Rapid7
Operation ASTERIX: AI-Driven Crypto Fraud Campaign Exposed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Operation ASTERIX is a sophisticated cryptocurrency fraud campaign that utilized vishing, phishing, and fake wallet applications to steal recovery phrases from victims. Rapid7 researchers discovered an exposed server containing tools for account enumeration, phishing panels, and AI-assisted development artifacts. The campaign targeted confirmed cryptocurrency users by verifying phone numbers linked to active accounts. Key components included counterfeit Ledger, Trezor, and Exodus applications, as well as Telegram exfiltration code. The operation's infrastructure was still active at the time of discovery, allowing for timely notifications to relevant authorities. The use of AI coding assistants was notable, with operators attempting to bypass safety controls to enhance their fraud tools. This multi-faceted approach highlights the increasing sophistication of cybercriminal operations in the cryptocurrency space.
Key Points: • Operation ASTERIX combines vishing, phishing, and fake wallet apps to steal crypto recovery phrases. • AI coding tools were used extensively in the development of the fraud campaign's infrastructure. • Rapid7 exposed the operation while it was still active, enabling immediate action by authorities.