Shady Transactions With a Tech Angle
An individual threat actor fluent in Russian, employing a jailbroken Google Gemini, orchestrated a scam and credential theft strategy aimed at dedicated Trump supporters and conspiracy theorists. From September 2025 to May 2026, this “low-skilled” miscreant known as bandcampro collaborated with the LLM to impersonate a U.S. veteran, manage a Telegram channel (@americanpatriotus), hack administrator credentials, and pilfer cryptocurrency, as reported by TrendAI.
The Mechanics of the Fraud
His sole “actual expense” during the operation consisted of pilfered API keys. Ultimately, bandcampro accumulated around 17,000 followers, utilized 73 possibly-stolen Gemini API keys, breached 29 WordPress admin credentials, infiltrated at least one organization, and drained at least one victim’s cryptocurrency wallets, according to TrendAI analysts Philippe Lin, Joseph C Chen, Fyodor Yarochkin, and Vladimir Kropotov.
The Growth of AI-Enhanced Tricks
The threat analysts detailed this undertaking in a report released on Thursday, noting that while the Telegram channel has existed for five years, bandcampro’s achievements surged after he began leveraging AI-generated material last autumn. “We have reached a tipping point for cybercrime conspiracies,” Tom Kellermann, TrendAI’s VP of AI security and threat research, shared with GadgetLad, emphasizing that “bandcampro’s conspiracy illustrates the sophistication of the Russian cybercriminal ecosystem and how weaponized jailbroken LLMs are manipulated to conduct a systemic cybercrime operation.”
AI’s Vulnerability: API Breaches
Kellermann remarked that the attack “highlights the vulnerability of LLMs, which face significant risks from API attacks.” TrendAI analysts uncovered the scammers’ infrastructure in May, revealing the complete details of the operator’s environment. He employed Google Gemini to create the text for the Telegram channel and Venice.ai to support an interactive chatbot aimed at simulating a Quantum Financial System (QFS) terminal. Neither Google nor Venice provided responses to GadgetLad’s inquiries for comments.
The Lure for the MAGA Crowd
The campaign specifically targeted the QAnon and MAGA factions, imitating the cryptic, anonymous “Q drop” messages central to the QAnon mythos, but researchers suggest his “implementation of information operation strategies was more likely aimed at cryptocurrency fraud rather than political intentions,” based on the posted content and the common remote access trojan (RAT) used alongside other commercial malware.
The Counterfeit Freedom Wallet
On September 9, 2025, the actor introduced a bogus “freedom-first, self-custody wallet” named StellarMonster, offering a welcome incentive of up to 1,000 XLM (approximately $380) on the Telegram channel. This was an executable file titled StellarMonSetup.exe. Analysis revealed that, in reality, StellarMonSetup.exe is an authentic remote access tool known as GoToResolve, which permits the operator to maintain a continuous remote desktop session with file access, command execution, and clipboard capture. Moreover, any subscribers who utilized the “import your wallet” feature and entered their seed phrase into the phony import interface inadvertently provided the attacker with their wallet keys.
Words That Break
“At least one victim’s crypto-wallet was thoroughly compromised: password cracked, 12-word mnemonic pilfered, and the owner’s 40+ wallet addresses collected across all major blockchains,” the researchers stated. It was also reported that the attacker employed an AI-driven brute-force tool to breach WordPress accounts.
The Script That Understands You Too Well
“The script operates on the assumption that individuals alter familiar base passwords in predictable manners, and Gemini 2.5 Flash can simulate the alterations when fed with static wordlists,” Trend reported. In total, the AI-fueled WordPress hacking initiative compromised 29 administrator accounts, including those owned by arms dealers, law firms, medical practices, and small businesses.
The Quantum Patriot Content Engine
While engaging with Gemini, bandcampro posed inquiries like: “Once the bot gains 5,000 active users, how much profit can we make from one pump-and-dump cycle?” He also sought insights into how professional crypto call centers deceive North American victims, with Gemini suggesting healthcare fraud targeting senior citizens.
Automating the Mayhem
The Russian speaker further automated his content generation process with a system named “Quantum Patriot,” a collection of Python scripts that called upon Gemini to act as an American veteran patriot. The system supplied a predetermined list of news feeds into the LLM, which then reworded them, prompted to behave as an admin of an “American Patriot” channel probing for “hidden angles.”
The Daily Grind of Cybercrime
The thief of credentials and cryptocurrency also utilized Gemini to assist in hacking, establish a command-and-control framework—including an email-testing utility, a Gmail aggregator, and an anonymous proxy on a VM based in the Netherlands—validate credentials, and operate the chatbot.
The Active Bot’s Work Routine
“In the course of one hectic working day, Gemini initiated server deployment, helped troubleshoot code, automated operations, devised a script for rotating API keys, and oversaw the actor’s Cloudflare tunnels,” observed the TrendAI researchers. “The actor prompted in Russian, while the LLM reasoned and responded in English. Over one 16-hour span, the actor collaborated with Gemini in an end-to-end fashion.”
Who Needs Collaboration?
At one point, following a nine-hour break from the human collaborator, which the authors speculate “was likely a 9-hour sleep,” bandcampro discovered the bot posting every 20 minutes without pause, albeit with Russian slang appearing in the English content. He then opened another session to rectify the issue.
A One-Person Tech Circus
“What once relied on a team of writers, social media managers, IT professionals, and malware developers can now be executed by a single individual using a VPS, a Telegram bot, and API access to cutting-edge models,” Trend’s team cautioned.
What’s the Score?
And there you go, everyone. A low-skill opportunist from Russia making use of a hacked Google Gemini to rob MAGA wallets. Who needs a team when you’ve got AI, right? Just a guy, his scripts, and a spot of shady work – well, very shady work indeed. Keep your wallets tightly secured and your API keys even closer! Until next time on GadgetLad.