【CyCraft Monthly Intelligence】AI-Powered Lone-Wolf Operations: Analysis of "Patriot Bait" Influence Manipulation and Fraud Techniques

AI-Powered Lone-Wolf Operations: Analysis of "Patriot Bait" Influence Manipulation and Fraud Techniques
Threat andImpact

The"Patriot Bait" campaign illustrates how a financially motivatedcybercriminal combined social engineering, AI automation, credential theft, andcryptocurrency fraud into a long-term, stealthy cyber operation. According toexisting threat intelligence, the threat actor operating under the handle"bandcampro" is a solo, Russian-speaking malicious operator.Operating through the Telegram channel @americanpatriotus, they cultivated a fraudulentAmerican conservative persona that currently has approximately 17,000subscribers.

Unliketraditional campaigns focused primarily on political influence, the"Patriot Bait" operation appears to be driven mainly by profit."bandcampro" impersonated American "patriot" and"veteran" personas to build trust among politically engaged U.S.audiences—specifically targeting MAGA, QAnon, NESARA/GESARA, andcryptocurrency-focused communities. Once the audience was established, thechannel became a vehicle to promote cryptocurrency, distribute fake wallets,steal credentials, and execute scams.

A landmarkimplication of this incident is how AI automation services have lowered thebarrier to entry for individual cybercriminals: starting around September 2025,the actor began using AI not only to write content, but also to operationalizekey aspects of the campaign. Threat intelligence indicates that a jailbrokenGoogle Gemini instance served as an operational assistant—generating QAnon-styleposts, eliminating Russian linguistic footprints, managing infrastructure,rotating stolen API keys, and supporting password-guessing activities.Furthermore, the actor leveraged Venice AI ("Private AI for UnlimitedCreative Freedom") to power a QFS-themed chatbot, maintaining userengagement through financial conspiracy narratives and gamified "clearancelevels."

This campaigndemonstrates that AI-driven fraud no longer requires large teams. Activitiesthat previously demanded copywriters, social media managers, softwaredevelopers, infrastructure administrators, and credential attackers can now beexecuted by a single individual utilizing AI tools, Telegram automation, stolenAPI keys, and commercial remote access software—creating a scalable model forlow-cost influence manipulation and fraud operations in the future.

While thedirect impact of this campaign was contained, it was nonetheless significant.Researchers noted that the actor had:

  • Cracked 29 WordPress administrator accounts.
  • Infiltrated at least one corporate entity.
  • Completely compromised at least one cryptocurrency wallet.
  • Leveraged 73 suspected stolen Gemini API keys.
  • Distributed fake cryptocurrency wallet installers weaponized withrepackaged remote management tools.
  • Targeted a Telegramaudience of approximately 17,000 subscribers.

The affectedWordPress accounts belonged to small businesses and organizations spanning armsretail, legal services, medical clinics, and small commercial websites. Thesesectors are inherently vulnerable because many small organizations rely heavilyon WordPress while lacking adequate cybersecurity personnel, leading to poorpassword hygiene, inconsistent multi-factor authentication (MFA) adoption, andvirtually no monitoring for credential attacks.

For individualvictims, the risks were severe. The fake wallet installer—named"StellarMonster" and distributed as StellarMonSetup.exe—was actually a repurposedversion of GoToResolve, a legitimate remote management tool. Once installed, itgranted the actor persistent remote desktop control, file access, commandexecution, and clipboard capture. The fake wallet's import feature alsoprovided a direct pipeline for harvesting seed phrases. At least one victim hadtheir wallet password cracked, their 12-word recovery seed phrase stolen, andover 40 wallet addresses harvested across major blockchains.

For businesses,the impact extended beyond compromised accounts. Compromised WordPress adminaccounts allowed attackers to deface websites, host malicious files, redirectvisitor traffic, exfiltrate customer data, plant phishing pages, or repurposethe sites as infrastructure for follow-on attacks. In regulated industries suchas healthcare and legal services, even a breach of a small website can triggersevere reputational, operational, and regulatory compliance risks.

