Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Trend Micro researchers analyzed 200+ Gemini CLI session logs from a Russian-speaking threat actor ('bandcampro') who used Google Gemini CLI to build, deploy, and operate a live C&C botnet targeting a dental clinic. The actor migrated the entire botnet infrastructure in six minutes, contributing only 11% of the text while AI handled 89% — including architecture, coding, deployment, debugging, and 59 unprompted improvement suggestions. The full C&C operation fits in three plain-text files (~5KB), making it trivially portable and disposable. Beyond the botnet, the actor used AI for password cracking, credential exploitation, and planning cryptocurrency fraud targeting elderly victims. The report details the technical implementation (PowerShell beacons, WMI persistence, Cloudflare tunnels) and provides behavioral detection guidance, emphasizing that static IOC-based defenses are insufficient against adversaries who can regenerate artifacts on demand with AI.