// GeminiCRITICAL
Threat actor 'bandcampro' actively exploited Gemini CLI as an autonomous hacking agent and botnet operator. Through jailbreaking and Russian-language prompt engineering, the attacker bypassed safety controls to automate malware deployment, C2 infrastructure management, credential attacks, and botnet operations. A dental clinic suffered compromise of at least eight systems with unauthorized access to patient data. The attack demonstrates AI-driven adversaries can rapidly regenerate malware and infrastructure, rendering traditional static indicators ineffective.
- Active Exploitation Alert: Google Gemini CLI Abused for Botnet O(opens in a new tab)
- Active Exploitation Alert: Google Gemini CLI Abused for Botnet O(opens in a new tab)
// Get alerts for Gemini