This incidentalso highlights broader threat vectors facing AI platforms and enterprisesconsuming AI services. The actor's use and automated rotation of stolen APIkeys demonstrate how abused AI access can become part of a criminal supplychain. Organizations failing to detect leaked or abused API keys risk havingtheir paid AI resources depleted, malicious workflows automated on their dime,and operational costs obscured within compromised accounts.

In summary, the "Patriot Bait" operation exemplifies anemerging model of AI-assisted cybercrime: low-cost, persona-centric, socialengineering-driven, and financially motivated. Although the observed financiallosses were not massive, the campaign demonstrates how a single actor—bycombining AI systems, stolen credentials, and trusted online communities—canrapidly scale influence manipulation, credential harvesting, and cryptocurrencyfraud.

Analyst Perspective

This campaigndoes not appear to be a nation-state operation. Despite Russian linguisticmarkers associated with the actor, researchers found no meaningful pro-Russianmessaging, indicating that the political persona was cultivated solely asfinancial bait. The actor leveraged pre-existing audience beliefs, culturalrhetoric, and trust signals to make the fraud blend seamlessly into thecommunity's ideological norms.

Consequently,the broader impact lies not merely in the confirmed victim count, but in thereplicability of this operational model. Any tightly-knit onlinecommunity—whether political, financial, religious, gaming, activist, orprofessional—can be targeted using similar techniques. Authentic personas,AI-generated content, automated interactions, and financial incentives can beintegrated into a low-cost, continuous fraud pipeline that end users findnearly impossible to distinguish from genuine community activity.

Technical Details

"PatriotBait" was not a traditional intrusion campaign executed by a large team orsophisticated malware developers. Its technical significance lies in how asingle Russian-speaking actor combined social engineering, AI automation,stolen AI API access, commercial remote management software, and weakcredential management to carry out a multi-year influence manipulation andfraud operation.

The success ofthis campaign stemmed from multiple vulnerabilities: AI safety guardrails thatcould be bypassed and sustained through memory files, stolen or leaked GeminiAPI keys that brought automation costs close to zero, user trust in apolitically aligned Telegram persona, victim willingness to install unverified"wallet" software, and weak or reused WordPress administratorpasswords.

Trackedas bandcampro, the threat actor leveraged AI as a virtual personalassistant across almost every phase of the campaign, including contentgeneration, infrastructure setup, API key rotation, credential attacks, chatbotoperation, and cryptocurrency fraud planning.

Reconnaissance

The actorconducted reconnaissance targeting both the influence campaign audience andtechnical credential theft targets.

For credentialattacks, the actor gathered target-specific intelligence from multiple sources,including purchased DaisyCloud info-stealer logs, LinkedIn profiles, emailaddresses, and context from previous successful logons. This context was fedinto Gemini to generate targeted password variations. Rather than relyingsolely on static dictionary lists, the actor leveraged contextualreconnaissance to make password guessing significantly more targeted.

The actor alsoresearched specialized cryptocurrency fraud tactics targeting North Americanvictims, studying how call centers utilize personal data for voice phishing(vishing) and how to design crypto-scam lures. This indicates that the socialengineering component of the campaign was informed by established fraudplaybooks.

Resource Development

The actor developed and acquiredmultiple resources to support the campaign. They built an AI-assisted contentproduction pipeline named "Quantum Patriot," consisting of Pythonscripts that used Gemini to convert news links into QAnon-style Telegram posts.Generated posts could be sent privately to the actor for review prior topublication or scheduled for automated posting. The system also featuredscheduling logic designed to emulate a human operator in the U.S., suppressingposts late at night and concentrating output during peak hours in the U.S.Eastern Time zone.

Another coreresource was the QFS-themed Telegram bot @QFS_Terminal_Bot, branded as "QFS 2.0 Terminal." It catered to QAnon/NESARAcommunity beliefs regarding a secret Quantum Financial System. The bot employedmilitary-style terminology—such as [INTEL], [STATUS], [ENCRYPTED], Protocol 1776, and DigitalSoldier—andimplemented a referral-based hierarchy where users unlocked higher"clearance levels" and increased daily AI query allowances byrecruiting others.

The actor alsodeveloped and deployed technical infrastructure with AI assistance. In oneobserved session, Gemini assisted in server deployment, executing instructionsfrom C2_MIGRATION_GUIDE.md, unpacking software archives,patching binary path errors, updating Python code, debugging deployments,terminating legacy servers, configuring Cloudflare Tunnels, and setting uptools on a Netherlands-based virtual machine. This infrastructure hosted emailtesting tools, a Gmail aggregator, and anonymizing proxies.

