Also known as: Popa, tracked as, Gallium, has a nearly, TeamPCP, approximately 17, 000 subscribers, pivoted to AI-automated content, fraud, including smart TVs, streaming boxes, Dort, 23, Ottawa, Canada, operation of the botnet
A solo Russian-speaking threat actor tracked as 'bandcampro' operated a five-year MAGA-themed Telegram channel with approximately 17,000 subscribers, initially forwarding cryptocurrency scam content before pivoting to AI-automated operations in September 2025. The actor utilized jailbroken Google Gemini to generate QAnon-styled posts, deploy infrastructure, manage stolen API keys, and run credential theft operations targeting politically engaged American audiences. The campaign weaponized cultural alignment with QAnon and MAGA communities to facilitate cryptocurrency fraud rather than political influence. Through AI assistance, the actor cracked 29 WordPress admin credentials, infiltrated at least one company, deployed remote access trojans disguised as cryptocurrency wallets, and operated a gamified chatbot called 'QFS 2.0 Terminal'. The operation demonstrates how frontier AI systems enable scalable, low-cost cybercriminal activities by allowing a single actor to perform tasks traditionally requiring enti...
Targeted Sectors
Targeted Countries / Regions
No AI analysis yet.
No campaigns linked yet.
No observed data linked yet.
4
Techniques
45
Tools
0
Campaigns
36
IOCs
0
Observed Data
3
Tactics