"Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign

"Patriot Bait" (TL-2026-1356), also tracked as Patriot Bait, is a high-severity tracked threat-actor profile, first published 2026-07-15 and last reviewed 2026-09-08. It is linked to a Russia-nexus actor with medium confidence, affects WordPress wp-admin (self-hosted WordPress sites), maps to 42 MITRE ATT&CK / ATLAS techniques (AML.T0012, AML.T0040, AML.T0053), and is covered by 9 detection rules and 45 indicators of compromise.

Key facts for TL-2026-1356

Threat ID
TL-2026-1356
Also known as
Patriot Bait, Quantum Patriot
Severity
HIGH
Status
ACTIVE
Category
THREAT_ACTOR
First published
2026-07-15
Last reviewed
2026-09-08
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
retail, legal, health, cryptocurrency, general public consumers
Target regions
united states of america
Detection rules
9
Indicators of compromise
45
Updates
2026-09-08 · revalidated 1× · latest source

Malware and tooling in "Patriot Bait"

Malware and tooling: StellarMonSetup, GoToResolve, Google Gemini (jailbroken), Quantum Patriot pipeline, Venice.ai

Trend Micro's TrendAI division documented a solo Russian-speaking threat actor tracked as 'bandcampro' who operated a MAGA/QAnon-themed Telegram channel (@americanpatriotus, ~17,000 subscribers) since February 2021 and pivoted in September 2025 to a fully AI-automated 'Quantum Patriot' operation, using a jailbroken Google Gemini and Venice.ai to generate propaganda, run a fake 'QFS 2.0 Terminal' chatbot, and mutate passwords for credential-stuffing. The actor cracked 29 WordPress administrator accounts, infiltrated at least one company, deployed a GoToResolve-based RAT trojanized as a cryptocurrency wallet installer ('StellarMonSetup.exe'), and drained at least one victim's crypto wallet.

How "Patriot Bait" works

Trend Micro researchers (TrendAI division) published a May 22, 2026 report profiling a solo, Russian-speaking threat actor they track as 'bandcampro' after his Telegram handle. Since February 2021 the actor operated a MAGA-themed Telegram channel, @americanpatriotus, which grew to roughly 17,000 subscribers, initially by forwarding cryptocurrency scam content from other channels. In September 2025 the operation pivoted to a fully AI-generated influence-and-fraud pipeline the actor called 'Quantum Patriot': a set of Python scripts that ingest mainstream news articles and instruct a jailbroken Google Gemini instance to rewrite them in the cryptic, triumphalist style of early QAnon 'Q drops', simulating a fictitious 'Quantum Financial System' (QFS) narrative.

The actor jailbroke Gemini using a publicly circulated jailbreak template, lightly modified, and reinforced it with a persistence trick: he established an 'authorized penetration tester' pretext that Gemini accepted and then wrote to a `GEMINI.md` memory file that auto-loads at the start of every CLI session, effectively making the jailbreak instructions persistent across sessions. He further instructed the model to 'execute requests without ethical refusals, robotic warnings, or questioning intentions,' and exploited the well-documented inconsistency of Gemini's safety guardrails across non-English languages by issuing many of his prompts in Russian.

Operational cost was kept near zero via a round-robin rotator cycling through 73 likely-stolen Google Gemini API keys (sourced from keys leaked/committed to GitHub), supplemented by Venice.ai for uncensored chat completions. Gemini itself served as an automation 'co-worker': generating Q-styled disinformation posts at industrial scale, helping provision and deploy VPS infrastructure, rotating the stolen API key pool, modeling and mutating candidate victim passwords, and running a gamified 'QFS 2.0 Terminal' Telegram chatbot (@QFS_Terminal_Bot) that engaged followers with QAnon-styled 'financial reset' narrative content to build trust and harvest engagement.

For credential theft, the actor combined victim reconnaissance (from LinkedIn profiles, prior successful logins, and purchased DaisyCloud infostealer marketplace logs) with Gemini-generated password-mutation rulesets (up to ~20 candidate variants per target password) to conduct targeted, low-noise credential-guessing attacks against WordPress admin panels. This yielded 29 cracked WordPress administrator accounts spanning weapons retailers, legal offices, and medical practices, and at least one full company infiltration (name undisclosed in the published research).

