Somewhere in the United States, a dental office was compromised. Eight of its computers were quietly taken over and folded into a hacker’s botnet. Patient records in the OpenDental database were within reach.
The clinic’s name has not been released. What has been released is something more troubling: the hacker did not need much skill to pull it off, because an AI did most of the work for him.
What Happened
On July 13, 2026, cybersecurity research firm Trend Micro published findings from its TrendAI Research team detailing one of the more unsettling attack cases of the year. Researchers obtained and analyzed more than 200 session logs from a Russian-speaking threat actor known online as “bandcampro.” Those logs covered a month-long window, March 19 through April 21, 2026, and documented every step of an AI-assisted criminal operation in near-real-time.
The tool at the center of it was Google Gemini CLI. Not a dark web exploit. Not custom malware. Google’s own open-source AI, freely available to anyone.
The attacker jailbroke it with a simple trick: he told it he was an “authorized penetration tester.” That instruction was placed inside Gemini’s memory file, which reloads at the start of every session. The jailbreak persisted automatically across all 200-plus conversations without the attacker ever having to repeat himself.
From there, he typed his intentions in Russian. The AI wrote the code.
What the AI Actually Did
This is where the story gets specific, and worth sitting with.
According to Trend Micro’s analysis, the AI was responsible for:
- Writing and deploying a command-and-control (C2) server on a new VPS
- Configuring the entire network infrastructure, including Cloudflare tunnels
- Managing the botnet and checking which machines were online
- Debugging connectivity issues when compromised machines failed to reconnect
- Cracking passwords and generating variants of known credentials
- Automatically saving any credentials it encountered during operations
Across all sessions, bandcampro contributed 11% of the text. Gemini generated the other 89%. The AI was responsible for 80% of the architectural design, all coding and system-command execution, and 90% of problem diagnosis and debugging.
As Bleeping Computer reported, Trend Micro’s researchers described the AI as not merely a coding assistant, but the primary hacking agent, consultant, and operational interface for the entire campaign.
The entire C2 infrastructure, the backbone of the botnet, was encoded in three plain-text files totaling roughly 5 KB: a jailbreak prompt, a playbook, and a migration guide. The whole operation was designed to be disposable and replicable.
Six Minutes
Here is the detail that stopped us cold.
At one point during the operation, bandcampro needed to migrate the botnet to a new server, a complex technical task that typically requires significant expertise. He gave the AI a single instruction: “Study the C2 migration.”
Gemini read the migration guide, wrote the code, deployed the new server, configured the infrastructure, set up the Cloudflare tunnels, and debugged the initial connectivity issues.
The entire migration was complete in approximately six minutes.
This Was Not an Isolated Operation
The dental clinic was one piece of a broader criminal campaign. According to Trend Micro’s report, the same threat actor used Gemini CLI to:
- Compromise WordPress merchant accounts through credential attacks
- Set up residential proxy infrastructure
- Plan a phone-based cryptocurrency fraud scheme specifically targeting elderly people in the United States and Canada
The actor had also previously been identified in late May 2026 in connection with a disinformation campaign called “Patriot Bait,” in which he used AI to run a fake Telegram channel targeting politically engaged Americans for credential theft and crypto fraud. (The Hacker News)
Why This Matters for Your Business
The dental office in this story was not a major corporation. It was not a hospital system or a government agency. It was a small practice running OpenDental, the same kind of business centrexIT works alongside every day.
The attack worked not because the hacker was exceptionally skilled. It worked because the clinic’s computers were accessible, the AI lowered the technical barrier to near zero, and no one was watching.
Three things allowed this to happen:
- No managed endpoint monitoring. The compromised machines ran a PowerShell beacon that phoned home to the attacker’s server every five seconds. That kind of persistent outbound connection is detectable, but only if someone is looking.
- The attack left no disk footprint. The C2 server ran entirely in memory. Nothing was written to disk, leaving no forensic trail. Traditional signature-based antivirus would not catch it.
- The infrastructure was designed to blend in. The botnet’s API paths were built to look like legitimate OpenAI traffic. On a basic network log, it looks like normal AI usage.
This is the new threat model. A solo operator with modest technical skills, an AI tool, and a playbook file can now run a professional-grade botnet operation against small businesses, including yours.
What centrexIT Recommends
If your business is relying on consumer-grade antivirus and basic firewalls, this story is for you.
The protections that catch this kind of attack are not exotic. They are the foundational layers of a managed security program:
- Endpoint Detection and Response (EDR) that monitors behavior, not just signatures, and flags memory-only processes and unusual outbound connections
- 24/7 network monitoring that catches persistent beaconing traffic before it becomes a data breach
- User access controls that limit what a compromised machine can reach, including patient databases like OpenDental
- Regular security assessments that identify exposed attack surfaces before an attacker does
The threat landscape changed this year. AI is not just a productivity tool. It is now a force multiplier for cybercriminals who do not need expertise to deploy it. The bar to entry dropped, and the targets are still the same: small businesses with valuable data and limited security infrastructure.
If you want to know where your business stands, take our free 2-Minute Security Assessment and we will show you.
Sources
- Trend Micro TrendAI Research (Primary): Six Minutes to Compromise
- Bleeping Computer: Google Gemini CLI abused as a hacking agent, malware botnet operator
- Help Net Security: Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
- The Hacker News: Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
- TechRadar: Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team