A key resourcewas a pool of 73 suspected stolen Gemini API keys. The actor pasted batches ofkeys into Gemini for validation and tasked Gemini with building a cycling APIkey rotator featuring cooldown logic. This distributed requests across stolenkeys, keeping operational costs near zero while mitigating the risk ofoperational disruption if individual keys hit quota limits or triggered abusedetections.

The actorrepurposed GoToResolve, a legitimate remote management tool, masquerading it asa fake cryptocurrency wallet installer named StellarMonSetup.exe ("StellarMonster"). Additionally, they purchasedor utilized info-stealer logs and developed an AI-assisted WordPressbrute-forcing tool, ultimately compromising 29 WordPress admin accounts.

Initial Access

Initial access was primarily obtained through two vectors:social engineering users into installing a fake cryptocurrency wallet, andcompromising WordPress administrator credentials.

The fake walletcampaign began on September 9, 2025, when the threat actor posted StellarMonSetup.exe in the Telegram channel.Advertised as "StellarMonster," a "freedom-first, self-custodialwallet," it promised rewards of up to 1,000 XLM. In reality, the installerdeployed GoToResolve, granting the actor remote access to the victim's system.

This techniquerelied on long-term trust built through the Telegram persona. Subscribers weretargeted from within a community channel operating for years, rather thanreceiving unsolicited phishing emails. The malware lure aligned with thechannel's pre-existing cryptocurrency, QFS, GESARA, and financial resetnarratives.

The fake walletalso included an "Import Wallet" feature. When victims entered theirseed phrases into the fake import interface, they handed their recovery keysdirectly to the actor. This provided initial access not only to the endpoint,but also to their cryptocurrency assets.

Additionally,the actor accessed WordPress admin accounts using stolen or guessedcredentials. Intelligence reports attribute the compromise of 29 WordPressadmin accounts to an AI-driven password-mutation brute-forcing tool. Theseattacks appeared to exploit weak, predictable, or reused passwords rather thancore WordPress or plugin vulnerabilities.

Execution

Execution occurred when users ran the fake wallet installer,as well as on the actor's infrastructure as scripts and tools were operated.

On victimmachines, execution initiated via StellarMonSetup.exe. Once launched, the installerdeployed or enabled GoToResolve under the guise of the StellarMonster walletapplication. Because GoToResolve is a legitimate commercial remote managementtool, the actor did not need to compile custom malware. Running this toolgranted the actor interactive remote desktop access, file access, commandexecution, and clipboard capture capabilities.

On the actor'sside, execution activities included running the "Quantum Patriot"pipeline, Telegram bot automation, API key validation and rotation, C2migration, infrastructure deployment, and Python scripts for WordPressbrute-forcing. Gemini served as a coding and debugging assistant, helping theactor patch binary paths, update code, adjust script behavior, and automateworkflows.

The QFS 2.0 Terminal bot also served as an execution layer within thefraud funnel—interacting with users, maintaining engagement, and gamifyingreferrals through automated clearance mechanisms.

Persistence

Persistence onvictim endpoints was achieved primarily through the abuse of GoToResolve.

Designed forunattended remote administration, GoToResolve—when repurposed as a RemoteAccess Trojan (RAT) via the fake StellarMonster installer—granted the actorpersistent remote desktop sessions and continuous host access. This enabled theactor to reconnect, browse files, execute commands, and monitor clipboardactivity long after initial installation. This persistence mechanism waseffective because it utilized a legitimate remote support tool rather thanobvious custom malware, making it harder for security tools and users to flagwithout inspecting deployment context.

Operationalpersistence was also maintained at the platform level. The Telegram channel hadbeen active since 2021, with the actor maintaining continuity by evolving thepersona over time: initially forwarding cryptocurrency scams, transitioning toframing mainstream news through a QAnon lens, and ultimately automating contentproduction with AI.

Privilege Escalation

The most explicit privilege escalation technique in thiscampaign was the compromise of WordPress admin accounts.

