Operation ASTERIX: AI-Driven Crypto Fraud Campaign Exposed

Operation ASTERIX: AI-Driven Crypto Fraud Campaign Exposed

First seen 18 Aug 2026, 10:37 UTC Rapid7Gbhackers 83% similarity 67.5

Article Content

Browse articles
ThreatCluster

Operation ASTERIX is a sophisticated cryptocurrency fraud campaign that utilized vishing, phishing, and fake wallet applications to steal recovery phrases from victims. Rapid7 researchers discovered an exposed server containing tools for account enumeration, phishing panels, and AI-assisted development artifacts. The campaign targeted confirmed cryptocurrency users by verifying phone numbers linked to active accounts. Key components included counterfeit Ledger, Trezor, and Exodus applications, as well as Telegram exfiltration code. The operation's infrastructure was still active at the time of discovery, allowing for timely notifications to relevant authorities. The use of AI coding assistants was notable, with operators attempting to bypass safety controls to enhance their fraud tools. This multi-faceted approach highlights the increasing sophistication of cybercriminal operations in the cryptocurrency space.

Key Points: • Operation ASTERIX combines vishing, phishing, and fake wallet apps to steal crypto recovery phrases. • AI coding tools were used extensively in the development of the fraud campaign's infrastructure. • Rapid7 exposed the operation while it was still active, enabling immediate action by authorities.

ThreatCluster AI How this analysis works

Timeline

2026-08-17
Operation ASTERIX exposed by Rapid7
Rapid7 identified an exposed server with tools for a cryptocurrency fraud operation, revealing AI integration in its development.
Rapid7
2026-08-18
Gbhackers report on Operation ASTERIX
Gbhackers published details on the operation, highlighting its use of vishing and trojanized wallet software.
Gbhackers

Community

Browse all →

Tracked Entities in This Story