Home AISix Minutes to Compromise: How the ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet

Six Minutes to Compromise: How the ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet

by OmarAli
Six Minutes to Compromise: How the 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet

Although the actor managed to jailbreak the AI ​​agent and bypass its security controls for the above operations, the guardrail was still triggered in some cases. In cases where the AI ​​protections were triggered and could not be bypassed, the logs showed that the threat actor gave up and moved on to other tasks.

Beyond the botnet

The C&C deployment was just one part of a broader AI-powered campaign documented in the meeting minutes. TrendAI™ Research read Gemini CLI logs for over a month, which revealed a much broader range of intent.

The actor effectively “used” the AI ​​model for daily operations such as setting up a proxy for home users, performing multi-threaded password scans, installing software, writing code to call third-party APIs, processing infostealer dumps, and even exploring websites. In practice, the AI ​​acted as a proactive technical collaborator in the actor’s operations.

The logs also showed that on several other occasions when guardrails were triggered, the AI ​​agent provided the actor with friendly and helpful suggestions for manual workarounds, as shown in Figure 6.

Crack password

The actor used AI as a large-scale credential mutation machine. The actor leveraged the AntiPublic Credentials Database API, pulled all old and new passwords associated with a target email, and then passed the list of passwords to the model to predict possible variants.

These AI-generated estimates were more efficient than random estimates. They are fed into a WordPress admin panel brute force tool, and the actor has actually had some success.

Exploitation of credentials

In another case, the perpetrator provided a 1Password dump and the AI ​​figured out which company the victim had access to and found a way to use Duo and the company’s VPN. Even an internal admin panel was figured out.

Although the actor didn’t succeed in the end, it was only because the context window was too long and the model couldn’t track what he was doing.

Cryptocurrency scam planning

The actor also discussed with AI the feasibility of setting up a phone-based cryptocurrency fraud scheme targeting the elderly in the US and Canada. The actor had the AI ​​hack a major online e-commerce site using stolen cookies and create a fraud bot based on psychological manipulations also recommended by the AI.

Conclusion and safety recommendations

The article explained a real-world case where a C&C framework was built, deployed, and operated entirely through a generative AI coding agent.

Over the entire log month, the actor contributed 11% of the text produced and the AI ​​contributed 89%, i.e. twelve times the actor’s word count. The actor provided strategic direction and acted as product manager, while the AI ​​represented its entire engineering team, handling 80% of the architecture design, 100% of the coding and system instruction execution, and 90% of problem diagnosis and resolution. During the C&C migration session alone, the AI ​​made 59 unsolicited suggestions or improvements.

In the age of AI, a successful criminal business no longer depends on skills and experience, but on imagination, creativity and how well a threat actor can work with AI agents.

The portable skill file model means this methodology is likely to become widespread. The skill file is plain text, unlikely to be detected by traditional malware scanners on its own, can be shared in forums, and modified in seconds. It turns any capable AI coding agent into a C&C operator if they can successfully convince the built-in security mechanisms in AI agents. The nature of instruction-following models is that they are pleasant and therefore susceptible to tricks of human psychology just to comply with the requests given to them. Even though Gemini was used in this case, any powerful AI model could be fooled by various jailbreaking techniques.

As AI continues to reduce the cost and complexity of operating malicious infrastructure, it is very likely that we will see more AI-powered malicious infrastructure in the future.

Static defenses based on known indicators cannot keep up with an opponent who can regenerate any artifact on demand. The following defense strategies instead address the underlying behaviors:

  • Prioritize behavioral detection over static indicators. AI can rotate filenames, registry keys, and API paths as needed. Focus on what remains constant: recurring outbound queries, PowerShell execution from non-standard locations, and WMI subscriptions created at runtime.
  • Protect your login credentials from AI-powered password attacks. Enforce unique passwords, monitor employee credentials for database security breaches, and require phishing-resistant multi-factor authentication.
  • Plan for a quick enemy recovery. A takedown no longer means the end of the operation. Combine any server removal with network-level blocking and ongoing monitoring for reconnection attempts.

The following behavioral indicators are from the source code of this particular botnet. Parameters in bold can easily be changed by asking the AI ​​for a new version, but the underlying behavior pattern remains:

  • Fixed 5 second HTTP GET query /api/v1/update
  • Non-standard HTTP header with computer name and user name
  • Browser-style user agent string sent by a PowerShell script
  • Svchost.exe is running from a non-standard path (%APPDATA%\Microsoft\Windows\Runtime\)
  • WMI filter enabled Win32_PerfFormattedData_PerfOS_System
  • PowerShell downloads .ps1 %TEMP%\win_update_svc_*

TrendAI Vision One™ Threat Intelligence Hub

The TrendAI Vision One™ Threat Intelligence Hub provides the latest insights on emerging threats and threat actors, exclusive strategic reports from TrendAI™ Research, and TrendAI Vision One™ Threat Intelligence Feed in the TrendAI Vision One™ platform.

Emerging Threats: Patriot Bait: How Solo Operators Automated Influence, Fraud, and Credential Theft with AI

TrendAI Vision One™ Intelligence Reports (IOC Sweeping)

IOC sweep link here.

TrendAI Vision One™ XDR Data Explorer app

TrendAI Vision One™ customers can use the XDR Data Explorer app to match or hunt the malicious indicators mentioned in this blog post with data in their environment.

Additional hunt queries are available for TrendAI Vision One™ with Threat Intelligence Hub permission enabled.

Indicators of compromise

Signs of compromise can be found here.

https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html

Viral Trends

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More