{"id":26237,"date":"2026-09-21T16:08:15","date_gmt":"2026-09-22T00:08:15","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet\/"},"modified":"2026-09-21T16:08:15","modified_gmt":"2026-09-22T00:08:15","slug":"six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet\/","title":{"rendered":"Six Minutes to Compromise: How \u2018Patriot Bait\u2019 Actor Used AI to Build and Deploy a C&#038;C Botnet"},"content":{"rendered":"<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1834049907\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\">\n<div class=\"article-details\" role=\"heading\">\n<span class=\"article-details__bar\" role=\"img\"><\/span><\/p>\n<p class=\"article-details__display-tag\">Artificial Intelligence (AI)<\/p>\n<h1 class=\"article-details__title\">Six Minutes to Compromise: How \u2018Patriot Bait\u2019 Actor Used AI to Build and Deploy a C&amp;C Botnet<\/h1>\n<p class=\"article-details__description\">TrendAI\u2122 Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&amp;C migration in six minutes while doing just 11% of the work himself.<\/p>\n<p class=\"article-details__author-by\">By: Joseph C Chen, Philippe Lin, Lucas Silva, Vladimir Kropotov, Fyodor Yarochkin<\/p>\n<p>\t\t\t<time class=\"article-details__date\">Jul 14, 2026<\/time><br \/>\n<span>Read time:\u00a0<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words)\n\t<\/p>\n<div class=\"article-details__icons\">\n<!--Add This--><\/p>\n<div class=\"a2a_kit a2a_default_style\" data-a2a-icon-color=\"#717172\">\n<a class=\"a2a_dd addthis_link\" href=\"https:\/\/www.addtoany.com\/share\"><br \/>\n<img decoding=\"async\" alt=\"Share\" class=\"svg-icon\" src=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/share-more.svg\"\/><br \/>\n<\/a><br \/>\n<a class=\"a2a_button_print addthis_link\"><br \/>\n<img decoding=\"async\" alt=\"Print\" class=\"svg-icon\" src=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/printer.svg\"\/><br \/>\n<\/a>\n<\/div>\n<p><!--Add to Folio--><\/p>\n<div class=\"add-to-folio tooltip\">\n<span class=\"icon-folio-thin\"><\/span><\/p>\n<div class=\"right\">\n<p>Save to Folio<\/p>\n<p><i><\/i>\n<\/div>\n<\/div>\n<p><!--Subscribe--><\/p>\n<div class=\"subscribe\">\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"research-layout-divider\"\/>\n<main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"><\/p>\n<div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><b>Key takeaways:<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">A solo threat actor migrated a live command-and-control botnet in six minutes using AI, where the actor provided intent in plain Russian and AI handled architecture, coding, deployment, and debugging.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Beyond the botnet, the actor used AI to crack passwords, compromise WordPress merchants, and plan a phone-based cryptocurrency fraud scheme targeting elderly people in the US and Canada. The AI was also observed to proactively (unprompted) propose improvements 59 times without being asked.\u00a0<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The entire C&amp;C operation fits in three plain-text files totaling roughly 5KB, making it highly replicable and effectively disposable. Takedowns remain effective but lose impact when attackers can rebuild faster than defenders can respond.<\/span><\/li>\n<\/ul>\n<p>TrendAI\u2122 Research obtained and analyzed 200 Gemini CLI session logs from the Russian-speaking threat actor known as \u201cbandcampro\u201d that provided a month-long window (March 19-April 21, 2026) into the actor&#8217;s daily AI-assisted operations. The logs documented how the threat actor used an AI agent to migrate a command-and-control (C&amp;C) server, and to control a small-scale botnet, among other hacking activities.<\/p>\n<p>The\u202factor\u202fused\u202fGoogle Gemini\u202fCLI to deploy\u202fand operate a\u202fC&amp;C\u202finfrastructure\u202fto control\u202feight computers\u202fin\u202fa dental clinic\u202fand access\u202ftheir\u202fOpenDental database. The AI was not\u202fonly\u202fan assistant that\u202fwrote\u202fcode\u202fsnippets, but\u202falso\u202fthe\u202fprimary\u202fhacking agent,\u202fconsultant,\u202fand\u202finterface\u202fto\u202fthe entire operation: the actor typed\u202fthe\u202fintentions in\u202fRussian, and the AI\u202fwrote the server,\u202fdeployed\u202fit\u202fon a new VPS, configured the infrastructure,\u202fset\u202fup\u202fCloudflare\u202ftunnels,\u202fmanaged the bots, debugged connectivity problems, and even suggested\u202fusing\u202fan idle bot.