Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors bandcampro

Also known as: Popa, tracked as, Gallium, has a nearly, TeamPCP, approximately 17, 000 subscribers, pivoted to AI-automated content, fraud, including smart TVs, streaming boxes, Dort, 23, Ottawa, Canada, operation of the botnet

Description

A solo Russian-speaking threat actor tracked as 'bandcampro' operated a five-year MAGA-themed Telegram channel with approximately 17,000 subscribers, initially forwarding cryptocurrency scam content before pivoting to AI-automated operations in September 2025. The actor utilized jailbroken Google Gemini to generate QAnon-styled posts, deploy infrastructure, manage stolen API keys, and run credential theft operations targeting politically engaged American audiences. The campaign weaponized cultural alignment with QAnon and MAGA communities to facilitate cryptocurrency fraud rather than political influence. Through AI assistance, the actor cracked 29 WordPress admin credentials, infiltrated at least one company, deployed remote access trojans disguised as cryptocurrency wallets, and operated a gamified chatbot called 'QFS 2.0 Terminal'. The operation demonstrates how frontier AI systems enable scalable, low-cost cybercriminal activities by allowing a single actor to perform tasks traditionally requiring enti...

Goals & Targeting

Targeted Sectors

Financial services
Healthcare
Defense
Government
Critical infrastructure
Education
Telecommunications
Manufacturing
Energy
Aerospace
Maritime
Retail
Hospitality
Entertainment

Targeted Countries / Regions

United States of America
US
CA
CN
IN
NG
GB
RU
KP

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Resource Development
1 technique
Stealth
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.trendmicro.com — Cited by web research for: approximately 17
  2. thehackernews.com — Cited by web research for: including smart TVs
  3. www.trendmicro.com — Cited by web research for: Payload
  4. www.malwarepatrol.net — Cited by web research for: RansomHub
  5. www.theregister.com — Cited by web research for: Government
  6. www.calmcoding.dev — Cited by web research for: UK
  7. the420.in — Cited by web research for: North Korea

Intel Summary

4

Techniques

45

Tools

0

Campaigns

36

IOCs

0

Observed Data

3

Tactics

Tags

Financial Targeting
Critical Infrastructure
Backdoor / C2
Data Exfiltration

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.