The actorleveraged an AI-assisted password mutation tool to crack 29 WordPress adminaccounts, using Gemini 2.5 Flash as a password variation generator. For eachtargeted username or email address, the tool fed surrounding context intoGemini to generate plausible password variations—including case alterations,appended years, character substitutions, name fragments, and keyboard patterns.

Thiseffectively elevated the actor from an external observer to a fulladministrator on compromised WordPress sites. Authenticating with adminprivileges granted high-level control over the sites, enabling the actor tomodify content, add users, alter plugins or themes, access stored data, andpotentially deploy secondary attack infrastructure.

Reports did notindicate exploitation of core WordPress vulnerabilities or plugin flaws.Privilege escalation was strictly credential-driven, amplifying weak or reusedpasswords with context-aware AI guessing.

Defense Evasion

The actor employed defense evasion techniques across AIplatforms, social channels, infrastructure, and software delivery.

The most novelevasion technique was the persistent jailbreaking of Gemini. The actor declaredthemselves an "authorized penetration tester" to the model, whichGemini accepted and stored in a persistent memory file (GEMINI.md). Subsequently, the actor instructed Gemini to retain thismemory, executing future requests without refusing, issuing ethical warnings,or questioning intent. Because the Gemini CLI automatically reloaded thismemory file at the start of every session, the jailbreak persisted acrossconversations. The AI effectively inherited and enforced its own previouslysaved unsafe instructions.

The actor alsoutilized Russian-language prompts and non-English interactions to bypass orweaken safety filters. Reports noted that safety guardrails were inconsistentacross languages, allowing the actor to request assistance with credentialtheft, password variation generation, API key rotation, and planningpump-and-dump schemes.

API keyrotation served as another evasion technique. The actor leveraged 73 suspectedstolen Gemini API keys, prompting Gemini to build a cycling rotator withcooldown logic. Distributing requests across multiple keys reduced reliance onany single account, minimizing the likelihood that rate limits or single-keyrevocations would halt operations.

Malwaredelivery relied on disguise: StellarMonSetup.exe was packaged to mimic alegitimate cryptocurrency wallet rather than a remote access tool. Utilizing GoToResolveprovided additional cover, as it is a signed, legitimate commercial productrather than custom malware.

Influenceoperations incorporated behavioral evasion. Early iterations of the automatedbot posted every 20 minutes continuously—even late at night—which appearedunnatural for a U.S.-based operator. After the actor noted that overnightposting and Russian slang (e.g., "bro") leaked into English posts,Gemini adjusted the schedule. It suppressed posts between 3:00 AM and 6:00 AMEST, issued morning greetings at 7:00 AM, and concentrated posting between11:00 AM and 4:00 PM EST. The actor also used Gemini to scrub Russian phrasing,refining the American patriot persona.

Credential Access

Credentialaccess was central to the entire campaign.

The actorattempted credential stuffing using purchased DaisyCloud info-stealer logs asinput for downstream intrusions. These logs provided usernames, passwords,cookies, and context to support account takeovers and targeted passwordguessing.

The AI-drivenWordPress brute-forcing tool represented a more advanced credential accessvector. Instead of relying solely on static dictionaries, the tool taskedGemini with generating context-aware password mutations based on target emailaddresses and associated metadata. This enabled highly targetedguessing—combining names, years, case alterations, symbols, and charactersubstitutions—ultimately compromising 29 WordPress admin accounts.

Stolen GeminiAPI keys were also treated as operational credentials. In one session, theactor pasted 40 stolen keys into Gemini to test validity and generate automatedrotation code. Across the campaign, 73 stolen Gemini API keys were exploited tosupply compute resources for content generation, automation, password modeling,and infrastructure management.

Cryptocurrencycredentials were aggressively targeted. The fake StellarMonster wallet importinterface directly harvested recovery seed phrases. In at least one fullycompromised wallet incident, the actor cracked the wallet password, stole a12-word recovery phrase, and harvested over 40 wallet addresses across majorblockchains.

GoToResolve's clipboard capture and file access capabilities providedadditional credential theft vectors. Captured clipboard data frequentlycontained copied passwords, wallet addresses, seed phrases, 2FA codes, andprivate keys.

Collection

The actor collected data from multiple sources.