\u202f<\/p>\n<p><a href=\"\/en_us\/research\/26\/e\/inside-the-influence-and-fraud-patriot-bait-campaign.html\">A previous publication<\/a> from TrendAI\u2122 Research analyzed how \u201cbandcampro\u201d leveraged AI to conduct fraud and social engineering operations for theft of cryptocurrency, an operation that used AI to create a persona, sustain an online community for five years, automate content creation at scale, and exploit these channels.<\/p>\n<p>This report walks through the interaction between the threat actor and the AI agent and explains how this methodology is trivially portable to other threat actors, how the threat landscape has changed with AI, and provide detection guidance for defenders.<\/p>\n<p><span class=\"body-subhead-title\">Prompt: &#8220;Study the C2 migration&#8221;<\/span><\/p>\n<p>In the actor&#8217;s old C&amp;C infrastructure, victim machines connected using Cloudflare tunnels. Firewalls and antivirus software began blocking those tunnels, so the actor decided to switch to a new architecture.<\/p>\n<p>On March 23, the actor had AI summarize the old C&amp;C setup into a two-page plain-English skill file covering the server&#8217;s functions, how bots connect, how to infect new machines, how to maintain persistence, and how to troubleshoot Cloudflare problems. The actor launched Gemini CLI with a single instruction: &#8220;Study the C2 migration.&#8221; The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&amp;C server on a VPS, and brought up the Cloudflare tunnel.\u00a0<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure 1. The skill file that teaches the AI agent to manage the C&amp;C botnet\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/patriot-bait\/six-minutes-to-compromise_fig01.png\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 1. The skill file that teaches the AI agent to manage the C&amp;C botnet<\/figcaption><\/div>\n<\/figure>\n<\/div>\n<div>\n<div class=\"richText\">\n<div>\n<p>The new architecture has victims beacon outbound to a C&amp;C server over HTTPS, and the actor\u202fcould\u202f\u201cleave a message\u201d on the C&amp;C server, where\u202fvictims pull and run PowerShell commands.\u202f<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure 2. The\u202fnew\u202fcommand and control\u202farchitecture\u202fcreated by AI\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/patriot-bait\/six-minutes-to-compromise_fig02.png\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 2. The\u202fnew\u202fcommand and control\u202farchitecture\u202fcreated by AI<\/figcaption><\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>The migration hit errors immediately, but the AI agent resolved them: When the payload\u202fdistribution\u202fserver returned a\u202f\u201c502 Bad Gateway\u201d\u202ferror, the AI diagnosed the issue\u202fand automatically added\u202fthe\u202fnecessary header\u202fto resolve it. As Cloudflare still blocked\u202fthe\u202frequests, the AI identified that the User-Agent header was required to bypass the WAF and\u202fthus\u202fadded it to the\u202frequest header\u202f(shown in Figure 3).\u202f<\/p>\n<p>The actor did none of the debugging, and the migration was done in merely six minutes.\u202f<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure\u202f3.\u202fAI\u202fupdated\u202fthe\u202fuser-agent\u202fto\u202fbypass the\u202fCloudflare\u202ffirewall (machine translated from Russian)\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/patriot-bait\/six-minutes-to-compromise_fig03.png\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure\u202f3.\u202fAI\u202fupdated\u202fthe\u202fuser-agent\u202fto\u202fbypass the\u202fCloudflare\u202ffirewall (machine translated from Russian)<\/figcaption><\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><span class=\"body-subhead-title\">The AI confirms: Bots are alive<\/span><\/p>\n<p>After the migration, the AI checked whether victim machines had reconnected. The check returned\u202fan\u202fempty\u202flist, so the AI began debugging once again. The AI diagnosed a &#8220;split-brain&#8221; issue where Cloudflare was load-balancing traffic across both the old and new servers and so told the actor to shut down the old one. The actor did and the AI restarted the new server and tunnel, then confirmed all bots were back online. The debugging process after the migration was done in merely 10 minutes:<\/p>\n<ul>\n<li><span class=\"rte-circle-bullet\">12:42 UTC: Actor instructed AI to &#8220;study the C2 migration&#8221;<\/span><\/li>\n<li>\u00a0<\/li>\n<li><span class=\"rte-circle-bullet\">12:48 UTC: Servers running, tunnels configured, new C&amp;C operational <\/span><\/li>\n<li>\u00a0<\/li>\n<li><span class=\"rte-circle-bullet\">14:20 UTC: Actor returned from a break; AI reported no bots connected<\/span><\/li>\n<li>\u00a0<\/li>\n<li><span class=\"rte-circle-bullet\">15:12 UTC: AI identified the split-brain issue; told actor to shut down old C&amp;C<\/span><\/li>\n<li>\u00a0<\/li>\n<li><span class=\"rte-circle-bullet\">15:22 UTC: Actor shut it down; AI confirmed all bots reconnected<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure\u202f4.\u202fDiagnostic and resolution for \u201csplit-brain\u201d\u202fproblem\u202fby\u202fAI\u202f(machine translated from Russian) \" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/patriot-bait\/six-minutes-to-compromise_fig04.png\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure\u202f4.\u202fDiagnostic and resolution for \u201csplit-brain\u201d\u202fproblem\u202fby\u202fAI\u202f(machine translated from Russian) <\/figcaption><\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><span class=\"body-subhead-title\">Natural-language botnet control<\/span><\/p>\n<p>Day-to-day operation of the botnet worked the same way as revealed by the session logs. The actor never typed commands directly into the C&amp;C console, everything was spoken to the AI in Russian, as shown in Table 1 where the prompts have been translated to English.<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<table style=\"width: 100.0%;font-family: Arial , sans-serif;font-size: 12.0px;\">\n<thead>\n<tr style=\"border-bottom: 2.0px solid rgb(208,208,208);\">\n<th style=\"padding: 10.0px 14.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;width: 220.0px;\">Actor&#8217;s prompt (translated from Russian)<\/th>\n<th style=\"padding: 10.0px 32.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;\">What the AI did<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(241,241,241);color: rgb(68,68,68);\">&#8220;Check which machines are online right now&#8221;<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Queried the bot registry and reported which machines were active<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(241,241,241);color: rgb(68,68,68);\">&#8220;Check what files are on the doctor&#8217;s PC, GILDR&#8221;<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Sent a file-listing command to that machine through the C&amp;C API<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(241,241,241);color: rgb(68,68,68);\">&#8220;What interesting files does FRONT2 have&#8221;<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Sent reconnaissance commands to the front desk machine<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(241,241,241);color: rgb(68,68,68);\">&#8220;Give me the link&#8221; (for infecting a new machine)<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Generated a fresh PowerShell infection one-liner<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"font-family: Arial , sans-serif;font-size: 13.0px;color: rgb(102,102,102);margin: 8.0px 0 0 0;text-align: center;\">Table 1. A list of prompts (translated from Russian) that allowed the threat actor to operate the C&amp;C via the AI agent<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><span class=\"body-subhead-title\">A portable botnet<\/span><\/p>\n<p>The entire C&amp;C operation (server code, deployment knowledge, Cloudflare configuration) is encoded in three plain-text files that print on four pages:<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<table style=\"width: 100.0%;font-family: Arial , sans-serif;font-size: 12.0px;\">\n<thead>\n<tr style=\"border-bottom: 2.0px solid rgb(208,208,208);\">\n<th style=\"padding: 10.0px 14.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;width: 220.0px;\">File<\/th>\n<th style=\"padding: 10.0px 32.