
Cybersecurity firm Rapid7 has uncovered Operation ASTERIX, a cryptocurrency fraud campaign that combined mass account enumeration, phishing emails, targeted phone calls and counterfeit wallet applications to steal users’ recovery phrases. Rapid7 Labs discovered the operation after finding an exposed web directory on infrastructure being used by the attacker. The misconfiguration provided researchers with an unusually detailed view of the campaign, including raw targeting data, source code, phishing panels, dialing scripts, malware builds and logs showing extensive use of artificial-intelligence coding assistants.Rapid7 named the campaign after Asterisk, the open-source telephony platform found on the server and used to automate voice-phishing, or vishing, operations. The attacker coordinated calls with fraudulent support emails and fake cryptocurrency-wallet software, creating a multi-stage process designed to make the eventual request for sensitive wallet information appear legitimate. Much of the infrastructure remained active or under development when discovered, allowing Rapid7 to notify service providers and relevant authorities, including Apple’s security team.
Attackers Narrowed 885,000 Numbers Into Crypto Targets
The exposed server contained approximately 885,000 phone numbers organized by geography and source. Its largest individual dataset contained 316,002 German mobile numbers, while additional files referenced Hong Kong, Bulgaria, the U.K., U.S., Canadian fintech users and Ledger-related data spanning 54 countries. Rather than contacting the entire dataset indiscriminately, the attacker used automated tools to determine which numbers were connected to cryptocurrency services.One Go-based tool queried a Crypto.com account-existence endpoint using 300 concurrent threads, rotating residential proxies and retry logic. Rapid7 found that 43,066 accounts were confirmed from the 316,002-number German dataset, producing a 13.6% hit rate. Separate infrastructure included a Kraken checker. Validated accounts were subsequently enriched with information including names, email addresses, locations and account details, creating higher-quality targets for social engineering. One recovered Binance lead panel displayed 5,576 validated crypto targets queued for attack.Phishing panels then generated branded emails impersonating companies including Crypto.com and Binance. Fake support cases and verification codes could subsequently be referenced during phone calls, allowing attackers to reinforce the same fraudulent story across multiple communications channels.
Fake Wallets Stole Seed Phrases as AI Helped Build Tooling
The final stages directed victims toward counterfeit versions of Ledger Live, Trezor Suite and Exodus. Rapid7 found that one fake Trezor application monitored for the legitimate software, terminated it and displayed a counterfeit interface requesting a 12-, 18-, 20- or 24-word BIP39 recovery phrase. Stolen seed phrases, passphrases and victims’ IP addresses could then be transmitted through Telegram. The exposed development environment also showed how AI coding assistants had become integrated into the attacker’s workflow. Recovered prompts, project files and shell history showed AI being used to package Electron applications, troubleshoot builds, modify phishing infrastructure and obfuscate malicious code.When one AI model refused parts of the workflow, Rapid7 said the operator switched providers and attempted to bypass another model’s safeguards using a custom jailbreak prompt spanning thousands of words. Rapid7 emphasized that ASTERIX’s individual phishing and malware techniques are not fundamentally new. What distinguishes the discovery is the visibility it provides into an integrated, AI-assisted fraud operation while its infrastructure was still active. For cryptocurrency holders, the campaign also reinforces why wallet recovery phrases remain particularly valuable targets. Unlike compromised exchange credentials, a stolen seed phrase can give an attacker direct control over the associated assets, making sophisticated support impersonation an increasingly important security threat as attackers improve how they identify likely crypto owners.
