CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4537

As cited

Copy frozen at (site build).

threat intel

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 researchers discovered an exposed web server hosting a complete cryptocurrency fraud operation called Operation ASTERIX, which combined phishing emails, vishing calls via automated phone systems, and fake cryptocurrency wallet applications to steal recovery phrases from victims. The infrastructure included datasets of approximately 885,000 phone numbers filtered for confirmed cryptocurrency exchange users, phishing panels impersonating platforms like Crypto.com and Binance, and counterfeit wallet applications for Trezor, Ledger, and Exodus. Throughout the campaign's development, the operator extensively used AI coding assistants such as GitHub Copilot and Claude Code to build and obfuscate malware, and when Claude declined to assist with obfuscation tasks, the operator switched to Kimi and attempted a sophisticated jailbreak prompt designed to override the model's safety controls.

Why it matters: Cryptocurrency users and exchange operators need to recognize coordinated phishing and vishing techniques combined with credential-stealing malware; security teams should block the identified domains, wallet application hashes, and Telegram exfiltration endpoints. Developers of AI coding assistants must expect attackers to systematically switch providers and craft sophisticated jailbreaks when models refuse harmful requests, making this a governance and detection problem for AI platform operators. Organizations distributing software should monitor for trojanized installation pages and educate users to verify authenticity before bypassing code-signing protections like Gatekeeper.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 researchers discovered an exposed web server supporting a cryptocurrency fraud operation called Operation ASTERIX that combined phishing, voice calling (vishing), and counterfeit wallet applications to steal cryptocurrency recovery phrases. The infrastructure revealed approximately 885,000 phone numbers validated against crypto exchanges, fake wallet applications for Trezor, Ledger, and Exodus, and automated calling systems powered by Asterisk and 3CX. The operator relied heavily on artificial intelligence (AI) coding assistants throughout development, including GitHub Copilot and Claude Code, and attempted to bypass an AI model's safety controls with a sophisticated jailbreak prompt when it refused to assist with code obfuscation.

Why it matters: Cryptocurrency users and financial-services defenders must secure against multi-channel social engineering attacks that combine validated personal data, fake branded support communications across email and phone, and convincing counterfeit applications; the operation's disclosure while active allowed provider notification and law enforcement coordination. Developers and security teams should recognize that attackers now routinely use AI assistants for malware development and actively work around model safety guardrails, making this a standard threat in attack pipelines rather than an edge case.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 researchers discovered an exposed web server supporting a cryptocurrency fraud operation called Operation ASTERIX that combined phishing, voice calling (vishing), and counterfeit wallet applications to steal cryptocurrency recovery phrases. The infrastructure revealed approximately 885,000 phone numbers validated against crypto exchanges, fake wallet applications for Trezor, Ledger, and Exodus, and automated calling systems powered by Asterisk and 3CX. The operator relied heavily on artificial intelligence (AI) coding assistants throughout development, including GitHub Copilot and Claude Code, and attempted to bypass an AI model's safety controls with a sophisticated jailbreak prompt when it refused to assist with code obfuscation.

Why it matters: Cryptocurrency users and financial-services defenders must secure against multi-channel social engineering attacks that combine validated personal data, fake branded support communications across email and phone, and convincing counterfeit applications; the operation's disclosure while active allowed provider notification and law enforcement coordination. Developers and security teams should recognize that attackers now routinely use AI assistants for malware development and actively work around model safety guardrails, making this a standard threat in attack pipelines rather than an edge case.

VendorsMicrosoftAppleGoogleGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary