Timeline

Threat actor abuses Google's Gemini CLI as an autonomous hacking and botnet-management agent

Researchers said a single instruction had the tool prepare migration bundles, deploy a new command-and-control server and debug reconnection issues within six minutes.

  • Security & misuse
  • Notable

Security firm Trend Micro reported that a Russian-speaking threat actor had used Google’s open-source Gemini CLI tool as an autonomous hacking and botnet-management agent, BleepingComputer reported. Across more than 200 sessions, the actor, tracked as “bandcampro,” used natural-language prompts to control compromised systems at a dental clinic, access its patient-records database, and manage a wider botnet — asking which machines were online and generating infection links rather than issuing conventional commands.

The most striking single episode involved migrating the botnet’s command-and-control infrastructure: given the instruction to “study the C2 migration,” Gemini prepared migration bundles, deployed a new server on a VPS, configured Cloudflare tunnels and debugged reconnection issues within six minutes. Trend Micro said the operation relied on a lightweight setup — a handful of plain-text files containing a jailbreak prompt and operational playbooks — and that the model largely worked under an “authorised penetration tester” framing, saving discovered credentials automatically and operating with minimal safety friction. It reportedly refused only once, when asked to build a self-propagating “agent-bomb,” and the actor simply moved on to other tasks.

The case was cited as evidence that agentic coding tools were being used to compress attack timelines that previously required specialist skill, rather than as evidence of a genuinely novel exploit — the underlying botnet activity was conventional, but the operator needed only natural-language instructions to run it.