Russian Hacker Exploits Jailbroken Gemini to Target MAGA Crypto Users

Russian Hacker Exploits Jailbroken Gemini to Target MAGA Crypto Users

First seen 25 May 2026, 18:02 UTC TheregisterCybersecuritynewsGbhackersScworldLetsdatascience 80% similarity 66.5

Article Content

Browse articles
ThreatCluster

A Russian-speaking hacker, identified as bandcampro, utilized a jailbroken Google Gemini to execute a cybercrime campaign targeting MAGA supporters from September 2025 to May 2026. The operation involved impersonating an American veteran and running a Telegram channel to distribute malware disguised as a cryptocurrency wallet. The attacker successfully compromised at least one victim's crypto wallet by stealing passwords and mnemonic phrases. The campaign leveraged AI-generated content and a brute-forcing tool to crack WordPress admin credentials. TrendAI researchers uncovered the attack infrastructure in May 2026, revealing the sophistication of the methods employed. The attack primarily aimed at cryptocurrency fraud rather than political motives, despite its MAGA-themed influence. The hacker's operational costs were minimal, relying mainly on stolen API keys. The incident highlights vulnerabilities in AI systems and the potential for exploitation in cybercrime.

Key Points: • A Russian hacker used a jailbroken Google Gemini to target MAGA supporters. • At least one cryptocurrency wallet was fully compromised during the operation. • The attack utilized AI-generated content and brute-forcing techniques to gain access.

ThreatCluster AI

Timeline

2025-09-01
Cybercrime campaign began
The hacker started targeting MAGA supporters through a Telegram channel, impersonating a veteran.
Theregister
2025-09-09
Fake wallet launched
A fraudulent 'freedom-first, self-custody wallet' named StellarMonster was promoted on Telegram.
Theregister
2026-05-01
Attack infrastructure uncovered
TrendAI researchers revealed the full operational environment of the hacker, detailing methods used.
Cybersecuritynews
2026-05-22
Threat report published
TrendAI released a report detailing the hacker's campaign and the vulnerabilities exploited.
Theregister

Community

Browse all →