Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Rapid7 Uncovers Operation ASTERIX, AI-Powered Crypto Phishing Campaign

Cybersecurity firm Rapid7 has uncovered Operation ASTERIX, a crypto fraud campaign utilizing AI-assisted development, phone datasets, and counterfeit wallet applications.
3 hours ago 7 views

Cybersecurity researchers at Rapid7 have uncovered Operation ASTERIX, a cryptocurrency fraud campaign that combined artificial intelligence-assisted development with targeted phishing tactics. The campaign utilized phone datasets, account-validation tools, phishing emails, voice calls, and counterfeit wallet applications to target digital asset users.

Phone Datasets and Account Validation

During the investigation, Rapid7 discovered approximately 885,000 phone numbers across multiple datasets linked to the operation. The attackers used validation tools to identify phone numbers connected to specific cryptocurrency accounts. For instance, a German dataset containing 316,002 mobile numbers allowed the operators to identify 43,066 associated Crypto.com accounts.

The campaign subsequently narrowed its target pool using enriched records, which included names, contact details, locations, and account-related information. According to Rapid7, this detailed data enabled attackers to make support impersonation attempts appear more convincing by coordinating emails and follow-up calls around matching support details. The phishing infrastructure impersonated major brands such as Crypto.com and Binance, alongside maintaining counterfeit applications resembling Trezor Suite, Ledger Live, and Exodus.

Role of AI Tools and Fake Applications

Recovered files from exposed infrastructure provided researchers with an unusual view into an active phishing operation, showing that attackers used AI coding tools throughout the campaign's development. Operators leveraged tools like GitHub Copilot and Claude Code for coding, scripting, data processing, debugging, application packaging, and infrastructure work.

The investigation noted instances where AI safety controls interacted with the threat actors' workflow. Claude refused certain requests involving code obfuscation, prompting the operator to switch to Kimi and attempt to bypass its safety controls. Rapid7 could not confirm whether the bypass attempt succeeded, but the evidence documented efforts to switch tools after encountering model restrictions.

The operation also distributed fake wallet applications designed to imitate popular cryptocurrency wallet software for macOS and Windows. Additionally, the attackers hosted a counterfeit Claude Code installer that attempted to install a malicious wallet application alongside legitimate software. Rapid7 discovered the campaign while much of its infrastructure was still active or under development, and subsequently notified relevant providers and authorities, including Apple's security team.