Researchers say a Russian-speaking threat actor used Google’s Gemini CLI as a hands-on assistant to run a small botnet and target a dental clinic’s systems. Trend Micro says the actor used more than 200 Gemini CLI sessions to migrate command-and-control infrastructure, manage eight infected systems, generate infection links, and pursue access to an OpenDental database; the malware used lightweight PowerShell agents, a Python HTTP server, scheduled tasks, WMI event persistence, and registry changes.
Why it matters: This matters because it shows an off-the-shelf AI coding tool being used to speed up real intrusions against a healthcare setting, lowering the skill and time needed to operate malware. Dental and healthcare organizations should review endpoint and PowerShell activity, check for unauthorized persistence, investigate access to OpenDental systems, and harden controls around remote administration and credential exposure.
Bill Toulas
2026.07.15
100% relevant
This article appears to be the first concrete report tying Gemini CLI to a specific botnet operation and intrusion against a dental clinic, so it establishes a distinct new story rather than updating an existing tracked event.
← Back to all stories