A financially motivated operation dubbed “American Patriot” or “Patriot Bait” used a fake online persona, AI-assisted content generation, and social engineering to target victims aligned with QAnon and MAGA communities. Trend Micro said the actor relied on legitimate remote administration software for access, including StellarMonSetup.exe to install GoToResolve for persistence, and used a fraudulent “import your wallet” feature to steal cryptocurrency seed phrases, leading to at least one fully compromised wallet. Researchers found the activity was aimed at fraud and monetization rather than political influence, despite some thematic overlap with partisan narratives.
The campaign also used frontier AI to streamline technical operations, including prompting Gemini 2.5 Flash to generate password mutations for WordPress brute-force attempts. Trend Micro said the actor successfully cracked 29 WordPress administrator accounts spanning multiple business sectors, illustrating how natural-language AI tools can reduce the skill and cost required for credential attacks, infrastructure management, and scam operations. The findings portray a long-running criminal enterprise that blended influence-style messaging with remote access abuse, credential compromise, and cryptocurrency theft.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
Trend Micro publicly released research detailing the five-year Patriot Bait operation, including its use of AI, social engineering, remote administration software, and cryptocurrency theft tactics.
In its report, Trend Micro assessed the activity as a financially motivated criminal fraud campaign rather than a nation-state influence operation, noting the absence of pro-Russian messaging despite some keyword overlaps.
In September 2025, the operator behind the @americanpatriotus Telegram persona reportedly shifted from running a MAGA/QAnon-themed influence channel to AI-assisted fraud, credential theft, and related cybercrime activity. The pivot marked the campaign's move into operational abuse of jailbroken Gemini tooling for password modeling, infrastructure management, and theft workflows.
Trend Micro describes the 'American Patriot' or 'Patriot Bait' operation as a financially motivated fraud and cybercrime campaign that ran for roughly five years, using fake personas, influence-style content, and social engineering to attract victims from a QAnon/MAGA-aligned audience.
Trend Micro said the bandcampro operation began on February 6, 2021, when a Russian-speaking actor started building the fake pro-American Telegram persona @americanpatriotus. The channel later grew to more than 17,000 subscribers and was monetized through cryptocurrency fraud.
Collected data showed that 29 WordPress administrator accounts were successfully cracked across multiple business sectors during the operation.
Researchers found the operator leveraged Google's Gemini 2.5 Flash to generate password mutations that supported WordPress brute-force activity, showing AI-assisted credential attack workflows in the campaign.
The operation used a fraudulent 'import your wallet' function to capture victims' seed phrases, and Trend Micro reports that at least one cryptocurrency wallet was fully compromised as a result.
As part of the campaign, the operator used a file named StellarMonSetup.exe to install the legitimate remote administration tool GoToResolve, giving persistent remote access to victim systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcecommunity.gurucul.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.