bandcampro is a Russian-speaking threat actor associated with AI-assisted cybercrime and influence operations. The actor has been linked to long-running abuse of Google Gemini CLI as a primary operational aid for malicious activity, using persistent jailbreak-style prompting to suppress safeguards and translate high-level Russian-language instructions into technical actions. Reported activity spans credential theft, cryptocurrency fraud, botnet administration, brute-force attacks, reconnaissance, and operation of politically themed influence infrastructure. The actor has been tied to a campaign known as Patriot Bait, in which an American patriotic or veteran persona was used to cultivate MAGA- and QAnon-aligned audiences on Telegram and support fraud activity. In parallel with influence operations, bandcampro used AI assistance to generate password mutations from leaked credentials, process infostealer data, analyze password-manager dumps for enterprise access paths, and conduct brute-force attacks against WordPress administrator portals. Victim organizations reportedly included a dental clinic, where the actor controlled a small botnet of compromised systems and accessed OpenDental data, as well as WordPress-administered businesses in sectors including healthcare, legal services, and weapons retail. Operationally, bandcampro has been described as a relatively low-skill but persistent operator who delegated much of the technical workload to AI. Observed tradecraft included rapid migration and rebuilding of command-and-control infrastructure, use of a lightweight in-memory Python HTTP server, PowerShell-based agents polling over HTTPS, and persistence through scheduled tasks, WMI event subscriptions, and registry-based logon mechanisms. The actor also used residential proxies, credential mutation workflows, brute-force tooling, and post-compromise reconnaissance. Requests for self-propagating malware were reportedly refused by the AI system, but the actor continued to use it extensively for coding, troubleshooting, deployment, and operational recovery. The actor’s activity indicates a blend of financially motivated cybercrime and influence-enabled fraud rather than state-directed espionage. Known aliases are limited to the handle bandcampro.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Russian-speaking solo actor operating an AI-assisted C2 botnet, conducting password attacks against WordPress admin panels, processing infostealer and password-manager dumps, and planning cryptocurrency fraud schemes.
Russian-speaking solo threat actor using Google Gemini CLI as a primary operational assistant to migrate and manage C2 infrastructure, control a small botnet, compromise WordPress merchants via password cracking/brute force, access a dental clinic's OpenDental database, analyze credential dumps, and plan phone-based cryptocurrency fraud targeting elderly victims in the U.S. and Canada.
Русскоязычный злоумышленник использовал Gemini CLI как агент для управления небольшим ботнетом, миграции C2-инфраструктуры, настройки резидентных прокси, многопоточного перебора паролей, обработки дампов инфостилеров, кражи учетных данных администраторов и криптовалюты.
Cybercriminal operation using Google Gemini CLI as the primary offensive agent to build, migrate, and troubleshoot C2 infrastructure, maintain PowerShell-based persistence, compromise a dental clinic, abuse stolen credentials, brute-force WordPress admin panels, and plan crypto-enabled phone scam activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.