< Back to all clusters
[TECHNOLOGY] · Germany, Hong Kong SAR China, United Kingdom, United States · 9 sources

started · updated

Operation ASTERIX: AI-driven crypto phishing targets 885,000 numbers

Cybersecurity firm Rapid7 Labs has exposed a large-scale cryptocurrency fraud campaign known as Operation ASTERIX. The operation utilized AI coding assistants to develop fraudulent mobile applications designed to impersonate legitimate self-custody wallet providers, including Ledger, Trezor, and Exodus.

Researchers discovered an exposed web directory containing the campaign's infrastructure, which included phone-number datasets, phishing panels, and voice-dialing scripts. The operation targeted approximately 885,000 phone numbers globally. A significant portion of the data included 316,002 German mobile numbers. By using account-validation tools, attackers successfully matched 43,066 of these numbers to active cryptocurrency exchange accounts, representing a hit rate of approximately 13.6%.

The campaign employed a combination of phishing (via fake emails and websites) and vishing (voice-phishing) to trick users into revealing their seed phrases or credentials. The attackers also identified a batch of 5,576 numbers specifically associated with Binance accounts for follow-on attacks.

Entities

Binance · Claude Code · Crypto.com · Exodus · Forcepoint X-Labs · Germany · GitHub Copilot · India · Ledger · Operation ASTERIX · Overwolf · Rapid7

Claims

What the coverage asserts, and how many sources carry each claim.