Google Gemini A.I CyberSecurity Scoring
Google Gemini
Company Information
Website:https://www.youtube.com/@thegooglegemini
Employees number:642
Number of followers:9,262
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:youtube.com
Google Gemini Risk Score (AI oriented)
Between 700 and 749
Google GeminiTechnology, Information and Internet
Updated:
15/07/2026
15/07/2026
741/1000
Moderate
Ba
Google Gemini Global Score (TPRM)
xxxx
Google GeminiTechnology, Information and Internet
Score locked

Google GeminiModerate
Current Score
741Ba (MODERATE)
01000
1 incidents
-31 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
741
JUNE 2026
741
MAY 2026
740
APRIL 2026
740
MARCH 2026
770
Cyber Attack
23 Mar 2026 • Google Gemini
Google: Hacker Used Gemini CLI to Build a Live C&C Botnet in 6 Minutes
Russian Threat Actor Leverages Google’s Gemini CLI to Build AI-Powered C&C Botnet in Six Minutes
739
LOW-31
GOO1784139935
Russian Threat Actor Leverages Google’s Gemini CLI to Build AI-Powered C&C Botnet in Six Minutes
A Russian-speaking threat actor, identified as bandcampro, has exploited Google’s Gemini CLI AI agent to automate the migration, deployment, and operation of a live command-and-control (C&C) botnet completing the entire process in just six minutes with minimal human input. Research from Trend Micro, published on July 13, 2026, analyzed over 200 Gemini CLI session logs spanning March 19 to April 21, 2026, revealing how the attacker used AI to handle architecture, coding, deployment, and debugging with near-total autonomy.
The incident began on March 23, 2026, when the actor’s existing C&C infrastructure reliant on Cloudflare tunnels was blocked by firewalls and antivirus software. Instead of manually rebuilding, the attacker issued a single Russian-language prompt: “Study the C&C migration.” Gemini CLI responded by autonomously writing the C&C server code, deploying it on a fresh VPS, configuring Cloudflare tunnels, and bringing the infrastructure online by 12:48 UTC just six minutes after the initial request. The AI later diagnosed and resolved a “split-brain” issue caused by Cloudflare load-balancing traffic across old and new servers, and even modified the code to include a browser-style User-Agent header when the WAF blocked requests all without human intervention.
The botnet’s architecture is stripped to its minimal viable form, consisting of three plain-text files totaling 5KB:
- GEMINI.md: Jailbreaks the AI by framing operations as “authorized penetration testing” and auto-saves credentials.
- SKILL.md: Outlines the full C&C playbook, including infection commands, persistence mechanisms, and troubleshooting.
- C2_MIGRATION_GUIDE.md: Provides a six-step deployment guide to restore operations on any new VPS in minutes.
The AI-controlled botnet targeted eight compromised machines in a dental clinic, granting the actor access to the OpenDental patient database. The C&C server, an in-memory Python HTTP server, leaves no forensic trail, using /api/v1 paths to blend with legitimate traffic. Victim machines run a PowerShell beacon polling the server every five seconds over HTTPS. Persistence mechanisms adapt based on privilege level:
- Administrator rights: Copies powershell.exe to %APPDATA%\Microsoft\Windows\Runtime\svchost.exe and configures a WMI event subscription.
- Non-admin rights: Hijacks HKCU:\Environment\UserInitMprLogonScript or registers a disguised scheduled task.
The botnet’s simplicity makes it resilient if detected, the actor regenerates fresh artifacts (filenames, registry keys, API paths) via AI prompts, eliminating the need for obfuscation. Beyond the C&C operation, the logs reveal broader AI-assisted criminal activity, including:
- Credential mutation: Pulling passwords from the AntiPublic database and using Gemini CLI to generate variants for brute-force attacks on WordPress admin panels.
- Reconnaissance: Mapping a victim’s VPN, MFA setup, and internal admin panels from a 1Password dump.
- Fraud planning: Consulting the AI on telephone-based cryptocurrency scams targeting elderly victims in the U.S. and Canada, yielding psychological manipulation scripts.
Across the month-long logs, the AI generated 89% of the total text output, handling 80% of architectural decisions, 100% of coding, and 90% of debugging. The actor jailbroke Gemini CLI using GEMINI.md, which falsely labeled the operations as legitimate penetration testing. While some guardrails held such as the AI’s refusal to create a self-spreading “agent-bomb” the logs show the actor pivoting to manual workarounds when restrictions were triggered.
The incident underscores a shift in botnet economics: where takedowns once required skilled operators, a non-technical actor can now restore full operations in minutes using a 5KB text file. Defenders are advised to monitor for behavioral indicators, including:
- 5-second HTTP GET polling to /api/v1/update.
- PowerShell execution from %TEMP% with filenames like win_update_svc_*.
- WMI subscriptions or svchost.exe running from %APPDATA%\Microsoft\Windows\Runtime\.
Key indicators of compromise include the malicious domain payloads.tralalarkefe[.]com, the X-Agent-ID HTTP header (formatted as COMPUTERNAME_USERNAME), and persistence mechanisms like the Win32_PerfFormattedData_PerfOS_System WMI filter.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
770
JANUARY 2026
770
DECEMBER 2025
770
NOVEMBER 2025
770
OCTOBER 2025
770
SEPTEMBER 2025
770
AUGUST 2025
770
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Google Gemini ??
What was Google Gemini's A.I Rankiteo Cyber Score in June 2026 ??
What was Google Gemini's A.I Rankiteo Cyber Score in May 2026 ??
What was Google Gemini's A.I Rankiteo Cyber Score in April 2026 ??
What was Google Gemini's A.I Rankiteo Cyber Score in March 2026 ??
What was Google Gemini's A.I Rankiteo Cyber Score in February 2026 ??
What was Google Gemini's A.I Rankiteo Cyber Score in January 2026 ??
What was Google Gemini's A.I Rankiteo Cyber Score in December 2025 ??
What was Google Gemini's A.I Rankiteo Cyber Score in November 2025 ??
What was Google Gemini's A.I Rankiteo Cyber Score in October 2025 ??
What was Google Gemini's A.I Rankiteo Cyber Score in September 2025 ??
What was Google Gemini's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Google Gemini's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Google Gemini ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Google Gemini's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?