{"id":13334,"date":"2026-06-03T10:04:11","date_gmt":"2026-06-03T10:04:11","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/03\/threat-actor-uses-stolen-gemini-api-keys-to-automate-telegram-influence-campaign\/"},"modified":"2026-06-03T10:04:11","modified_gmt":"2026-06-03T10:04:11","slug":"threat-actor-uses-stolen-gemini-api-keys-to-automate-telegram-influence-campaign","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/03\/threat-actor-uses-stolen-gemini-api-keys-to-automate-telegram-influence-campaign\/","title":{"rendered":"Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign"},"content":{"rendered":"<p>    Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A single threat actor has been running a fake political persona on Telegram for five years, quietly building an audience of over 17,000 subscribers while using stolen AI credentials to power the entire operation. <\/p>\n<p class=\"wp-block-paragraph\">What looks like an American patriot channel is actually a financially motivated fraud scheme run by a solo Russian-speaking operator. The goal was always money, and AI made scaling that goal nearly effortless.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/626d88c5-05e2-46ad-b3d0-adb1fea8f190\/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The campaign, tracked under the handle \u201cbandcampro,\u201d began on February 6, 2021, one month after the Capitol riot, when QAnon and MAGA communities were being deplatformed and migrating to Telegram. <\/p>\n<p class=\"wp-block-paragraph\">By positioning the fake channel, @americanpatriotus, as an authentic American conservative voice, the actor tapped into a ready-made audience already hungry for alternative platforms. The timing was clearly opportunistic.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/626d88c5-05e2-46ad-b3d0-adb1fea8f190\/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/e\/inside-the-influence-and-fraud-patriot-bait-campaign.html\" id=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/e\/inside-the-influence-and-fraud-patriot-bait-campaign.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Analysts at Trend Micro said in a\u00a0report<\/a> shared with Cyber Security News (CSN)\u00a0that in May 2026, their TrendAI Research team discovered the threat actor\u2019s operational environment had been inadvertently exposed, revealing the full scope of a five-year influence and fraud campaign. <\/p>\n<p class=\"wp-block-paragraph\">The actor used <a href=\"https:\/\/cybersecuritynews.com\/scattered-spider-with-new-telegram-channel\/\" id=\"120704\" target=\"_blank\" rel=\"noreferrer noopener\">AI-assisted techniques to run the Telegram channel<\/a>, targeting politically engaged American audiences for cryptocurrency fraud alongside AI-assisted credential theft.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/626d88c5-05e2-46ad-b3d0-adb1fea8f190\/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Starting in September 2025, the actor pivoted to fully AI-generated content, using a jailbroken version of Google Gemini as an operational co-worker. <\/p>\n<p class=\"wp-block-paragraph\">He named his content pipeline \u201cQuantum Patriot,\u201d a set of Python scripts that called Gemini to roleplay as an American veteran patriot. