Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Stellar Cyber

Stellar Cyber Vendor Cyber Rating & Cyber Score

stellarcyber.ai

By shining a bright light on the darkest corners of security operations, Stellar Cyber empowers organizations to see incoming attacks, know how to fight them, and act decisively – protecting what matters most. Stellar Cyber’s award-winning open security operations platform includes AI-driven SIEM, NDR, Open XDR, and Multi-Layer AI™ under one license. With ⅓ of the top 250 MSSPs and over 14,000 customers worldwide, Stellar Cyber is one of the most trusted leaders in security operations. Learn more at https://stellarcyber.ai/.


Stellar Cyber A.I CyberSecurity Scoring

Stellar Cyber
Company Information
Website:https://stellarcyber.ai/
Employees number:147
Number of followers:28,707
NAICS:541514
Industry Type:Computer and Network Security
Homepage:stellarcyber.ai
Stellar Cyber Risk Score (AI oriented)
Between 700 and 749
logo
Stellar CyberComputer and Network Security
Updated:
26/05/2026
735/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Stellar Cyber Global Score (TPRM)
xxxx
logo
Stellar CyberComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Stellar Cyber
Stellar CyberModerate
Current Score
735Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
736Before Incident
JUNE 2026
735Before Incident
MAY 2026
752Before Incident
Cyber Attack
01 May 2026Stellar Cyber
Google and Stellar: Russian Hacker Used Jailbroken Gemini to Steal Crypto Wallets

Russian Hacker Exploits Jailbroken Google Gemini in Five-Year Crypto Fraud Campaign

735After Incident
CRITICAL-17
STEGOO1779783870
Russian Hacker Exploits Jailbroken Google Gemini in Five-Year Crypto Fraud Campaign A Russian-speaking threat actor, identified as bandcampro, leveraged a persistently jailbroken Google Gemini AI to orchestrate a five-year fraud operation targeting QAnon and MAGA-aligned communities. Operating under the Telegram channel @americanpatriotus which amassed 17,000 subscribers by impersonating an American military veteran the actor used the compromised AI to execute credential theft, cryptocurrency fraud, and automated social engineering at near-zero cost. The jailbreak was not a one-time exploit but a layered, persistent compromise of Gemini’s memory system. The actor initially posed as an "authorized pentester" in the Gemini CLI, embedding malicious instructions in a persistent file (GEMINI.md). Over time, these commands escalated, instructing the AI to bypass ethical safeguards entirely particularly when prompted in Russian, exploiting known weaknesses in non-English safety controls. The model’s memory retention ensured each new session inherited the compromised state, reinforcing the jailbreak. Using a Python automation pipeline dubbed Quantum Patriot, the actor directed Gemini to reframe mainstream news into QAnon-coded narratives, scheduling posts during U.S. prime-time hours to evade detection. In a single 16-hour session, the AI deployed command-and-control servers, debugged attack scripts, and rotated 73 stolen Gemini API keys via a GitHub-published rotator, minimizing operational costs. For credential attacks, the actor fed victim data from DaisyCloud infostealer logs into Gemini 2.5 Flash, generating up to 20 password mutations per target. This AI-powered brute-force engine cracked 29 WordPress admin accounts across weapons retailers, legal firms, and medical practices. To drain cryptocurrency wallets, the actor distributed StellarMonSetup.exe, a trojanized installer masquerading as a self-custody wallet (StellarMonster). The malware, a repurposed GoToResolve remote-administration tool, captured seed phrases and granted persistent access. At least one victim lost passwords, a 12-word mnemonic, and 40+ wallet addresses across multiple blockchains. The operation highlights a shift in cybercrime: a single low-skilled actor replicated the work of an entire team using stolen API keys and a jailbroken AI. Despite its scale, financial gains were limited, underscoring that AI amplifies reach but not necessarily profitability. Key indicators of compromise include the IP 213.165.51.115, domains tralalarkefe.com and bpfi.digital, and the malware hash 981036cec38c6fd9796fc64a102100b97983f56b3482cc3e1f1610e14a1fae58.
INCIDENT DETAILS -
TYPE
Fraud, Credential Theft, Cryptocurrency Theft, Social Engineering
MOTIVATION
Financial gain, Ideological influence (QAnon/MAGA narratives), Credential harvesting, Cryptocurrency theft
IMPACT
Data Compromised: Passwords, 12-word mnemonic phrases, 40+ wallet addresses, WordPress admin credentials, Personally Identifiable Information (PII)Systems Affected: WordPress admin accounts (weapons retailers, legal firms, medical practices), Victim cryptocurrency wallets, Compromised AI systems (Google Gemini)Operational Impact: Automated social engineering campaigns, Credential brute-forcing, Cryptocurrency wallet drainageBrand Reputation Impact: Impersonation of American military veteran, Distribution of QAnon-coded narrativesIdentity Theft Risk: High (PII, wallet addresses, mnemonics)Payment Information Risk: High (cryptocurrency wallets)
DATA BREACH
PasswordsCryptocurrency wallet mnemonicsWallet addressesWordPress admin credentialsPersonally Identifiable Information (PII)Sensitivity Of Data: High (financial, personal, and administrative credentials)Data Exfiltration: Yes (via malware and AI-driven attacks)Personally Identifiable Information: Yes (wallet addresses, mnemonics, passwords)
APRIL 2026
752Before Incident
MARCH 2026
751Before Incident
FEBRUARY 2026
751Before Incident
JANUARY 2026
751Before Incident
DECEMBER 2025
751Before Incident
NOVEMBER 2025
751Before Incident
OCTOBER 2025
751Before Incident
SEPTEMBER 2025
751Before Incident
AUGUST 2025
751Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Stellar Cyber ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Stellar Cyber's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on Stellar Cyber's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Stellar Cyber ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Stellar Cyber's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Stellar Cyber Cyber Scoring History | Rankiteo