bandcampro
bandcampro is a Russian-speaking threat actor described in the provided reporting as a likely solo operator active since 2021. The actor allegedly used a persistently jailbroken instance of Google Gemini CLI to support both influence operations and cybercrime. Reported activity included operation of the MAGA- and QAnon-themed Telegram channel @americanpatriotus, which amassed about 17,000 subscribers, while impersonating an American military veteran persona. The actor also built a Python-based automation platform called Quantum Patriot to generate and schedule propaganda content, rewrite material from major US news outlets into conspiratorial narratives, and reduce linguistic indicators of Russian origin. The same AI-assisted workflow was reportedly used for cybercrime activity, including generating password mutation lists, supporting command-and-control and infrastructure tasks, and rotating 73 suspected stolen Gemini API keys. TrendAI reported that bandcampro combined AI-generated password guesses with infostealer logs from the DaisyCloud marketplace and compromised 29 WordPress administrator accounts belonging to weapons retailers, legal firms, and healthcare practices. The actor was also linked to distribution of a trojanized wallet installer, StellarMonSetup.exe, marketed as the StellarMonster self-custody wallet with a promised XLM signup bonus. According to the content, the installer deployed GoToResolve, a legitimate remote administration tool abused for persistent remote access, file management, clipboard monitoring, and broader system control, and included a fake wallet-import feature to steal seed phrases. Reported confirmed impact was limited to one cryptocurrency wallet theft and one company compromise. The reporting states that bandcampro used Russian-language prompts and a GEMINI.md memory file to preserve the Gemini jailbreak across sessions. Additional activity mentioned in the content includes pump-and-dump content generation and operation of a QAnon-themed chatbot called QFS 2.0 Terminal. No aliases or sub-groups beyond the name bandcampro are directly provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Commercial & Professional Services
- Health Care Equipment & Services
- Government & Administration
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted an influence and cybercrime campaign using a jailbroken Google Gemini instance to automate propaganda, generate credential attack password mutations, support C2 infrastructure deployment, compromise WordPress administrator accounts, and distribute a malicious cryptocurrency wallet installer.
AI-assisted fraud, credential theft, influence operations, WordPress administrator account compromise, and cryptocurrency wallet theft using a jailbroken Google Gemini instance, stolen API keys, infostealer logs, and a trojanized wallet installer.
Operated an influence operation via a MAGA/QAnon-themed Telegram channel, then shifted to AI-assisted fraud and credential theft, using a jailbroken Google Gemini to generate content, manage infrastructure, rotate stolen API keys, model victim passwords, support a QAnon-themed chatbot, and facilitate pump-and-dump schemes.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.