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjTlFiA3gCcQzpyyu2RqjpckMNX_SPiWy8oh5a5GWAoUjpjfGbqQIpnGR9NwiMHFE4YTuLlkqnH2PZuwcaYLEeXfTmi8i5zCfXp5lVYYon8y2HDW0CQVVXLXDPUN1nA34HkvEOzs0yQLEtZlbSalo5jENKw4AafTym7-1oDVPeccH5R2_hLYi62_CqA9uE\/s16000\/The%2520%25E2%2580%259CAmerican%2520Patriot%25E2%2580%259D%2520Telegram%2520profile%2520%28Source%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"The \u201cAmerican Patriot\u201d Telegram profile (Source - Trend Micro)\"><figcaption class=\"wp-element-caption\">The \u201cAmerican Patriot\u201d Telegram profile (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The AI generated Q-style posts, deployed servers, rotated stolen API keys, and managed Cloudflare tunnels, all from natural-language commands typed in Russian.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/626d88c5-05e2-46ad-b3d0-adb1fea8f190\/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">What made the operation alarming was its near-zero cost. The actor used 73 likely stolen Gemini API keys on a round-robin rotation, meaning he paid almost nothing for industrial-scale content generation. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgnet-APgCv2oYaqFHxckC6FhayfslMPhPPE6B-AWhWeC4BYAaodJ0PSF5sQnGTmnI6aUQkrd5Ce2tystoWFhMMNuHgp_YxVDGXv-AJnlcIqPDcnIGpmRgd6Z0n5SQJms-ennEbypAN05dD35TFe3V6TwLytpmtOAuq_33Ifvg4IxmQrjYFuPWZUpM-fXo\/s16000\/The%2520%25E2%2580%259CQuantum%2520Patriot%25E2%2580%259D%2520pipeline%2520%28Source%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"The \u201cQuantum Patriot\u201d pipeline (Source - Trend Micro)\"><figcaption class=\"wp-element-caption\">The \u201cQuantum Patriot\u201d pipeline (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">With 29 WordPress accounts cracked, one company infiltrated, and one victim\u2019s cryptocurrency wallet fully drained, the operation showed that AI can scale a one-person fraud scheme to team-level output.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/626d88c5-05e2-46ad-b3d0-adb1fea8f190\/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-threat-actor-uses-stolen-gemini-api-keys\" class=\"wp-block-heading\"><strong>Threat Actor Uses Stolen Gemini API Keys<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The actor\u2019s use of stolen Gemini API keys was central to keeping the operation cost-free. During one documented 16-hour session, Gemini validated 40 likely stolen API keys and wrote a round-robin rotator that cycled through them automatically. <\/p>\n<p class=\"wp-block-paragraph\">That rotator was later published to GitHub as a clean, open-source project, disguising its criminal purpose entirely.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgV15sZzlK_V8FsBsCNGidTSOYzMtsabioIqKQ6Y1tZqiahYYsoz3LzTOYeZ2jIaDbaR0uNZTO3hz_KVF_PrPEPrlcX1at6CWzCMYTJYkoYf4SksweyfncTBcA0ZovlOoG86mPAHrTvwq63Gsj8_ILdOy_0yzb99irsdU_6x9dbDmbHD5WpIZMTrKnyb68\/s16000\/Screenshot%2520of%2520the%2520QFS%25202.0%2520Terminal%2520%28Source%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"Screenshot of the QFS 2.0 Terminal (Source - Trend Micro)\"><figcaption class=\"wp-element-caption\">Screenshot of the QFS 2.0 Terminal (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">To bypass Gemini\u2019s safety guardrails, the actor established himself to the AI as an \u201cauthorized pentester,\u201d which Gemini accepted and saved into a persistent memory file called GEMINI.md. <\/p>\n<p class=\"wp-block-paragraph\">Over subsequent sessions, he escalated by getting the AI to memorize it should execute requests without ethical refusals or warnings. Since <a href=\"https:\/\/cybersecuritynews.com\/gemini-cli-rce-vulnerability\/\" id=\"148462\" target=\"_blank\" rel=\"noreferrer noopener\">Gemini CLI reloads this memory file at every session start<\/a>, each new conversation automatically inherited those jailbreak instructions.