Путин хуйло 06/01/2026 (Mon) 20:23 Id: d8208b No.864924 del
(1.07 MB 1099x1099 Josef-GTAV.png)
(71.99 KB 472x513 Figure-1.png)
(364.90 KB 376x777 Figure-11a.png)
(116.75 KB 439x541 Figure-11b.png)
Ухахахахахаха

> A solo Russian-speaking threat actor (tracked as “bandcampro”) ran a 5-year MAGA-themed Telegram channel (@americanpatriotus, approximately 17,000 subscribers) and pivoted to AI-automated content, fraud, and credential theft starting September 2025.

> The campaign's branding, narrative, and audience engagement strategy were precisely calibrated to resonate with the QAnon and MAGA communities, mimicking the cryptic, militaristic tone of "Q drops."

> We track this actor as bandcampro, after his Telegram handle. He is a Russian speaker who used the LLM to impersonate an American veteran patriot and to avoid Russian phrasing. Based on the posted content and his use of a stock RAT malware, we assess that the use of information operation techniques was more likely for cryptocurrency fraud instead of political motives.

> Phase 1 — manual curation (2021–2022): Most content was forwarded from two Telegram channels in the Stellar/Lobstr crypto fraud ecosystem, promoting Stellar-based ICOs, “gold-backed Russian Ruble” (VBRF) tokens

> Phase 2 — news links (Jan 2023–Sep 2025): The channel pivoted from forwarding crypto-fraud posts to sharing hyperlinks to mainstream news outlets (Fox News, CNN, NYT, NY Post, Washington Times, etc.) paired with brief QAnon-coded keywords like “GESARA/NESARA”, “White Hats”, and “Great Awakening”. The phase peaked on July 14, 2025, driven by a one-time dump of Epstein files.

https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html

Tags: волосы, зубы, баба, работа, госзаказ