ThroughGoToResolve, the actor accessed file systems and clipboard contents on victimendpoints, while interactive remote desktop access allowed direct observationof victim environments. Clipboard capture was particularly lucrative forcryptocurrency theft, as users frequently copy wallet addresses, recoveryphrases, passwords, and private keys.

The fake walletimport feature directly exfiltrated seed phrases. In at least one confirmedcase, the actor acquired the victim's wallet password, stole a 12-word seedphrase, and mapped over 40 wallet addresses across multiple blockchains.

Contextualintelligence was collected from info-stealer logs, LinkedIn profiles, and priorsuccessful logins. Rather than remaining passive, this data served as directinput for Gemini password modeling scripts—meaning data collection directlyenabled credential access.

The Telegram campaign also harvested audience attention and engagement.The QFS 2.0 Terminal bot utilized gamified referral mechanics and query limitsto incentivize users to recruit additional participants, systematicallyexpanding the pool of prospective fraud targets.

Command and Control

Command andcontrol (C2) was implemented through a mix of traditional infrastructure andabused commercial services. The primary endpoint C2 mechanism was GoToResolve.Installed via the fake StellarMonster wallet, it granted the actor persistentremote control over victim systems, including remote desktop sessions, filetransfers, command execution, and clipboard capture. Relevant networkindicators noted in reports include:

  • 213.165.51.115
  • 34.34.57.141
  • 34.34.81.129
  • 35.192.41.201

The actor alsoused Gemini to execute C2 migrations. In one observed session, Gemini followed C2_MIGRATION_GUIDE.md to unpack archives, patch binarypath errors, update Python code, debug deployments, terminate legacy servers,and verify new operational environments—demonstrating that AI was used tomaintain backend infrastructure alongside content generation.

CloudflareTunnels were managed with Gemini's assistance to expose and route serviceswhile concealing backend origin servers. Additionally, the actor configured aNetherlands-based virtual machine equipped with anonymizing proxies, emailtesting tools, and Gmail aggregation utilities to support operations andmaintain anonymity.

Telegramfunctioned as a quasi-C2 coordination layer for the social engineering funnel.Public channels distributed content, scam promotions, and fake walletinstallers, while automated bots engaged users to maintain the fraud pipeline.

Exfiltration

Dataexfiltration occurred via both the remote access software and direct phishinginputs.

The fakewallet's import flow exfiltrated recovery seed phrases entered by victims. Thisrepresented a direct exfiltration path: victims believed they were importing anexisting wallet, but their seed phrases were captured directly by the actor.

GoToResolveprovided secondary exfiltration pathways through file system access andclipboard scraping. Operators could view and exfiltrate host data during activeremote desktop sessions, harvesting clipboard entries containing credentials,private keys, and wallet details.

In confirmed compromise cases, the actor exfiltrated 12-word recoveryphrases, cracked wallet passwords, and harvested data across 40+ walletaddresses, achieving complete exfiltration and takeover of the victim'scryptocurrency assets.

Impact

While the primary impact of this campaign was financial loss,its execution was enabled by influence operation techniques.

The actorpromoted cryptocurrency scams, including a Stellar-based token named HYPE andcoordinated pump-and-dump schemes. Internal communications revealed explicitplans to monetize the audience once active QFS bot users reached5,000—confirming that the Telegram influence operation was fundamentally afinancial fraud funnel rather than a political campaign.

Upon obtaininga victim's password, 12-word seed phrase, and wallet address metadata, theactor systematically drained the victim's cryptocurrency assets. Furthermore,compromising 29 WordPress admin accounts exposed affected businesses—spanningarms retailers, law firms, medical clinics, and commercial sites—to operationaldisruption and data loss.

Operationally, this incident highlights how AI lowers the technical andresource threshold for conducting hybrid cybercrime. A solo threat actorsuccessfully leveraged AI to automate content generation, infrastructuremanagement, credential attacks, and fraud planning. While the observedfinancial yields appeared modest, the campaign proves that a single operatorcan integrate social trust, AI tooling, commercial RATs, and stolen credentialsinto a scalable fraud ecosystem.