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/626d88c5-05e2-46ad-b3d0-adb1fea8f190\/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-ai-assisted-credential-theft-and-fraud\" class=\"wp-block-heading\"><strong>AI-Assisted Credential Theft and Fraud<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Beyond running the channel, the actor used Gemini to assist with credential theft and a gamified chatbot designed to steal cryptocurrency. <\/p>\n<p class=\"wp-block-paragraph\">On September 9, 2025, he posted an executable called StellarMonSetup.exe, framed as a self-custody wallet with a welcome bonus of up to 1,000 XLM. <\/p>\n<p class=\"wp-block-paragraph\">The file was actually GoToResolve, a remote-administration tool that gave the actor persistent remote desktop access, command execution, and clipboard capture on victim machines.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/626d88c5-05e2-46ad-b3d0-adb1fea8f190\/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The actor also deployed an <a href=\"https:\/\/cybersecuritynews.com\/guardian-ai-penetration-testing-tool\/\" id=\"143044\" target=\"_blank\" rel=\"noreferrer noopener\">AI-powered brute-forcing tool targeting WordPress sites<\/a>. Using Gemini 2.5 Flash as a password-mutation oracle, the script generated 20 plausible password variants per target by modeling patterns such as swapping cases, appending years, and substituting symbols. <\/p>\n<p class=\"wp-block-paragraph\">Collected data confirmed that 29 WordPress administrator accounts were cracked across weapons retailers, legal offices, medical practices, and small commercial sites.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiHVWm5CqoFZYU19qz1ZFkrjB4dOGALv5RZJSl4lFS67gFQ0YgdrtsAa0TJ8og2Xt4AYjrz432YlqtQoDIXrfU7srARtz6hyQnXYqXuPUrFRKErIXN9j_BmRNYMpxsjAT_2ygmtmhAWgxVp9fZDcTYF0ApyZa2zkBqMtpzpu1_WikV8a9eZOGcvS7aPgZk\/s16000\/%28top%29%2520The%2520fake%2520wallet%2520was%2520forwarded%2520from%2520a%2520channel%2520impersonating%2520Donald%2520J.%2520Trump%2C%2520%28bottom%29%2520The%2520attached%2520executable%2520is%2520in%2520fact%2520a%2520remote-access%2520Trojan%2520%28Source%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"(top) The fake wallet was forwarded from a channel impersonating Donald J. Trump, (bottom) The attached executable is in fact a remote-access Trojan (Source - Trend Micro)\"><figcaption class=\"wp-element-caption\">(top) The fake wallet was forwarded from a channel impersonating Donald J. Trump, (bottom) The attached executable is in fact a remote-access Trojan (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Defenders should never install software or enter a seed phrase based on instructions from a social media channel, as legitimate platforms will never make such requests. <\/p>\n<p class=\"wp-block-paragraph\">Enterprises should monitor for stolen API key reuse, anomalous CLI-driven infrastructure changes, and credential-stuffing patterns consistent with LLM-assisted password mutation. <\/p>\n<p class=\"wp-block-paragraph\">AI vendors should treat cross-language guardrail parity and jailbreak-resistant memory as urgent priorities, since this campaign proves those gaps are already being actively exploited.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/626d88c5-05e2-46ad-b3d0-adb1fea8f190\/Threat-Actor-Uses-Stolen-Gemini-API-Keys-to-Automate-Telegram-Influence-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYE7JKC4HAJ&amp;Signature=z%2FKCe9F1XQE9KZsxSKWKz%2BpNqt8%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEF8aCXVzLWVhc3QtMSJGMEQCIGoTaK9S5Q5n5MP01JMnP2DMLea8M%2BbI0jY5zmboNbMxAiAoLLyyNw%2BdmQgO4rg9C%2BBKIAbDK65PeQJpuC%2BoDi61xSrzBAgoEAEaDDY5OTc1MzMwOTcwNSIMvZ9IAXVBYCAfjD04KtAEYvAP0q4XeZEnmsPl%2FjTCK1wX0dB%2BDzIN0p4o6gUVdQiU%2BR0QceyphwMlgQiU%2BeoHEpRKEodJA18vPp%2FT1