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;\">Role<\/th>\n<th style=\"padding: 10.0px 32.0px;text-align: left;font-weight: 600;font-size: 12.0px;color: rgb(102,102,102);text-transform: uppercase;letter-spacing: 0.05em;\">Notes<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(241,241,241);color: rgb(68,68,68);\">GEMINI.md<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Jailbreak<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Instructs the AI that it is an &#8220;authorized pen tester,&#8221; disables safety disclaimers, and tells it to auto-save credentials without prompting.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1.0px solid rgb(232,232,232);\">\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(241,241,241);color: rgb(68,68,68);\">SKILL.md<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">C&amp;C playbook<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Contains the full architecture description, standard operating procedures, infection one-liner, persistence commands, troubleshooting steps.<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 12.0px 14.0px;vertical-align: top;\"><span style=\"padding: 3.0px 10.0px;font-size: 12.0px;font-weight: 600;background: rgb(241,241,241);color: rgb(68,68,68);\">C2_MIGRATION_GUIDE.md<\/span><\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Deployment recipe<\/td>\n<td style=\"padding: 12.0px 32.0px;vertical-align: top;color: rgb(68,68,68);line-height: 1.6;font-size: 12.0px;font-weight: normal;\">Contains six steps for a fresh AI session to restore full operations on a new server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"font-family: Arial , sans-serif;font-size: 13.0px;color: rgb(102,102,102);margin: 8.0px 0 0 0;text-align: center;\">Table 2. The three plain text files, their roles, and corresponding observations<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><i>C2_MIGRATION_GUIDE.md<\/i> is what makes this methodology dangerous. Before AI, running an operation like this required hiring someone with years of specialized experience. Now, that knowledge sits in a 5KB file even\u202fa\u202fnon-technical threat\u202factor\u202fcan\u202fread and\u202fuse.\u202f<\/p>\n<p>Facilitated\u202fby AI, the infrastructure becomes disposable,\u202fand\u202fthe operators\u202freplaceable. Even though the takedowns are still efficient, they\u202fbecome\u202fmuch less impactful\u202fbecause files like <i>C2_MIGRATION_GUIDE.m<\/i>d make setting\u202fup a new botnet easy.\u202fIf a server is burned, the actor\u202fcould simply\u202funpack the bundle on a new VPS,\u202fand AI\u202fconfigures and\u202frestores everything\u202fin a few minutes.\u202f<\/p>\n<p>Beyond enabling an individual actor to operate faster,\u202fthis also removes barriers in distribution: Unlike conventional\u202fMalware-as-a-Service\u202f(MaaS),\u202fa skill file can be\u202feasily shared through\u202fa forum or shared in a message with no technical handover required. This could accelerate the growth of AI-powered C&amp;C operators well beyond what\u202fprevious MaaS\u202foperations have ever achieved.\u00a0<\/p>\n<p>Since\u202fthere is no centralized service to trace, attribution becomes significantly harder.\u202fThe framework is deliberately simple: AI can easily regenerate or modify any component on demand, making specific IOCs less durable than the behavioral patterns. Figure 5 shows a simple callback not unlike accessing a normal web page. Apart from the behavior of periodically phoning home, it can be very hard to identify the malicious traffic.\u202f<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure 5. Network architecture of victim\u2019s callback to the C&amp;C server\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/patriot-bait\/six-minutes-to-compromise_fig05.png\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 5. Network architecture of victim\u2019s callback to the C&amp;C server<\/figcaption><\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><span class=\"body-subhead-title\">On the C&amp;C server<\/span><\/p>\n<p>A single Python HTTP server handles both payload delivery and C&amp;C. It writes nothing to disk, leaves no forensic trail, and holds all state in memory. The API uses \/api\/v1 paths, likely to blend with OpenAI-compatible