Rapid7 Operation ASTERIX: AI-Driven Crypto Fraud Campaign Exposed
Article Content
- •Operation ASTERIX combines vishing, phishing, and fake wallet apps to steal crypto recovery phrases.
- •AI coding tools were used extensively in the development of the fraud campaign's infrastructure.
- •Rapid7 exposed the operation while it was still active, enabling immediate action by authorities.
Operation ASTERIX is a sophisticated cryptocurrency fraud campaign that utilized vishing, phishing, and fake wallet applications to steal recovery phrases from victims. Rapid7 researchers discovered an exposed server containing tools for account enumeration, phishing panels, and AI-assisted development artifacts. The campaign targeted confirmed cryptocurrency users by verifying phone numbers linked to active accounts. Key components included counterfeit Ledger, Trezor, and Exodus applications, as well as Telegram exfiltration code. The operation's infrastructure was still active at the time of discovery, allowing for timely notifications to relevant authorities. The use of AI coding assistants was notable, with operators attempting to bypass safety controls to enhance their fraud tools. This multi-faceted approach highlights the increasing sophistication of cybercriminal operations in the cryptocurrency space.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…