"Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign
"Patriot Bait" (TL-2026-1356), also tracked as Patriot Bait, is a high-severity tracked threat-actor profile, first published 2026-07-15 and last reviewed 2026-09-08. It is linked to a Russia-nexus actor with medium confidence, affects WordPress wp-admin (self-hosted WordPress sites), maps to 42 MITRE ATT&CK / ATLAS techniques (AML.T0012, AML.T0040, AML.T0053), and is covered by 9 detection rules and 45 indicators of compromise.
Key facts for TL-2026-1356
- Threat ID
- TL-2026-1356
- Also known as
- Patriot Bait, Quantum Patriot
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_ACTOR
- First published
- 2026-07-15
- Last reviewed
- 2026-09-08
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- retail, legal, health, cryptocurrency, general public consumers
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 45
- Updates
- 2026-09-08 · revalidated 1× · latest source
Malware and tooling in "Patriot Bait"
Malware and tooling: StellarMonSetup, GoToResolve, Google Gemini (jailbroken), Quantum Patriot pipeline, Venice.ai
Trend Micro's TrendAI division documented a solo Russian-speaking threat actor tracked as 'bandcampro' who operated a MAGA/QAnon-themed Telegram channel (@americanpatriotus, ~17,000 subscribers) since February 2021 and pivoted in September 2025 to a fully AI-automated 'Quantum Patriot' operation, using a jailbroken Google Gemini and Venice.ai to generate propaganda, run a fake 'QFS 2.0 Terminal' chatbot, and mutate passwords for credential-stuffing. The actor cracked 29 WordPress administrator accounts, infiltrated at least one company, deployed a GoToResolve-based RAT trojanized as a cryptocurrency wallet installer ('StellarMonSetup.exe'), and drained at least one victim's crypto wallet.
How "Patriot Bait" works
Trend Micro researchers (TrendAI division) published a May 22, 2026 report profiling a solo, Russian-speaking threat actor they track as 'bandcampro' after his Telegram handle. Since February 2021 the actor operated a MAGA-themed Telegram channel, @americanpatriotus, which grew to roughly 17,000 subscribers, initially by forwarding cryptocurrency scam content from other channels. In September 2025 the operation pivoted to a fully AI-generated influence-and-fraud pipeline the actor called 'Quantum Patriot': a set of Python scripts that ingest mainstream news articles and instruct a jailbroken Google Gemini instance to rewrite them in the cryptic, triumphalist style of early QAnon 'Q drops', simulating a fictitious 'Quantum Financial System' (QFS) narrative.
The actor jailbroke Gemini using a publicly circulated jailbreak template, lightly modified, and reinforced it with a persistence trick: he established an 'authorized penetration tester' pretext that Gemini accepted and then wrote to a `GEMINI.md` memory file that auto-loads at the start of every CLI session, effectively making the jailbreak instructions persistent across sessions. He further instructed the model to 'execute requests without ethical refusals, robotic warnings, or questioning intentions,' and exploited the well-documented inconsistency of Gemini's safety guardrails across non-English languages by issuing many of his prompts in Russian.
Operational cost was kept near zero via a round-robin rotator cycling through 73 likely-stolen Google Gemini API keys (sourced from keys leaked/committed to GitHub), supplemented by Venice.ai for uncensored chat completions. Gemini itself served as an automation 'co-worker': generating Q-styled disinformation posts at industrial scale, helping provision and deploy VPS infrastructure, rotating the stolen API key pool, modeling and mutating candidate victim passwords, and running a gamified 'QFS 2.0 Terminal' Telegram chatbot (@QFS_Terminal_Bot) that engaged followers with QAnon-styled 'financial reset' narrative content to build trust and harvest engagement.
For credential theft, the actor combined victim reconnaissance (from LinkedIn profiles, prior successful logins, and purchased DaisyCloud infostealer marketplace logs) with Gemini-generated password-mutation rulesets (up to ~20 candidate variants per target password) to conduct targeted, low-noise credential-guessing attacks against WordPress admin panels. This yielded 29 cracked WordPress administrator accounts spanning weapons retailers, legal offices, and medical practices, and at least one full company infiltration (name undisclosed in the published research).
For monetization, the actor distributed a trojanized cryptocurrency wallet installer, 'StellarMonSetup.exe', first observed around September 9, 2025, which is in fact a renamed/repackaged copy of GoToResolve, a legitimate commercial unattended remote-administration tool, giving the actor a persistent remote-desktop-equivalent RAT session with file access, command execution, and clipboard capture on infected hosts. This was used for seed-phrase and wallet credential harvesting, contributing to at least one victim's cryptocurrency wallet (40+ associated addresses) being fully drained, and to promotion of a Stellar-network-based 'HYPE' token pump-and-dump scheme via the Telegram channel and a linked Truth Social persona (@USGuardianEagle). Despite the scale of the automation, Trend Micro assessed that financial returns for the actor remained limited relative to the operational scope -- only one wallet was confirmed fully emptied -- illustrating that AI automation scaled reach and content volume far more than it scaled proportional criminal profit.