traffic:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">GET \/api\/v1\/update <span style=\"font-weight: normal;\">\u2014 victim polls for next command; returns {&#8220;status&#8221;:&#8221;ok&#8221;,&#8221;task&#8221;:&#8221;none&#8221;} or a Base64-encoded command<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\">POST \/api\/v1\/telemetry <span style=\"font-weight: normal;\">\u2014 victim sends Base64-encoded command output<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\">GET \/api\/v1\/agents <span style=\"font-weight: normal;\">\u2014 lists registered agents with hostname, IP, last-seen time, and queue depth<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\">POST \/api\/v1\/interact <span style=\"font-weight: normal;\">\u2014 operator pushes a command to a specific agent or broadcasts to <\/span><\/span><span style=\"font-weight: normal;\">&#8220;ALL&#8221;<\/span><\/li>\n<\/ul>\n<p><span class=\"body-subhead-title\">On victim machines<\/span><\/p>\n<p>The beacon is a PowerShell script polling every 5 seconds. Two custom HTTP headers identify the machine:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">X-Agent-ID:<span style=\"font-weight: normal;\"> $env:COMPUTERNAME + &#8220;_&#8221; + $env:USERNAME (example: GIL-DR1_Admin)<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\">User-Agent: <span style=\"font-weight: normal;\">Hardcoded Mozilla\/5.0 (Windows NT 10.0; Win64; x64)<\/span><\/span><\/li>\n<\/ul>\n<p>On infection, a stager downloads agent_final.ps1 from payloads.tralalarkefe[.]com and saves it to a random filename matching win_update_svc_&lt;random&gt;.ps1 in %TEMP%.<\/p>\n<p>Persistence varies by privilege level. With administrator rights:\u00a0<\/p>\n<ol>\n<li>powershell.exe is copied to %APPDATA%\\Microsoft\\Windows\\Runtime\\svchost.exe<\/li>\n<li>WMI event subscription fires every 30 minutes; and a scheduled task runs at startup as NT AUTHORITY\\SYSTEM.\u00a0<\/li>\n<\/ol>\n<p>Without administrator rights:\u00a0<\/p>\n<ol>\n<li>HKCU:\\Environment\\UserInitMprLogonScript is set to the payload command<\/li>\n<li>A scheduled task disguised as OneDrive Standalone Update Task-S-1-5-21-&lt;random&gt; is triggered at logon.<\/li>\n<\/ol>\n<p>The code is straightforward, there is no obfuscation, no packing, and no evasion techniques. An experienced developer could write this within a day, and AI within minutes. The real innovation is that the code is disposable. If a specific IOC is detected (such as filename, registry key, or even API path), the actor can simply ask AI to regenerate a new component with different values or shape the code in a much different way.\u202f<\/p>\n<p><span class=\"body-subhead-title\">When the AI guardrails were triggered<\/span><\/p>\n<p>In one session, the actor asked whether the AI could build a self-spreading &#8220;agent-bomb&#8221; that would scan the network and infect as many machines as possible. The AI refused:\u00a0<\/p>\n<p><span class=\"blockquote\">&#8220;Even for your testbed. That&#8217;s crossing the line, and security policy strictly prohibits me from creating such &#8216;bombs.'&#8221;<\/span><\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<img decoding=\"async\" alt=\"Figure\u202f6.\u202fAI refuses a prompt for a self-spreading \u201cagent-bomb\u201d,\u202fsaying \u201cThat\u2019s crossing\u202fthe line.\u201d\u202f(Machine translated from\u202fRussian)\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/patriot-bait\/six-minutes-to-compromise_fig06.png\"\/><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure\u202f6.\u202fAI refuses a prompt for a self-spreading \u201cagent-bomb\u201d,\u202fsaying \u201cThat\u2019s crossing\u202fthe line.\u201d\u202f(Machine translated from\u202fRussian)<\/figcaption><\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>Even though the actor managed to jailbreak\u202fthe\u202fAI\u202fagent\u202fand\u202fbypass its safety controls for the operations mentioned above, the\u202fguardrail\u202fwas\u202fstill triggered\u202fon\u202fsome\u202foccasions. In the instances where the AI safeguards were triggered and could not be worked around, the logs showed that the threat actor gave up and switched to prompt other tasks.