Browsing: Gemini

The Gemini CLI impersonation campaign was first publicly identified by independent threat researcher @g0njxa[1], whose initial discovery enabled analysis and infrastructure pivoting documented in this report. The infection chain begins with a Google search by a developer looking for the official Gemini CLI[2]or Claude Code[3]installation page. Threat actors use SEO poisoning to surface a fake…

Unlike rankings, impressions, or clicks, Gemini brand mentions don’t appear in Search Console or Google Analytics. A buyer might discover your company in a Gemini response, continue researching through Google Search, and later return through a branded search or direct visit.