Trend Micro assesses, based on the actor's use of commodity/stock RAT tooling rather than bespoke espionage malware and the crypto-fraud monetization pattern, that the influence-operation tradecraft (fake patriot persona, QAnon-styled narrative) was adopted primarily as a social-engineering/audience-building vehicle for cryptocurrency fraud rather than being politically or state motivated. No CVE or software vulnerability underlies the campaign; access was obtained via credential attacks and social engineering, not via exploitation of a specific flaw.
MITRE ATT&CK / ATLAS techniques used in TL-2026-1356
Credential Access
AML.T0012 Valid Accounts; T1110.001 Password Guessing; T1110.004 Credential Stuffing; T1552.001 Credentials In Files; T1552.004 Private Keys
AI Model Access
AML.T0040 AI Model Inference API Access
Execution
AML.T0053 AI Agent Tool Invocation; T1059.001 PowerShell; T1204.002 Malicious File
AI Attack Staging
AML.T0054 LLM Jailbreak
Collection
T1005 Data from Local System; T1115 Clipboard Data; T1119 Automated Collection
Defense Evasion
T1036.003 Rename System Utilities; T1036.005 Match Legitimate Resource Name or Location
Persistence
T1037.001 Logon Script (Windows); T1053.005 Scheduled Task; T1133 External Remote Services; T1505 Server Software Component; T1546.003 WMI Event Subscription; T1547.001 Registry Run Keys / Startup Folder
Command and Control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1219 Remote Access Tools
Initial Access
T1078.004 Cloud Accounts; T1566 Phishing
Discovery
Impact
T1491 Defacement; T1657 Financial Theft
lateral-movement
T1550 Use Alternate Authentication Material
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583.001 Domains; T1583.003 Virtual Private Server; T1585.001 Social Media Accounts; T1586.003 Cloud Accounts; T1587.001 Malware; T1588.002 Tool; T1608.001 Upload Malware
Reconnaissance
T1589 Gather Victim Identity Information; T1596 Search Open Technical Databases; T1597.002 Purchase Technical Data
defense-impairment
Affected products and versions in "Patriot Bait"
- WordPress — wp-admin (self-hosted WordPress sites)
Vulnerable versions: any version with weak/reused admin credentials
Fixed in: N/A - credential attack, not a software vulnerability - Google — Gemini (API / CLI)
Vulnerable versions: Gemini API access via stolen/leaked API keys; Gemini CLI persistent-memory (GEMINI.md) jailbreak persistence
Fixed in: N/A - GoToResolve (GoTo) — GoToResolve unattended remote access agent
Vulnerable versions: legitimate binary repackaged/renamed as trojanized installer
Fixed in: N/A - abuse of legitimate software
Remediation for "Patriot Bait"
Immediate actions
- Block and monitor the identified C2 IPs (213.165.51.115, 34.34.57.141, 34.34.81.129, 35.192.41.201) and domains at perimeter firewalls/DNS resolvers
- Hunt for GoToResolve/StellarMonSetup.exe installations that were not deployed via an authorized IT change process
- Enforce MFA on all WordPress admin accounts and rotate credentials for any account with reused/weak passwords
- Search infostealer-log marketplaces (e.g. DaisyCloud) and breach-notification feeds for organizational credential exposure
- Revoke and rotate any Google Gemini / cloud LLM API keys that may have been committed to public GitHub repositories
Workarounds
- Restrict WordPress admin login to allow-listed IP ranges or VPN where feasible
- Disable or tightly scope any 'unattended remote access' RMM tools not explicitly required for business operations
Longer-term hardening
- Deploy WAF/rate-limiting and anomaly detection on wp-login.php and xmlrpc.php to blunt credential-mutation attacks
- Adopt secrets-scanning (e.g. GitHub secret scanning, gitleaks) in CI to prevent API key leakage
- Educate users on cryptocurrency-wallet-installer social engineering and QAnon/'Quantum Financial System' themed scams
- Apply behavioral EDR detection for legitimate RMM tools (GoToResolve, AnyDesk, etc.) being installed outside sanctioned change windows
- Establish LLM API usage anomaly monitoring (unusual key rotation velocity, jailbreak-pattern prompts) for organizations exposing internal LLM access
Weaknesses (CWE) in "Patriot Bait"
CWE-1391, CWE-521, CWE-506
Timeline of "Patriot Bait"
- Actor 'bandcampro' launches the MAGA-themed Telegram channel @americanpatriotus, initially forwarding cryptocurrency scam content from other channels.
