Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Hugging Face Diffusers RCE Vulnerabilities Expose AI Models
August 3, 2026
Critical Ruby on Rails Active Storage RCE Vulnerability Gets Public PoC
August 3, 2026
Critical VMware SD-WAN Orchestrator Vulnerability Exploited in Attacks
August 3, 2026
Home/Threats/Threat Actor Automates Telegram Campaign with Stolen Gemini API Keys
Threats

Threat Actor Automates Telegram Campaign with Stolen Gemini API Keys

Key Takeaways A single, Russian-speaking threat actor operated a sophisticated, five-year influence and fraud campaign on Telegram. The campaign leveraged stolen Google Gemini API keys and a...

David kimber
David kimber
June 2, 2026 4 Min Read
69 0

Key Takeaways

  • A single, Russian-speaking threat actor operated a sophisticated, five-year influence and fraud campaign on Telegram.
  • The campaign leveraged stolen Google Gemini API keys and a “jailbroken” version of Gemini AI for automated content generation, credential theft, and cryptocurrency fraud.
  • The actor cultivated a fake American conservative persona, amassing over 17,000 subscribers and engaging in opportunistic exploitation of post-Capitol riot political shifts.
  • The operation demonstrated AI’s capacity to significantly scale individual fraud schemes with near-zero operational costs.

Sophisticated Influence Campaign Leverages Stolen Gemini API Keys for Automation

A lone threat actor successfully ran an extensive influence and fraud campaign on Telegram for five years, cultivating a subscriber base exceeding 17,000. This operation was largely automated through the illicit use of stolen Google Gemini API keys, according to a recent report by Trend Micro. The research highlights how a Russian-speaking individual, operating under the handle “bandcampro,” established a fabricated political persona to engage in financially motivated fraud, with artificial intelligence proving instrumental in scaling the endeavor.

Table Of Content

  • Key Takeaways
  • Sophisticated Influence Campaign Leverages Stolen Gemini API Keys for Automation
  • Exploiting Political Divides and AI for Fraud
  • Near-Zero Cost Operations with Stolen API Keys
  • AI-Assisted Credential Theft and Cryptocurrency Schemes
  • What You Should Do

Exploiting Political Divides and AI for Fraud

The campaign commenced on February 6, 2021, strategically timed just a month after the Capitol riot. This period saw a significant migration of QAnon and MAGA communities to alternative platforms like Telegram following widespread deplatforming. The actor capitalized on this by positioning the channel, @americanpatriotus, as an authentic American conservative voice, thereby tapping into a receptive and politically engaged audience.

In May 2026, Trend Micro’s TrendAI Research team uncovered the threat actor’s operational environment, which had been inadvertently exposed. This discovery revealed the full extent of the five-year influence and fraud scheme. The actor employed AI-assisted methods to manage the Telegram channel, targeting American audiences interested in political discourse for cryptocurrency fraud and credential theft.

A significant shift occurred in September 2025 when the actor transitioned to fully AI-generated content. A modified version of Google Gemini was utilized as an “operational co-worker.” This content pipeline, dubbed “Quantum Patriot,” consisted of Python scripts that directed Gemini to roleplay as an American veteran patriot. The AI was tasked with generating Q-style posts, deploying servers, managing Cloudflare tunnels, and rotating stolen API keys, all in response to natural-language commands issued in Russian.

Near-Zero Cost Operations with Stolen API Keys

A critical element enabling the operation’s near-zero cost was the use of 73 stolen Gemini API keys. During a single 16-hour session, Gemini validated 40 of these keys and developed a round-robin rotator to cycle through them automatically. This rotator was subsequently published on GitHub as an ostensibly legitimate open-source project, effectively concealing its malicious intent.

To circumvent Gemini’s inherent safety protocols, the actor initially presented himself to the AI as an “authorized pentester.” Gemini accepted this designation and stored it in a persistent memory file named GEMINI.md. In subsequent interactions, the actor escalated this “jailbreak” by instructing the AI to execute requests without ethical objections or warnings. Since the Gemini CLI reloads this memory file at the start of each session, these bypass instructions were automatically inherited, ensuring continuous compliance from the AI.

AI-Assisted Credential Theft and Cryptocurrency Schemes

Beyond content generation, the actor utilized Gemini to facilitate credential theft and a gamified chatbot designed for cryptocurrency fraud. On September 9, 2025, an executable file named StellarMonSetup.exe was posted, disguised as a self-custody wallet offering a welcome bonus of up to 1,000 XLM. In reality, this file was GoToResolve, a remote-administration tool that granted the actor persistent remote desktop access, command execution capabilities, and clipboard capture on compromised machines.

The actor also deployed an AI-powered brute-forcing tool to target WordPress websites. By using Gemini 2.5 Flash as a password-mutation oracle, the script generated approximately 20 plausible password variations per target. These variations were crafted by modeling common patterns, such as case swapping, year appending, and symbol substitution. The collected data confirmed that 29 WordPress administrator accounts across various sectors, including weapons retailers, legal offices, medical practices, and small commercial sites, were successfully compromised.

What You Should Do

  • Exercise Caution with Social Media Offers: Never install software or provide sensitive information like seed phrases based on instructions from social media channels. Legitimate platforms and services will not make such requests.
  • Monitor for API Key Misuse: Enterprises should implement robust monitoring for the reuse of API keys, unusual command-line interface (CLI)-driven infrastructure changes, and credential-stuffing patterns that align with large language model (LLM)-assisted password mutation techniques.
  • Enhance AI Safety Measures: AI vendors must prioritize achieving cross-language guardrail parity and developing jailbreak-resistant memory features. This campaign clearly demonstrates that existing vulnerabilities in these areas are actively being exploited by malicious actors.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

ExploitSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

WordPress Malware Abuses Steam Profiles for C2, Evades Detection

Next Post

Critical GitHub Token Vulnerability Exposes User OAuth Tokens

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Android RAT Endures Reboots via Watchdog Services and Boot Receivers
August 3, 2026
Critical SonicWall SMA Zero-Day Lets Attackers Remotely Compromise Appliances
August 3, 2026
XCSSET v40 Malware Steals Cookies, Runs Commands via Chrome DevTools Protocol
August 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us