Skip to main content
AVOID.NET

bandcampro (StellarMonster Wallet Malware)

avoid.net/bandcampro-stellarmonster-wallet-malware→0/100·88% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·34T2N1…nZzY
last updated 2026-05-27

Summary

bandcampro is a Russian-speaking threat actor who operated an 8-month AI-assisted crypto theft and influence campaign (September 2025–May 2026) via the Telegram channel @americanpatriotus, which had accumulated roughly 17,000 subscribers over a five-year run beginning February 2021. The actor distributed a trojanized self-custody wallet called StellarMonster that deployed the GoToResolve remote access tool, enabling seed phrase harvesting and full wallet compromise. A jailbroken Google Gemini instance and 73 stolen API keys automated content generation, credential attacks, and infrastructure management. The campaign was publicly exposed by Trend Micro researchers on or around May 22, 2026.

Connected Entities

2 entities · 18 linked investigations
Organizations
□Stellar50□bandcampro (StellarMonster Wallet Malware)
Relationships
  • bandcampro (StellarMonster Wallet Malware)→mentioned with→Stellar(70%)

Connected Through

1 shared actor · 18 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about bandcampro (StellarMonster Wallet Malware)?

Timeline(6 events)

6 January 2021

January 6 Capitol riot triggers mass deplatforming of QAnon and MAGA communities from Facebook and Twitter; many users migrate to Telegram — the conditions that created the target audience.

Trend Micro Patriot Bait report

6 February 2021

Telegram channel @americanpatriotus created, approximately one month after the Capitol riot, initially curating and forwarding Stellar/Lobstr crypto ICO content and VBRF token promotions.

Trend Micro Patriot Bait report

9 September 2025

StellarMonster wallet malware (StellarMonSetup.exe) distributed to @americanpatriotus subscribers as a 'freedom-first, self-custody wallet' with an alleged 1,000 XLM welcome bonus; the executable deployed the GoToResolve remote access tool.

The Register; CybersecurityNews

September 2025

AI-assisted phase of campaign begins; actor integrates jailbroken Google Gemini CLI via GEMINI.md persistent memory file and begins rotating 73 stolen Gemini API keys.

CybersecurityNews; Security Boulevard

October 2025

Gemini-powered WordPress brute-force attacks begin; DaisyCloud infostealer logs used to generate password mutations, eventually compromising 29 WordPress administrator accounts.

CyberPress; GBHackers

22 May 2026

Trend Micro publishes full exposure of the 'Patriot Bait' campaign, revealing bandcampro's complete operational environment including malware, IOCs, AI jailbreak method, and victim impact data.

The Register; Trend Micro
Provenance & Audit Trail

Decision Log

  • #3review revise-8Recorded on Solana ✓6/3/2026, 2:06:02 AM
    slot 423932894 · hash 3qLqHFk53cvwqKGAwa1nD1GxRp7HQLCNd23yLCrBaxyg
  • #2reviewRecorded on Solana ✓6/3/2026, 2:06:02 AM
    slot 423932891 · hash 7GQWRV6HbiDCKMncqAEDbnonqJzTtk16atbitD78kEtz
  • #1publishRecorded on Solana ✓5/27/2026, 5:31:40 PM
    slot 422548077 · hash FKex79ZVLHoM5wLd7KfewXR7KSZDCXjR2kGoR9rVBudp

This investigation is cryptographically anchored to the Solana blockchain (3 decisions). 9 of 10 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 5/27/2026, 5:30:36 PM

last updated: 5/27/2026, 5:30:36 PM

1 view

avoid.net — verified advice for a post-truth world