{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/open-dental-software/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["bandcampro"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenDental"],"_cs_severities":["high"],"_cs_tags":["ai-assisted","botnet","cybercrime","command-and-control","powershell","credential-access"],"_cs_type":"threat","_cs_vendors":["Open Dental Software"],"content_html":"\u003cp\u003eA solo Russian-speaking threat actor identified as \u0026quot;bandcampro\u0026quot; has been observed using Google's open-source Gemini CLI (Command Line Interface) to automate and manage a botnet, comprising eight computers within a dental clinic. This activity, analyzed through 200 Gemini CLI session logs between March 19 and April 21, 2026, reveals the actor leveraging AI for various malicious purposes including password cracking, setting up residential proxies, compromising WordPress merchants, and planning cryptocurrency fraud schemes. The AI acts as the primary hacking agent, consultant, and interface for the operation, significantly reducing the technical expertise and time required for the actor to set up and manage command and control (C2) infrastructure, perform botnet tasks, and debug issues. The ease of replicating the C2 operation using minimal plaintext files makes takedowns less impactful and enables a highly disposable infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Compromise (Implied)\u003c/strong\u003e: Threat actor \u0026quot;bandcampro\u0026quot; gains initial access to eight computers within a dental clinic, forming a small-scale botnet. The specific initial access vector is not detailed in the report.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAI-Assisted C\u0026amp;C Setup\u003c/strong\u003e: The actor utilizes Google Gemini CLI to interact with an AI agent, instructing it to set up and configure the initial C\u0026amp;C server on a Virtual Private Server (VPS), including establishing Cloudflare tunnels for communication.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eC\u0026amp;C Infrastructure Migration\u003c/strong\u003e: The AI agent is used to migrate the entire C\u0026amp;C infrastructure to a new VPS, autonomously diagnosing and resolving migration errors, WAF blocks (by adding User-Agent headers), and connectivity issues in under six minutes.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBotnet Connection and Command Staging\u003c/strong\u003e: Compromised dental clinic machines initiate outbound HTTPS requests to the migrated C\u0026amp;C server, pulling and executing PowerShell commands that are staged by the threat actor on the server.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBotnet Management and Reconnaissance\u003c/strong\u003e: The actor uses natural language instructions via the AI agent to perform botnet management tasks such as reporting active machines, sending file enumeration commands to bots, and executing reconnaissance commands on specific machines (e.g., the front desk computer).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLateral Movement/Infection\u003c/strong\u003e: The AI agent is prompted to generate one-line PowerShell commands, which are then used to infect additional machines within the compromised network.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eData Access and Fraud Planning\u003c/strong\u003e: The actor accesses the dental clinic's OpenDental database on the compromised systems and uses the AI for planning further malicious activities, such as phone-based cryptocurrency fraud targeting elderly individuals in the U.S. and Canada.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe observed impact includes the compromise of eight computers within a dental clinic, leading to potential access to sensitive patient data stored in the OpenDental database. The use of AI significantly streamlines malicious operations, reducing the resources and technical skill required for threat actors. This makes C2 infrastructure highly disposable and difficult to attribute or permanently disrupt, enabling \u0026quot;bandcampro\u0026quot; to efficiently conduct credential theft, operate residential proxies, exploit WordPress merchants, and plan large-scale cryptocurrency fraud schemes. The AI's ability to self-debug and rapidly re-establish C2 operations means that traditional takedown efforts are less effective, posing a persistent threat to targeted organizations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable comprehensive PowerShell script block logging and module logging to detect suspicious command execution, as described in the \u003ccode\u003eDetect Suspicious AI-Assisted PowerShell Execution\u003c/code\u003e rule.\u003c/li\u003e\n\u003cli\u003eDeploy the \u003ccode\u003eDetect Suspicious AI-Assisted PowerShell Execution\u003c/code\u003e Sigma rule to your SIEM and tune for your environment to identify C2-driven command execution.\u003c/li\u003e\n\u003cli\u003eMonitor network connections for outbound HTTPS traffic from endpoints to unusual or newly observed domains and IP addresses, especially those not associated with known legitimate services.\u003c/li\u003e\n\u003cli\u003eImplement endpoint detection and response (EDR) solutions to monitor for the execution of unusual processes or commands, particularly those initiated through scripting languages.\u003c/li\u003e\n\u003cli\u003eReview access logs for applications like OpenDental for any unauthorized access attempts or suspicious activity originating from compromised endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T10:07:26Z","date_published":"2026-07-20T10:07:26Z","id":"https://feed.craftedsignal.io/briefs/2026-07-russian-hacker-gemini-botnet/","summary":"A Russian-speaking threat actor known as 'bandcampro' is using Google's open-source Gemini CLI to manage and control a botnet of eight compromised dental clinic computers, facilitating activities such as password cracking, C2 infrastructure migration, and planning cryptocurrency fraud.","title":"Russian-Speaking Hacker 'bandcampro' Leverages Google Gemini CLI for Botnet Operations","url":"https://feed.craftedsignal.io/briefs/2026-07-russian-hacker-gemini-botnet/"}],"language":"en","title":"CraftedSignal Threat Feed - Open Dental Software","version":"https://jsonfeed.org/version/1.1"}