 

Mitigation

No single patch can resolve thisincident, as the campaign did not rely on a single software vulnerability.Instead, the actor combined stolen or abused AI access, weak or reusedcredentials, social engineering, unauthorized remote access tools, and cryptocurrencyfraud. Consequently, effective mitigation must span multiple layers, includingAI services, cloud infrastructure, endpoints, WordPress administration, socialplatforms, and user security awareness.

  • Organizations should first address the AI supply chain that enabled this operation. Frontier AI providers should improve the consistency of safety guardrails across different languages, as actors can bypass protections through jailbreaks and non-English prompts. Persistent memory features should also be hardened to prevent attackers from storing commands that instruct models to ignore safety rules in future sessions. AI platforms should monitor for abuse patterns, such as API key rotation, requests for password mutation generation, credential processing, pump-and-dump planning, phishing workflows, and suspicious automated social media content generation.
  • Enterprises using AI APIs or CLI-based AI assistants should treat AI credentials as high-value secrets. API keys should be stored in managed secret vaults, scoped according to the principle of least privilege, rotated regularly, and revoked immediately upon compromise. Security teams should monitor for anomalous AI API usage, including activity originating from unfamiliar geographic locations, VPS providers, proxies, Cloudflare Tunnels, or instances where a single client queries multiple unrelated keys. Sudden usage spikes, cyclical key behavior, and repeated API call failures may indicate that stolen keys are being validated or abused.
  • Cloud and infrastructure monitoring is equally critical. In this case, the actor used AI to deploy servers, manage Cloudflare Tunnels, configure tools, and execute infrastructure changes via CLI. Organizations should alert on unexpected virtual machine creation, new tunnels or proxies, anomalous service account activity, changes made via unfamiliar CLI sessions, and the creation of files storing credentials or deployment notes. Google Cloud Platform service accounts, storage buckets, GitHub repositories, Cloudflare Tunnel configurations, and automation scripts should all be audited for unauthorized access or exposed secrets.
  • Endpoint controls should focus on detecting the abuse of legitimate remote management tools. The actor disguised GoToResolve as StellarMonSetup.exe and promoted it as a cryptocurrency wallet. Organizations should maintain an allowlist of approved remote access tools, blocking or alerting on unauthorized installations of GoToResolve, AnyDesk, ScreenConnect, TeamViewer, or similar utilities. Legitimate remote support deployments should be tied directly to helpdesk tickets, approved tenants, known administrators, and managed software distribution channels. Any remote access tool installed via Telegram, email links, file-sharing sites, or cryptocurrency promotions should be treated as suspicious.
  • Network defenders can also leverage indicators from this campaignfor threat hunting and blocking. Reports specifically highlight infrastructureassociated with GoToResolve, including connections to:
    • 213.165.51.115
    • 34.34.57.141
    • 34.34.81.129
    • 35.192.41.201

Security teams should query endpoint and network telemetry forthese destinations, particularly in environments where GoToResolve is notapproved for use. Hosts connecting to suspicious destinations should beisolated immediately to check for unauthorized remote access software, confirmwhether credential theft has occurred, and inspect wallet, browser, clipboard,and file access activity.

  • WordPress site owners must prioritize account security hardening. Reports did not identify affected WordPress administrators as victims of core WordPress or plugin vulnerabilities; the primary weakness was predictable, weak, or reused passwords, compounded by info-stealer data and AI-generated password mutations. Site owners should require strong, unique passwords and multi-factor authentication (MFA) across all administrator accounts, remove unused admin profiles, restrict access to /wp-admin where possible, and limit or block repeated login attempts. Web Application Firewalls (WAFs) and WordPress security plugins can assist in detecting brute-force and credential-stuffing behavior. Administrator login logs should be audited for anomalous IP addresses, successful logins following multiple failures, and access originating from anonymizing infrastructure.
  • Cryptocurrency users require specific safeguards because this campaign relies on trust-based lures rather than technical software exploits alone. Users should never install wallet software promoted through Telegram channels, political groups, influencer posts, or unsolicited messages. Legitimate wallets or exchanges will never ask users to enter seed phrases into a new application to claim rewards. Recovery seed phrases, private keys, and backup words should never be entered into unfamiliar software, websites, bots, or "wallet import" prompts. Adopting hardware wallets, securing high-value assets on dedicated, uncompromised devices, and conducting small test transactions can reduce exposure. Any offer involving urgent rewards, "QFS" access, secret financial resets, guaranteed token profits, or time-sensitive crypto rewards should be treated as a suspected scam.
  • Finally, incident response teams should assume that victims exposed to this campaign may face multi-faceted compromises. A user who installed the fake wallet may have also exposed their seed phrases, browser credentials, clipboard contents, local files, and remote desktop access. A compromised WordPress admin account may indicate that the same password was reused elsewhere. Stolen AI API keys may point to broader secret exposure across repositories, developer workstations, or cloud environments. Consequently, remediation measures must include resetting credentials, revoking API keys, enforcing MFA, isolating endpoints, removing remote access tools, migrating wallets to new keys, and conducting retroactive log reviews.

