By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hacker Leveraged Google Gemini CLI to Control Botnet

A Russian-speaking hacker, identified as "bandcampro," utilized Google's open-source Gemini Command Line Interface (CLI) to control a botnet comprising eight computers from dental clinics. This operation was discovered through an analysis of 200 Gemini CLI session logs spanning from March 19 to April 21, 2026. The threat actor employed the AI tool for various malicious activities, including password cracking and establishing a residential proxy network.
The investigation, conducted by security researchers, revealed that "bandcampro" leveraged Gemini CLI to automate tasks that would typically require significant manual effort. The botnet's infrastructure was built using compromised machines belonging to dental practices, suggesting a targeted approach to exploit specific types of organizations. The AI's capabilities were instrumental in streamlining the attacker's workflow, enabling them to manage the compromised devices and execute commands remotely.
This incident highlights a new frontier in cybercrime, where sophisticated AI tools are being integrated into the attack chain. The use of Gemini CLI for botnet management demonstrates the growing trend of threat actors adopting advanced technologies to enhance their operational efficiency and evade detection. The analysis of the session logs provided critical insights into the methods employed by "bandcampro," including the specific commands and configurations used to maintain control over the botnet.
The compromised dental clinic PCs were used to create a residential proxy network, which can be exploited for a multitude of illicit purposes, such as masking the origin of further cyberattacks or facilitating fraudulent activities. The researchers noted that the hacker's proficiency in using the Gemini CLI suggests a level of technical expertise that could pose a significant challenge to cybersecurity defenses. The findings underscore the need for continuous monitoring and adaptation of security strategies to counter evolving threat actor methodologies.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.