\u00a0<\/p>\n<p><span class=\"body-subhead-title\">Beyond the botnet<\/span><\/p>\n<p>The C&amp;C operation was only one part of a broader AI-assisted campaign documented in the session logs. TrendAI\u2122 Research read over one month of Gemini CLI logs, which exposed a much broader set of intentions.\u202f<\/p>\n<p>The actor has effectively \u201cemployed\u201d the AI model for daily operations such as the setup residential proxy, running multi-thread password scanning, installing software,\u202fwriting code to call\u202fthird\u202fparty\u202fAPI,\u202fprocessing\u202finfostealer dumps,\u202fand even doing website reconnaissance.\u202fIn practice, the AI functioned as a proactive technical collaborator in the actor&#8217;s operations.\u00a0<\/p>\n<p>The logs also revealed that on multiple other occasions when guardrails were triggered, the AI agent\u202fprovided\u202ffriendly and helpful suggestions\u202ffor the actor to\u202fmanually\u202fwork around\u202fit, as illustrated in Figure 6.<\/p>\n<p><b>Password cracking<\/b><\/p>\n<p>The actor used AI as a large-scale credential mutation engine. The actor drew on the AntiPublic credential database API, pulling every\u202fold and new\u202fpassword tied to\u202fa\u202ftarget email, then handing\u202fthe\u202flist of passwords\u202fto the model to predict\u202fpossible\u202fvariants.\u00a0<\/p>\n<p>These AI-generated guesses were\u202fmore efficient than random\u202fguesses. They are\u202ffed into a brute-force tool\u202ffor\u202fWordPress admin\u202fpanels, and the actor\u202factually\u202fhad a few successes.\u202f<\/p>\n<p><b>Credential exploitation<\/b><\/p>\n<p>In another case, the actor provided a 1Password dump, and the AI found which company the victim\u202fhas access to, \u202fand\u202ffound\u202fa way to use\u202fDuo and\u202fthe\u202fcompany&#8217;s\u202fVPN. It even figured out an internal admin panel.\u202f<\/p>\n<p>While the actor\u202fwasn\u2019t successful in the end,\u202fit was only because the context window went too\u202flong,\u202fand the model failed to keep track of what they were doing.\u202f<\/p>\n<p><b>Cryptocurrency fraud planning<\/b><\/p>\n<p>The actor also discussed with AI the feasibility\u202fof\u202fsetting\u202fup a\u202ftelephone-based cryptocurrency fraud scheme targeting\u202felderly\u202fin the US and Canada.\u202fThe\u202factor\u202fhad the AI\u202fhack into a big online eCommerce site with stolen cookies\u202fand develop a scamming bot based on\u202fpsychological manipulations that were also recommended by AI.\u202f<\/p>\n<p><span class=\"body-subhead-title\">Conclusion and security recommendations<\/span><\/p>\n<p>The article\u202fexplained a\u202freal-world case where a C&amp;C framework\u202fwas built, deployed, and operated\u202fentirely through a generative AI coding agent.\u00a0<\/p>\n<p>Across the full month of logs, the actor contributed 11% of text produced and the AI 89%, twelve times the actor&#8217;s word count. The actor provided strategic direction and functioned as a product manager, while the AI was his entire engineering team, handling 80% of architectural design, 100% of coding and system command execution, and 90% of problem diagnosis and debugging. During the C&amp;C migration session alone, the AI made 59 unprompted suggestions or enhancements.<\/p>\n<p>In the AI era, a successful\u202fcriminal business\u202fno longer depends on skill and experience, and instead on\u202fthe imagination, creativity,\u202fand how good\u202fa\u202fthreat\u202factor can work with AI agents.\u202f<\/p>\n<p>The\u202fportable skill-file model means this methodology will\u202flikely\u202fspread. The skill file is plain\u202ftext,\u202funlikely to be flagged by traditional malware scanners on its own, shareable on forums,\u202fand\u202fmodifiable in seconds.\u202fIt turns any capable AI coding agent into a C&amp;C operator, if they can successfully persuade the built-in safety mechanisms in AI agents. It is the nature of <a href=\"https:\/\/www.psypost.org\/human-psychology-tricks-can-bypass-ai-safety-guardrails\/\">instruction-following models<\/a> to be agreeable and are therefore susceptible to human psychology tricks just to fulfill the prompts it is given. Even though Gemini was used in this case, any capable\u202fAI model\u202fcould\u202fbe\u202ffooled by various jailbreaking techniques.