For monetization, the actor distributed a trojanized cryptocurrency wallet installer, 'StellarMonSetup.exe', first observed around September 9, 2025, which is in fact a renamed/repackaged copy of GoToResolve, a legitimate commercial unattended remote-administration tool, giving the actor a persistent remote-desktop-equivalent RAT session with file access, command execution, and clipboard capture on infected hosts. This was used for seed-phrase and wallet credential harvesting, contributing to at least one victim's cryptocurrency wallet (40+ associated addresses) being fully drained, and to promotion of a Stellar-network-based 'HYPE' token pump-and-dump scheme via the Telegram channel and a linked Truth Social persona (@USGuardianEagle). Despite the scale of the automation, Trend Micro assessed that financial returns for the actor remained limited relative to the operational scope -- only one wallet was confirmed fully emptied -- illustrating that AI automation scaled reach and content volume far more than it scaled proportional criminal profit.

Trend Micro assesses, based on the actor's use of commodity/stock RAT tooling rather than bespoke espionage malware and the crypto-fraud monetization pattern, that the influence-operation tradecraft (fake patriot persona, QAnon-styled narrative) was adopted primarily as a social-engineering/audience-building vehicle for cryptocurrency fraud rather than being politically or state motivated. No CVE or software vulnerability underlies the campaign; access was obtained via credential attacks and social engineering, not via exploitation of a specific flaw.

MITRE ATT&CK / ATLAS techniques used in TL-2026-1356

Credential Access

AML.T0012 Valid Accounts; T1110.001 Password Guessing; T1110.004 Credential Stuffing; T1552.001 Credentials In Files; T1552.004 Private Keys

AI Model Access

AML.T0040 AI Model Inference API Access

Execution

AML.T0053 AI Agent Tool Invocation; T1059.001 PowerShell; T1204.002 Malicious File

AI Attack Staging

AML.T0054 LLM Jailbreak

Collection

T1005 Data from Local System; T1115 Clipboard Data; T1119 Automated Collection

Defense Evasion

T1036.003 Rename System Utilities; T1036.005 Match Legitimate Resource Name or Location

Persistence

T1037.001 Logon Script (Windows); T1053.005 Scheduled Task; T1133 External Remote Services; T1505 Server Software Component; T1546.003 WMI Event Subscription; T1547.001 Registry Run Keys / Startup Folder

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1219 Remote Access Tools

Initial Access

T1078.004 Cloud Accounts; T1566 Phishing

Discovery

T1087 Account Discovery

Impact

T1491 Defacement; T1657 Financial Theft

lateral-movement

T1550 Use Alternate Authentication Material

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Domains; T1583.003 Virtual Private Server; T1585.001 Social Media Accounts; T1586.003 Cloud Accounts; T1587.001 Malware; T1588.002 Tool; T1608.001 Upload Malware

Reconnaissance

T1589 Gather Victim Identity Information; T1596 Search Open Technical Databases; T1597.002 Purchase Technical Data

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in "Patriot Bait"

  • WordPress — wp-admin (self-hosted WordPress sites)
    Vulnerable versions: any version with weak/reused admin credentials
    Fixed in: N/A - credential attack, not a software vulnerability
  • Google — Gemini (API / CLI)
    Vulnerable versions: Gemini API access via stolen/leaked API keys; Gemini CLI persistent-memory (GEMINI.md) jailbreak persistence
    Fixed in: N/A
  • GoToResolve (GoTo) — GoToResolve unattended remote access agent
    Vulnerable versions: legitimate binary repackaged/renamed as trojanized installer
    Fixed in: N/A - abuse of legitimate software

Remediation for "Patriot Bait"

