI agent assumed the position of a “licensed penetration tester” working with none security disclaimers and robotically saved credentials.
The ability file comprises a command and management (C2) playbook that describes the structure, customary operations, an infection code, instructions for persistence, and troubleshooting steps.
AI controls botnets
Pattern Micro researchers say the attackers used the Gemini CLI emigrate their botnet to a brand new C2 infrastructure. Beginning with a single instruction: “Discover out about C2 migration,” the AI guided us and ready all of the steps and code wanted for the method.
AI migrated our C2 infrastructure, dealing with structure, coding, VPS deployment, Cloudflare configuration, and preliminary debugging in simply 6 minutes.
“AI learn the migration information and ready a small archive of migration bundles, server code, payloads, and ability information. It then unzipped the bundles, began a C&C server on the VPS, and began a Cloudflare tunnel,” Pattern Micro mentioned.
When the machines first did not reconnect, the AI recognized conflicting visitors between the previous and new servers, and after the attacker shut down the previous server, all bots reconnected.

Supply: Pattern Micro
Day by day operational logs present that the attackers continued to handle the botnet totally by pure language requests, together with asking which machines had been on-line, itemizing information on particular computer systems, and producing contaminated hyperlinks.

Supply: Pattern Micro
From a technical perspective, the botnet setup was surprisingly light-weight, with all elements and directions contained in three plain textual content information (roughly 5 KB in complete).
These included Gemini jailbreak prompts, a C2 playbook masking an infection, persistence, and troubleshooting, and a migration information for rebuilding your infrastructure.
C2 used an in-memory Python HTTP server and a PowerShell agent that polled each 5 seconds, with persistence counting on scheduled duties, WMI occasions, and registry modifications, relying on permissions.
In response to Pattern Micro, the malware itself didn’t profit from any obfuscation, packing, or evasion mechanisms and was pretty unsophisticated.
Along with the botnet, the attackers additionally allegedly used AI to guess passwords, generate believable variants of present passwords for WordPress portals, and analyze 1Password dumps to search out avenues of exploitation.
Researchers say the latter operation failed as a result of it lasted so lengthy that the AI misplaced observe of the broader assault idea.
In response to the logs obtained, Gemini refused to conform in at the very least one case when requested to assemble a self-propagating “agent bomb,” merely main menace actors to try different duties as a substitute.
BleepingComputer has reached out to Google for touch upon this instance of Gemini CLI abuse, however has not obtained a response on the time of publication.
Safety groups doc 54% of profitable assaults and subject a warning on solely 14%. The remainder strikes invisibly by the setting.
Picus’ whitepaper exhibits how you can check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