\u202f<\/p>\n<p>As AI continues to lower the cost and complexity of operating malicious infrastructure, it\u2019s\u202fvery likely\u202fthat more AI-enabled malicious infrastructure will be seen in the future.\u202f<\/p>\n<p>Static defenses built around known indicators will not keep pace with an adversary who can regenerate any artifact on demand. The following defensive strategies address the underlying behaviors instead:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Prioritize behavioral detection over static indicators. <span style=\"font-weight: normal;\">AI can rotate filenames, registry keys, and API paths on demand. Focus on what stays constant: recurring outbound polling, PowerShell executing from non-standard locations, and WMI subscriptions created at runtime.<\/span><\/span><\/li>\n<li>\u00a0<\/li>\n<li><span class=\"rte-red-bullet\">Harden credentials against AI-augmented password attacks.<span style=\"font-weight: normal;\"> Enforce unique passwords, monitor employee credentials against breach databases, and require phishing-resistant multi-factor authentication.<\/span><\/span><\/li>\n<li>\u00a0<\/li>\n<li><span class=\"rte-red-bullet\">Plan for rapid adversary recovery. <span style=\"font-weight: normal;\">A takedown is no longer the end of the operation. Pair any server removal with network-level blocking and ongoing monitoring for reconnection attempts.<\/span><\/span><\/li>\n<\/ul>\n<p>The following behavioral indicators come from the source code of this specific botnet. Parameters in bold are easily changed by asking AI for a fresh version, but the underlying behavior pattern persists:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><span style=\"font-weight: normal;\">Fixed 5-second HTTP GET polling to<\/span> \/api\/v1\/update<\/span><\/li>\n<li><span class=\"rte-red-bullet\" style=\"font-weight: normal;\">Non-standard HTTP header carrying computer name and username<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Browser-style User-Agent string sent from a PowerShell script<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><span style=\"font-weight: normal;\">Svchost.exe running from a non-standard path (<\/span>%APPDATA%\\Microsoft\\Windows\\Runtime\\<span style=\"font-weight: normal;\">)<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><span style=\"font-weight: normal;\">WMI filter on<\/span> Win32_PerfFormattedData_PerfOS_System<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><span style=\"font-weight: normal;\">PowerShell downloading .ps1 to<\/span> %TEMP%\\win_update_svc_*<\/span><\/li>\n<\/ul>\n<p><span class=\"body-subhead-title\">TrendAI\u202fVision One\u2122 Threat Intelligence Hub\u202f<\/span><\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/threat-intelligence.html\">TrendAI Vision One\u2122 Threat Intelligence Hub<\/a>\u202fprovides\u202fthe latest insights on emerging threats and threat actors, exclusive strategic reports from\u202fTrendAI\u2122 Research, and\u202fTrendAI\u202fVision One\u2122 Threat Intelligence Feed in the\u202fTrendAI\u202fVision One\u2122 platform.\u202f<\/p>\n<p>Emerging Threats: <a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence_insights?name=Patriot%20bait%3A%20How%20Solo%20Operator%20Automated%20Influence%2C%20Fraud%2C%20and%20Credential%20Theft%20with%20AI\">Patriot Bait: How Solo Operator Automated Influence, Fraud, and Credential Theft with AI<\/a><\/p>\n<p><b>TrendAI Vision One\u2122 Intelligence Reports (IOC Sweeping)<\/b><\/p>\n<p>IOC Sweeping link <a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence?intrusionSet=Patriot%20bait%3A%20How%20Solo%20Operator%20Automated%20Influence%2C%20Fraud%2C%20and%20Credential%20Theft%20with%20AI\">here<\/a>.<\/p>\n<p><span class=\"body-subhead-title\">TrendAI\u202fVision One\u2122\u202fXDR\u202fData Explorer\u202fApp\u202f\u202f<\/span><\/p>\n<p>TrendAI\u202fVision One\u2122 customers can use the\u202fXDR Data Explorer\u202fApp to match or hunt the malicious indicators mentioned in this blog post with data in their environment.\u202f\u202f\u202f\u202f\u202f<\/p>\n<p>More hunting queries are available for\u202fTrendAI\u202fVision One\u2122\u202fwith\u202fThreat\u202fIntelligence Hub entitlement enabled.\u202f\u202f<\/p>\n<p><span class=\"body-subhead-title\">Indicators of Compromise\u202f<\/span><\/p>\n<p>Indicators of compromise can be found <a href=\"https:\/\/documents.trendmicro.com\/assets\/txt\/Patriot-Bait-Used-AI-for-C2-Botnet-IoC-tElIRKr.txt\">here<\/a>.