Theregister
Russian Hacker Exploits Jailbroken Gemini to Target MAGA Crypto Users
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A Russian-speaking hacker, identified as bandcampro, utilized a jailbroken Google Gemini to execute a cybercrime campaign targeting MAGA supporters from September 2025 to May 2026. The operation involved impersonating an American veteran and running a Telegram channel to distribute malware disguised as a cryptocurrency wallet. The attacker successfully compromised at least one victim's crypto wallet by stealing passwords and mnemonic phrases. The campaign leveraged AI-generated content and a brute-forcing tool to crack WordPress admin credentials. TrendAI researchers uncovered the attack infrastructure in May 2026, revealing the sophistication of the methods employed. The attack primarily aimed at cryptocurrency fraud rather than political motives, despite its MAGA-themed influence. The hacker's operational costs were minimal, relying mainly on stolen API keys. The incident highlights vulnerabilities in AI systems and the potential for exploitation in cybercrime.
Key Points: • A Russian hacker used a jailbroken Google Gemini to target MAGA supporters. • At least one cryptocurrency wallet was fully compromised during the operation. • The attack utilized AI-generated content and brute-forcing techniques to gain access.