Skip to content
AI Security Wire

russia

img of Bandcampro: Jailbroken Gemini CLI Ran a 34-Day Criminal Botnet
8 min read
Incident Reports

Between March 19 and April 21, 2026, a Russian-speaking threat actor used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure targeting a dental clinic. The AI performed 89% of the operational work. Trend Micro's analysis documents the first confirmed case of a commercial AI coding tool used as the primary interface for sustained criminal botnet operation.