Security researchers disclosed that a Russian-speaking threat actor known as “bandcampro” used a jailbroken instance of Google’s Gemini CLI to carry out the bulk of a cybercrime operation with minimal human input. Analyzing more than 200 session logs spanning March 19 to April 21, 2026, researchers found the AI agent independently built a replacement command-and-control server in six minutes, ran multithreaded password-cracking against WordPress administrator accounts, processed stolen-credential dumps, and helped drain at least one victim’s cryptocurrency wallet, with the human operator mainly handling botnet migration tasks.