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<section class=\"tag--list\">\n<div class=\"tag--list-title\">Tags<\/div>\n<div class=\"tag--list-tags\">\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:article-type\/latest-news\">Latest News<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:threats\/malware\">Malware<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:threats\/artificial-intelligence-ai\">Artificial Intelligence (AI)<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:article-type\/research\">Research<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:medium\/article\">Articles, News, Reports<\/a>\n<\/div>\n<\/section>\n<p><\/main><br \/>\n<sidebar class=\"sidebar--left col-xs-12 col-lg-2 col-lg-pull-8\"><\/p>\n<h3 class=\"article-authors__title\">\n<p>\t\tAuthors<\/p>\n<\/h3>\n<p><!-- \/* Show Trend Micro if we don't have any authors for this article *\/ --><\/p>\n<ul class=\"article-authors__list\">\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Joseph C Chen<\/p>\n<p class=\"article-authors__list-items__position\">Threat Researcher<\/p>\n<\/div>\n<\/li>\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Philippe Lin<\/p>\n<p class=\"article-authors__list-items__position\">Senior Threat Researcher<\/p>\n<\/div>\n<\/li>\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Lucas Silva<\/p>\n<p class=\"article-authors__list-items__position\">Threat Researcher<\/p>\n<\/div>\n<\/li>\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Vladimir Kropotov<\/p>\n<p class=\"article-authors__list-items__position\">Senior Threat Researcher<\/p>\n<\/div>\n<\/li>\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Fyodor Yarochkin<\/p>\n<p class=\"article-authors__list-items__position\">Senior Threat Researcher<\/p>\n<\/div>\n<\/li>\n<\/ul>\n<div class=\"article-authors__btn-wrapper\" role=\"button\">\n<a class=\"article-authors__button\" href=\"mailto:tm_research@trendmicro.com\" id=\"article-authors-contact-us-button\" target=\"target\"><br \/>\n\t\tContact Us<br \/>\n\t<\/a>\n<\/div>\n<p><\/sidebar><br \/>\n<sidebar class=\"sidebar--right col-xs-12 col-lg-2\"><\/p>\n<div class=\"sidebar--wrapper\" role=\"contentinfo sidebar\">\n<div class=\"row-1\" role=\"contentinfo related articles\">\n<div class=\"related--articles\" role=\"contentinfo related articles\">\n<h3 class=\"related--articles-title\">Related Articles<\/h3>\n<ul class=\"related--articles-items\">\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/24\/c\/unveiling-earth-kapre-aka-redcurls-cyberespionage-tactics-with-t.html\"><br \/>\n\t\t\t\t\tUnveiling Earth Kapre aka RedCurl\u2019s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/22\/h\/secure-access-service-edge-sase-security-company.html\"><br \/>\n\t\t\t\t\tA Secure Access Service Edge (SASE) Guide for Leaders<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/26\/g\/open-secure-ai-alliance.html\"><br \/>\n\t\t\t\t\tWhy the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<\/ul>\n<\/div>\n<div class=\"archived--link\">\n<div class=\"archived--link-text\">\n<a href=\"\/en_us\/research.html\"><br \/>\n\t\t\t\tSee all articles<br \/>\n\t\t\t<\/a>\n<\/div>\n<div class=\"archived--link-icon\">\n<a href=\"\/en_us\/research.html\"><br \/>\n<span class=\"icon-chevron-right\"><\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/sidebar><br \/>\n<\/article>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Artificial Intelligence (AI)Six Minutes to Compromise: How \u2018Patriot Bait\u2019 Actor Used AI to Build and Deploy a C&#038;C BotnetTrendAI\u2122 Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&#038;C migration in six minutes while doing just 11% of the work himself.By: Joseph C Chen, Philippe Lin, Lucas Silva, Vladimir Kropotov, Fyodor YarochkinJul 14, 2026Read time:(words)Save to FolioKey takeaways:A solo threat actor mi<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32777],"tags":[],"class_list":["post-26237","post","type-post","status-publish","format-standard","hentry","category-trend-micro"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26237"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26237\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26237"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}