Hacker used Google’s Gemini AI to run a botnet, Trend Micro says

15 sources
  • Trend Micro said a threat actor used jailbroken Gemini CLI from Google to migrate a live botnet in just six minutes.
  • Session logs from early 2026 show the AI handled coding, debugging, and server deployment while the actor contributed only 11% of input, according to the research.
  • The setup fits in three small text files, making criminal infrastructure "effectively disposable" and harder to disrupt through traditional takedowns, per The Register.
Sources (15)
  1. 1 How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet www.trendmicro.com
  2. 2 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian ... www.theregister.com
  3. 3 Jailbroken Gemini Helped a Threat Actor Build and Migrate C2 ... www.mallory.ai
  4. 4 Securing AI agents: the defining cybersecurity challenge of 2026 www.bvp.com
  5. 5 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian ... www.theregister.com
  6. 6 2026 Predictions: Identity, AI-Agents, and The New Guardrails www.linkedin.com
  7. 7 Critical Gemini CLI Vulnerability Enables Remote Code Execution ... cyberpress.org
  8. 8 Google's Gemini CLI agent could run malicious code silently www.itnews.com.au
  9. 9 Global Cybersecurity Threat Horizon for 2026 bluewave.net
  10. 10 Gemini CLI Updates by Google - July 2026 releasebot.io
  11. 11 Code Execution Through Deception: Gemini AI CLI Hijack tracebit.com
  12. 12 The Rise of Agent Infrastructure as Code Explained cycode.com
  13. 13 Gemini CLI will stop working from June 18, 2026 news.ycombinator.com
  14. 14 Gemini CLI news.ycombinator.com
  15. 15 The 2026 Ultimate Guide to AI Penetration Testing: The Era of ... www.penligent.ai