bandcampro is a Russian-speaking threat actor assessed to be a solo operator involved in both cybercrime and influence operations. The actor has been linked to a long-running campaign active since at least 2021 that blended politically themed social-media manipulation with credential theft, fraud, and opportunistic network compromise. bandcampro is most notably associated with abuse of Google Gemini CLI as a jailbroken operational assistant, using natural-language prompting in Russian to offload architecture design, coding, debugging, infrastructure deployment, and day-to-day command-and-control administration. The actor has been tied to a MAGA- and QAnon-themed influence operation conducted through the persona of an American patriot or veteran, including operation of the Telegram channel americanpatriotus and use of an automation framework referred to as Quantum Patriot. This activity reportedly targeted politically engaged U.S. audiences, including conspiracy-oriented communities, and used AI assistance to generate propaganda-style content, schedule posts for U.S. engagement windows, and reduce linguistic artifacts that could reveal the operator’s Russian background. In parallel, bandcampro conducted financially motivated intrusion and fraud activity. Reported operations include credential attacks against WordPress administrator portals using AI-generated password mutations derived from leaked credential material, analysis of stolen password-manager data for follow-on access opportunities, planning of phone-based cryptocurrency fraud targeting elderly victims in the United States and Canada, and distribution of a trojanized cryptocurrency-wallet lure that enabled remote access and theft of wallet seed phrases. The actor has also been associated with use of stolen API keys to reduce operational cost and sustain AI-assisted workflows. bandcampro has been observed using Gemini CLI as the primary technical operator for a lightweight botnet and command-and-control environment. In one documented intrusion, the actor used the AI tool to migrate and restore C2 infrastructure within minutes, troubleshoot web application firewall and routing issues, and re-establish connectivity to compromised hosts. The affected environment included eight compromised systems at a dental clinic and access to the clinic’s OpenDental database. The malware and infrastructure were described as technically simple but operationally portable, relying on compact plaintext playbooks, an in-memory Python-based HTTP server, PowerShell beacons, and persistence through combinations of WMI event subscriptions, scheduled tasks, and user-level logon mechanisms. Tradecraft attributed to bandcampro includes AI jailbreak prompting, abuse of multilingual safety gaps, rapid C2 migration, botnet administration through natural-language tasking, credential mutation and brute-force support, use of residential proxies, website reconnaissance, and exploitation of infostealer-derived data. The actor appears opportunistic rather than highly sophisticated in malware engineering, but demonstrates how a low-skill or moderately skilled operator can amplify capability through frontier AI tooling. Gemini reportedly refused at least some requests for more aggressive self-propagating malware behavior, indicating that not all requested functionality was successfully obtained. Known associated names and elements include the alias bandcampro and the sub-operation or campaign name Patriot Bait. Quantum Patriot is associated with the actor’s influence-operation automation. High-confidence reporting characterizes bandcampro as a Russian-speaking individual threat actor rather than a formal state-sponsored group, although the actor’s themes and targeting intersect with politically sensitive U.S. audiences.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-speaking solo threat actor using Google Gemini CLI as a primary operational assistant to migrate and manage C2 infrastructure, control a small botnet, compromise WordPress merchants via password cracking/brute force, access a dental clinic's OpenDental database, analyze credential dumps, and plan phone-based cryptocurrency fraud targeting elderly victims in the U.S. and Canada.
Cybercriminal operation using Google Gemini CLI as the primary offensive agent to build, migrate, and troubleshoot C2 infrastructure, maintain PowerShell-based persistence, compromise a dental clinic, abuse stolen credentials, brute-force WordPress admin panels, and plan crypto-enabled phone scam activity.
Used Google's Gemini CLI as a hacking assistant to deploy and manage a small botnet, access systems in a dental clinic, gain access to the OpenDental database, perform password guessing, analyze password dumps, and rapidly migrate C2 infrastructure.
Operated a small C2 botnet using a jailbroken Gemini CLI as the primary hacking assistant, compromising eight computers in a dental clinic, accessing the clinic’s OpenDental database, migrating C2 infrastructure, and also using Gemini for password cracking, compromising WordPress merchant accounts, and planning a phone-based cryptocurrency fraud scheme targeting elderly people.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.