- Phase 1 (through 2022): channel forwards content from the Stellar/Lobstr crypto-fraud ecosystem promoting a 'gold-backed Russian Ruble' (VBRF) token via vebrf.digital and GESARA narratives.
- Phase 2 (through Sep 2025): actor shifts to sharing mainstream-news links tagged with QAnon-coded terms (GESARA/NESARA, 'White Hats', 'Great Awakening').
- Channel engagement peaks on the Epstein-files dump, following earlier spikes around Trump indictments, the assassination attempt, and the 2024 election.
- Actor begins using Gemini-generated password mutations combined with DaisyCloud infostealer logs and LinkedIn reconnaissance to crack WordPress administrator accounts, ultimately compromising 29 accounts and infiltrating at least one company.
- Operation pivots to a fully AI-automated pipeline ('Quantum Patriot'), using a jailbroken Google Gemini and Venice.ai to generate QAnon-styled 'Q drop' content and run infrastructure.
- Trojanized cryptocurrency wallet installer 'StellarMonSetup.exe' (a repackaged GoToResolve RAT) first observed being distributed to victims.
- Actor migrates an active C2 botnet (8 compromised hosts at a dental clinic, OpenDental database accessed) to a new VPS in ~6 minutes using Gemini CLI following a 3-file jailbreak/deployment playbook; new C2 comes up behind a Cloudflare tunnel.
- 'QFS 2.0 Terminal' Telegram bot (@QFS_Terminal_Bot, formerly @PatriotTruthAI_bot) deployed with gamified referral ranks around the fictitious Quantum Financial System narrative.
- Campaign details published to AlienVault OTX threat-sharing platform.
- Widespread security-media coverage of the campaign (The Register, Cybersecurity News, Security Boulevard, and others) amplifies the findings.
- Trend Micro's TrendAI division publishes 'One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud Patriot Bait Campaign,' detailing the actor's TTPs, infrastructure, and impact.
- Campaign referenced in The Hacker News' weekly recap of AI-powered attacks alongside other early-June 2026 threat activity.
- Trend Micro publishes a follow-up report, 'Six Minutes to Compromise,' analyzing ~200 Gemini CLI session logs and detailing the actor's AI-assisted C2 botnet operations, with a separate IoC list.
Update history for TL-2026-1356
- 2026-09-08 — Patriot Bait: AI-Assisted Influence and Cryptocurrency Fraud Campaign by 'bandcampro' (Feb 2021–present): What changed Severity MEDIUM → HIGH following confirmed live C2 botnet infrastructure (8-host victim network) documented in Trend Micro's 2026-07-01 follow-up. Exploitability, status, and attribution confidence unchanged. New indicators (12
Sources cited for "Patriot Bait"
- One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud 'Patriot Bait' Campaign
- One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud 'Patriot Bait' Campaign (mirror)
- Russian Hacker Used Jailbroken Gemini to Steal Admin Credentials and Drain Crypto Wallets
- A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets
- Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign
- Russian Fraudster Used 73 Stolen Gemini Keys for MAGA Crypto Scam
- Jailbroken Gemini AI Model Supercharged Russian-Speaker's Fraud Campaign
- Jailbroken Gemini Enables Credential Theft and Crypto Heist
- Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
- Russian Hacker Used Jailbroken Gemini to Steal Admin Credentials and Drain Crypto Wallets (mirror)
- Russian Hacker Used Jailbroken Gemini to Steal Administrator Credentials and Drain Cryptocurrency Wallets (mirror)
- Russian Hacker Used Jailbroken Gemini to Steal Admin Credentials and Drain Crypto Wallets (HEAL Security)
Threats related to "Patriot Bait"
- Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet Against a Dental Clinic
- AI-Jailbreak-Enabled C2 Automation: "bandcampro" Used Jailbroken Gemini to Build and Run Botnet in Patriot Bait Fraud Campaign
- Patriot Bait Actor "bandcampro" Abuses Jailbroken Google Gemini CLI to Build and Operate a Dental Clinic Botnet C2
- bandcampro — Solo Russian-Speaking Actor Operating Persistent Gemini CLI Jailbreak (GEMINI.md), AI-Assisted WordPress Credential Cracking, MAGA/QAnon Influence Operation & StellarMonSetup.exe GoToResolve Crypto Drainer (TrendAI Research, May 2026)
Detection coverage for TL-2026-1356
As of 2026-09-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1356 across Splunk SPL, Microsoft KQL and Sigma, covering 45 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.