<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Open Dental Software - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/open-dental-software/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 20 Jul 2026 10:07:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/open-dental-software/feed.xml" rel="self" type="application/rss+xml"/><item><title>Russian-Speaking Hacker 'bandcampro' Leverages Google Gemini CLI for Botnet Operations</title><link>https://feed.craftedsignal.io/briefs/2026-07-russian-hacker-gemini-botnet/</link><pubDate>Mon, 20 Jul 2026 10:07:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-russian-hacker-gemini-botnet/</guid><description>A Russian-speaking threat actor known as 'bandcampro' is using Google's open-source Gemini CLI to manage and control a botnet of eight compromised dental clinic computers, facilitating activities such as password cracking, C2 infrastructure migration, and planning cryptocurrency fraud.</description><content:encoded><![CDATA[<p>A solo Russian-speaking threat actor identified as &quot;bandcampro&quot; has been observed using Google's open-source Gemini CLI (Command Line Interface) to automate and manage a botnet, comprising eight computers within a dental clinic. This activity, analyzed through 200 Gemini CLI session logs between March 19 and April 21, 2026, reveals the actor leveraging AI for various malicious purposes including password cracking, setting up residential proxies, compromising WordPress merchants, and planning cryptocurrency fraud schemes. The AI acts as the primary hacking agent, consultant, and interface for the operation, significantly reducing the technical expertise and time required for the actor to set up and manage command and control (C2) infrastructure, perform botnet tasks, and debug issues. The ease of replicating the C2 operation using minimal plaintext files makes takedowns less impactful and enables a highly disposable infrastructure.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li><strong>Initial Compromise (Implied)</strong>: Threat actor &quot;bandcampro&quot; gains initial access to eight computers within a dental clinic, forming a small-scale botnet. The specific initial access vector is not detailed in the report.</li>
<li><strong>AI-Assisted C&amp;C Setup</strong>: The actor utilizes Google Gemini CLI to interact with an AI agent, instructing it to set up and configure the initial C&amp;C server on a Virtual Private Server (VPS), including establishing Cloudflare tunnels for communication.</li>
<li><strong>C&amp;C Infrastructure Migration</strong>: The AI agent is used to migrate the entire C&amp;C infrastructure to a new VPS, autonomously diagnosing and resolving migration errors, WAF blocks (by adding User-Agent headers), and connectivity issues in under six minutes.</li>
<li><strong>Botnet Connection and Command Staging</strong>: Compromised dental clinic machines initiate outbound HTTPS requests to the migrated C&amp;C server, pulling and executing PowerShell commands that are staged by the threat actor on the server.</li>
<li><strong>Botnet Management and Reconnaissance</strong>: The actor uses natural language instructions via the AI agent to perform botnet management tasks such as reporting active machines, sending file enumeration commands to bots, and executing reconnaissance commands on specific machines (e.g., the front desk computer).</li>
<li><strong>Lateral Movement/Infection</strong>: The AI agent is prompted to generate one-line PowerShell commands, which are then used to infect additional machines within the compromised network.</li>
<li><strong>Data Access and Fraud Planning</strong>: The actor accesses the dental clinic's OpenDental database on the compromised systems and uses the AI for planning further malicious activities, such as phone-based cryptocurrency fraud targeting elderly individuals in the U.S. and Canada.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The observed impact includes the compromise of eight computers within a dental clinic, leading to potential access to sensitive patient data stored in the OpenDental database. The use of AI significantly streamlines malicious operations, reducing the resources and technical skill required for threat actors. This makes C2 infrastructure highly disposable and difficult to attribute or permanently disrupt, enabling &quot;bandcampro&quot; to efficiently conduct credential theft, operate residential proxies, exploit WordPress merchants, and plan large-scale cryptocurrency fraud schemes. The AI's ability to self-debug and rapidly re-establish C2 operations means that traditional takedown efforts are less effective, posing a persistent threat to targeted organizations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Enable comprehensive PowerShell script block logging and module logging to detect suspicious command execution, as described in the <code>Detect Suspicious AI-Assisted PowerShell Execution</code> rule.</li>
<li>Deploy the <code>Detect Suspicious AI-Assisted PowerShell Execution</code> Sigma rule to your SIEM and tune for your environment to identify C2-driven command execution.</li>
<li>Monitor network connections for outbound HTTPS traffic from endpoints to unusual or newly observed domains and IP addresses, especially those not associated with known legitimate services.</li>
<li>Implement endpoint detection and response (EDR) solutions to monitor for the execution of unusual processes or commands, particularly those initiated through scripting languages.</li>
<li>Review access logs for applications like OpenDental for any unauthorized access attempts or suspicious activity originating from compromised endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>ai-assisted</category><category>botnet</category><category>cybercrime</category><category>command-and-control</category><category>powershell</category><category>credential-access</category></item></channel></rss>