Rapid7 uncovers Operation ASTERIX: AI-powered phishing tools targeting crypto wallet recovery phrases

1 hour ago 5



A single misconfigured web server just pulled back the curtain on one of the more methodical crypto fraud operations researchers have seen in recent memory. Rapid7 Labs discovered and documented what it calls Operation ASTERIX, a multi-channel scheme that combined phishing emails, voice calls, and counterfeit wallet applications to steal cryptocurrency recovery phrases from targeted victims. The exposed directory contained approximately 885,000 phone numbers, automated tools for validating crypto exchange accounts, and fake versions of popular hardware wallet software. The fraudsters used AI coding assistants to build their malicious tools. Inside the operation’s playbook The largest batch of phone numbers in the exposed directory consisted of 316,002 German mobile numbers. The fraudsters used these numbers alongside Asterisk, an open-source telephony platform, to conduct vishing (voice phishing) calls. On the account validation front, the operation targeted Crypto.com users specifically, running automated checks against their database of phone numbers. The hit rate was 13.6%, meaning roughly one in seven numbers corresponded to an active account. Once potential victims were identi...

Read Entire Article