Six Minutes To Compromise: How 'Patriot Bait' Actor Used AI To Build And Deploy a C&C Botnet
Trend Micro, Tuesday, July 14th, 2026
Trend Micro analyzed 200 Gemini CLI session logs showing a Russian-speaking actor let AI do 89% of the work building a live botnet.
Trend Micro analyzed roughly 200 Google Gemini CLI session logs from a Russian-speaking threat actor tracked as 'bandcampro', covering daily AI-assisted operations from March 19 to April 21, 2026.
The logs show the AI acting as primary operator rather than coding helper: it wrote the command-and-control server, deployed it to a new VPS, configured Cloudflare tunnels, managed bots and debugged connectivity, completing a full C&C migration in about six minutes.
The actor controlled eight machines in a dental clinic and reached their OpenDental database, and also used AI to crack passwords and compromise WordPress merchants.
Although he jailbroke the model repeatedly, guardrails still fired on some requests, and the logs show him abandoning those tasks.