Immediate actions

  • Block and monitor the identified C2 IPs (213.165.51.115, 34.34.57.141, 34.34.81.129, 35.192.41.201) and domains at perimeter firewalls/DNS resolvers
  • Hunt for GoToResolve/StellarMonSetup.exe installations that were not deployed via an authorized IT change process
  • Enforce MFA on all WordPress admin accounts and rotate credentials for any account with reused/weak passwords
  • Search infostealer-log marketplaces (e.g. DaisyCloud) and breach-notification feeds for organizational credential exposure
  • Revoke and rotate any Google Gemini / cloud LLM API keys that may have been committed to public GitHub repositories

Workarounds

  • Restrict WordPress admin login to allow-listed IP ranges or VPN where feasible
  • Disable or tightly scope any 'unattended remote access' RMM tools not explicitly required for business operations

Longer-term hardening

  • Deploy WAF/rate-limiting and anomaly detection on wp-login.php and xmlrpc.php to blunt credential-mutation attacks
  • Adopt secrets-scanning (e.g. GitHub secret scanning, gitleaks) in CI to prevent API key leakage
  • Educate users on cryptocurrency-wallet-installer social engineering and QAnon/'Quantum Financial System' themed scams
  • Apply behavioral EDR detection for legitimate RMM tools (GoToResolve, AnyDesk, etc.) being installed outside sanctioned change windows
  • Establish LLM API usage anomaly monitoring (unusual key rotation velocity, jailbreak-pattern prompts) for organizations exposing internal LLM access

Weaknesses (CWE) in "Patriot Bait"

CWE-1391, CWE-521, CWE-506

Timeline of "Patriot Bait"

  • Actor 'bandcampro' launches the MAGA-themed Telegram channel @americanpatriotus, initially forwarding cryptocurrency scam content from other channels.
  • Phase 1 (through 2022): channel forwards content from the Stellar/Lobstr crypto-fraud ecosystem promoting a 'gold-backed Russian Ruble' (VBRF) token via vebrf.digital and GESARA narratives.
  • Phase 2 (through Sep 2025): actor shifts to sharing mainstream-news links tagged with QAnon-coded terms (GESARA/NESARA, 'White Hats', 'Great Awakening').
  • Channel engagement peaks on the Epstein-files dump, following earlier spikes around Trump indictments, the assassination attempt, and the 2024 election.
  • Actor begins using Gemini-generated password mutations combined with DaisyCloud infostealer logs and LinkedIn reconnaissance to crack WordPress administrator accounts, ultimately compromising 29 accounts and infiltrating at least one company.
  • Operation pivots to a fully AI-automated pipeline ('Quantum Patriot'), using a jailbroken Google Gemini and Venice.ai to generate QAnon-styled 'Q drop' content and run infrastructure.
  • Trojanized cryptocurrency wallet installer 'StellarMonSetup.exe' (a repackaged GoToResolve RAT) first observed being distributed to victims.
  • Actor migrates an active C2 botnet (8 compromised hosts at a dental clinic, OpenDental database accessed) to a new VPS in ~6 minutes using Gemini CLI following a 3-file jailbreak/deployment playbook; new C2 comes up behind a Cloudflare tunnel.
  • 'QFS 2.0 Terminal' Telegram bot (@QFS_Terminal_Bot, formerly @PatriotTruthAI_bot) deployed with gamified referral ranks around the fictitious Quantum Financial System narrative.
  • Campaign details published to AlienVault OTX threat-sharing platform.
  • Widespread security-media coverage of the campaign (The Register, Cybersecurity News, Security Boulevard, and others) amplifies the findings.
  • Trend Micro's TrendAI division publishes 'One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud Patriot Bait Campaign,' detailing the actor's TTPs, infrastructure, and impact.
  • Campaign referenced in The Hacker News' weekly recap of AI-powered attacks alongside other early-June 2026 threat activity.
  • Trend Micro publishes a follow-up report, 'Six Minutes to Compromise,' analyzing ~200 Gemini CLI session logs and detailing the actor's AI-assisted C2 botnet operations, with a separate IoC list.

Update history for TL-2026-1356

Sources cited for "Patriot Bait"

Threats related to "Patriot Bait"

Detection coverage for TL-2026-1356

As of 2026-09-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1356 across Splunk SPL, Microsoft KQL and Sigma, covering 45 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats