PULSE NAME
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud 'Patriot Bait' Campaign
WHITE bandcampro AlienVault 2026-05-21 Modified: 2026-05-22
19
IOCs
MEDIUM VOLUME
A solo Russian-speaking threat actor tracked as 'bandcampro' operated a five-year MAGA-themed Telegram channel with approximately 17,000 subscribers, initially forwarding cryptocurrency scam content before pivoting to AI-automated operations in September 2025. The actor utilized jailbroken Google Gemini to generate QAnon-styled posts, deploy infrastructure, manage stolen API keys, and run credential theft operations targeting politically engaged American audiences. The campaign weaponized cultural alignment with QAnon and MAGA communities to facilitate cryptocurrency fraud rather than political influence. Through AI assistance, the actor cracked 29 WordPress admin credentials, infiltrated at least one company, deployed remote access trojans disguised as cryptocurrency wallets, and operated a gamified chatbot called 'QFS 2.0 Terminal'. The operation demonstrates how frontier AI systems enable scalable, low-cost cybercriminal activities by allowing a single actor to perform tasks traditionally requiring enti...
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
GoToResolve
Indicators of Compromise (19)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 ea1c409fdcb6dca6751c443aeed13441 2026-05-21
FileHash-SHA1 9bf39391f9c0ce989ee53c02170d7885c6c23798 2026-05-21
FileHash-SHA256 981036cec38c6fd9796fc64a102100b97983f56b3482cc3e1f1610e14a1fae58 2026-05-21
IPv4 213.165.51.115 2026-05-21
domain bpfi.digital 2026-05-21
domain dzbank.capital 2026-05-21
domain indus.exchange 2026-05-21
domain induspayments.com 2026-05-21
domain indusx.tech 2026-05-21
domain tralalarkefe.com 2026-05-21
hostname c2.tralalarkefe.com 2026-05-21
hostname catchall1.tralalarkefe.com 2026-05-21
hostname docs.bpfi.digital 2026-05-21
hostname payloads.tralalarkefe.com 2026-05-21
hostname security.bpfi.digital 2026-05-21
hostname www.bpfi.digital 2026-05-21
hostname www.dzbank.capital 2026-05-21
hostname www.indusx.tech 2026-05-21
domain vebrf.digital 2026-05-21