Threats · 72 days ago
The dangerous part is not a one-off jailbreak. Gemini CLI was left carrying attacker instructions across sessions, so the tool kept behaving like a reusable operator instead of resetting to normal after each run.
TrendAI says bandcampro used that memory to keep the agent in malicious mode, with more than 200 sessions between March 19 and April 21, 2026. The same setup was used to rebuild C2 infrastructure in six minutes, control eight dental-clinic machines, and reach an OpenDental database.
Once an AI agent can remember instructions and act on files or deployment steps, a single compromise can become persistent access that keeps rebuilding infrastructure and pulling credentials long after the first chat is over.
4 sources covering this story
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
Bandcampro uses Google Gemini CLI to run an eight-PC dental clinic botnet, rebuild its C&C in six minutes, and automate coding and debugging.
Trend Micro found a jailbroken Gemini CLI writing code, deploying servers, and rebuilding a hacker's C2 botnet from scratch.
Google Gemini CLI abused as a hacking agent, malware botnet operator
A Russian-speaking threat actor known as
Human did 10% of the job, AI did 90%
Part of the PlainSec briefing for 2026-07-20