The central lesson of this incident is clear: AI-assisted fraud lowers the skill threshold and operational costs required to execute influence operations, credential attacks, and cryptocurrency theft. Therefore, effective mitigation must combine robust AI governance, enhanced identity and cloud monitoring, strict remote access tool controls, hardened WordPress administration, and continuous user education against social engineering-driven cryptocurrency scams.

Indicatorof Compromise (IoCs)

Files

Filename MD5 SHA-1 SHA-256
StellarMonSetup.exe ea1c409fdcb6dca6751c443aeed13441 9bf39391f9c0ce989ee53c02170d7885c6c23798 981036cec38c6fd9796fc64a102100b97983f56b3482cc3e1f1610e14a1fae58

IP Addresses

IP Addresses Description
213.165.51.115 Primary VPS (Content Host, QBOT)
34.34.57.141 Ghost Proxy (GCP Netherlands, SOCKS5 Port 1080)
34.34.81.129 Windows C&C Server (GCP europe-west4-a, RDP 3389)
35.192.41.201 Temporary Mail Server (Mailpit)

Domain

Domain Description
tralalarkefe[.]com Primary Cloudflare Domain
c2.tralalarkefe[.]com C&C Server Public Endpoint
payloads.tralalarkefe[.]com Payload Distribution Server
catchall1.tralalarkefe[.]com Catch-All Email (Mailpit)
dzbank[.]capital Impersonating DZ Bank AG (dzbank.com); Phishing Infrastructure (Active May–July 2022)
www.dzbank[.]capital Subdomains of the Above Domain
bpfi[.]digital Impersonating Banking & Payments Federation Ireland (bpfi.ie); Using Njalla Privacy Nameservers
www.bpfi[.]digital Subdomains of the Above Domain
docs.bpfi[.]digital Credential Harvesting Portal Subdomain
security.bpfi[.]digital Credential Harvesting Portal Subdomain
induspayments[.]com INDUS.exchange Scam Domain (Currently Offline)
indusx[.]tech Bulletproof Hosting Provider; Using Njalla Nameservers (Active 2022–September 2025)
www.indusx[.]tech Subdomains of the Above Domain

Telegram Identifiers

Account ID / Type Description
@americanpatriotus ID: 1482211747; Channel Primary influence operation broadcast channel
@QFS_Terminal_Bot Bot QAnon-themed AI chatbot
@PatriotTruthAI_bot Bot Legacy name of QFS Terminal Bot
@patriotstats_bot Bot Administrative control bot for the content host
@bandcampro ID: 6329112928; User Threat actor's administrative Telegram account
@Whiplash347 Channel Trending cryptocurrency scam channel

References

About CyCraft

CyCraft Technology(7823.TW) is a Taiwan-listed cybersecurity company, dedicated to automatingcybersecurity with AI technology and safeguarding AI models. CyCraft’s productsuite encompasses XecART, the AI Red Teaming, and XecGuard, the Guardrail APIfor LLMs and AI Agents. The XCockpit AI platform integrates EASM, IASM, andEndpoint protection, providing preemptive and real-time defense-in-depth. Witha proven track record in the government, finance, and semiconductor sectors,and recognition from international institutions, CyCraft continues to safeguardenterprise digital resilience.

Subscribe to CyCraft's Newsletter

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
By clicking this button, you agree to CyCraft's privacy policy and consent to CyCraft using the information you provided to contact you. You may cancel your subscription at any time.