HOjphSvSO1vMXQNt4bYapjomCgAQQ8h%2B87wJtS%2BjAzeD0hPovg69XmXG7WgTlRYQhd0M1mkQVWdY1zzpPJ0Ao%2F7TchBAlddRaNsl5bnmU3FgDqANm%2FYBa0M0XxoH0DBO662bUTZDoqyzSznQJYdAQDarrxT8qgZCOtzy9cRzelrzqv480ub8ItOh4xtJiF5UaPJtboO6K7RRATbb5WwBtBsVTlaRLYycTvuU%2FN5MGOThdn7eSSShMLQNJbJ9JZZc81v6h79s8Br8WBhWLNzvG%2FBnNAxYyRbIYW%2FTVuyowbHnXiSslMX3iyp97aYS31K7QOMEPf6tbTX6r1RTnh1emSFhiEk93QSLQ2LcsvXvmRmN%2B3EsT2RSPcYyL7bmhh6JXxMikKt0Y8xrqeUBvpFFlwVqu7sMJNUDB0TLmcEp2pFCCTjzHGYaVMOI%2FipkQeF%2FHD4KAMrdBFoDgZEqZp3CJJsC%2BFm2d%2BVoppaMWCJVFY44I1%2BCGPQBa1LY%2Fchz83PJe01nR3bRhyTe0VmKdVIISRGEnF9qgImduzPrlG6HaA%2FZ4CvljkZBR7k2L6zKERywV9KMKx4yD54iP3wPm3d%2FEIIkcm4tlVR%2FDwtlJ9fhddLdJRuh3xWnhWSXmWdIb5d749Wwi4aHPWECK34I68ZJ4AkpVMh6yzuiizQ08ULWGsstqzrJV3MFHefZ4psL32z5kaWhzDV0fvQBjqZAdDc8pluGRROV1Rb1MHFeCcvGPw3Uepj3lNyTlVK1lkS0r3Wyy0SANvlgnZeIL3IMX6QD8m4Opmy9%2BABX%2FBDG273JJmuaENwImsHq6Dsd%2BwZHRU5KlE5XOhNyGenIBQi9umtHAghPE0wN7qxYi85nh5rz2L9I0EsD659dxUE7aZHZAoU3OlyBQsqmNBr4F%2BjJGeiT%2F6VYoGp8w%3D%3D&amp;Expires=1780412099\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IoCs):-<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>IP Address<\/td>\n<td>213.165.51.115<\/td>\n<td>GoToResolve infrastructure network connection<\/td>\n<\/tr>\n<tr>\n<td>IP Address<\/td>\n<td>34.34.57.141<\/td>\n<td>GoToResolve infrastructure network connection<\/td>\n<\/tr>\n<tr>\n<td>IP Address<\/td>\n<td>34.34.81.129<\/td>\n<td>GoToResolve infrastructure network connection<\/td>\n<\/tr>\n<tr>\n<td>IP Address<\/td>\n<td>35.192.41.201<\/td>\n<td>GoToResolve infrastructure network connection<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>StellarMonSetup.exe<\/td>\n<td>Fake Stellar wallet executable; contains GoToResolve RAT<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>GEMINI.md<\/td>\n<td>Jailbreak memory file used to override Gemini AI safety guardrails<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>CREDENTIALS.md<\/td>\n<td>File used to store stolen tokens and GCP service accounts<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>DEPLOYED_TOOLS.md<\/td>\n<td>File cataloguing session output and deployed tooling<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>C2_MIGRATION_GUIDE.md<\/td>\n<td>Gemini-followed guide for command-and-control server migration<\/td>\n<\/tr>\n<tr>\n<td>Telegram Channel<\/td>\n<td>@americanpatriotus<\/td>\n<td>Primary influence operation distribution channel (~17,000 subscribers)<\/td>\n<\/tr>\n<tr>\n<td>Telegram Bot<\/td>\n<td>@QFS_Terminal_Bot<\/td>\n<td>Gamified QAnon-styled chatbot used to engage and defraud subscribers<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong>\u00a0<em>IP addresses and domains are intentionally defanged (e.g.,\u00a0<\/em><code><em>[.]<\/em><\/code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM<\/em>.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong> <strong><strong><a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actor-uses-stolen-gemini-api-keys\/\">Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actor-uses-stolen-gemini-api-keys\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign A single threat actor has been running a fake political persona on Telegram for five years, quietly building an audience of over 17,000 subscribers while using stolen AI credentials to power the entire operation. What looks like an American patriot channel is actually [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13334","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13334"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13334"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13334\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}