Operation ASTERIX: A Sophisticated Cryptocurrency Fraud Scheme
Operation ASTERIX has emerged as a notably intricate cryptocurrency fraud campaign, blending multiple tactics including account enumeration, phishing, targeted voice calls, and the distribution of malicious wallet software designed to capture victims’ recovery phrases. This operation stands out not only for its organized methodology but also for its strategic use of technology, particularly artificial intelligence, indicating a new level of sophistication in cybercriminal activities.
The naming of this operation after the Asterisk telephony platform highlights the integral role that communication technologies play in the perpetration of this fraud. Operation ASTERIX is structured as a carefully calibrated social-engineering pipeline. Unlike many other fraud schemes that cast wide nets to ensnare random victims, this operation begins with an essential step: validating whether specific phone numbers are associated with cryptocurrency services. Once this is established, the operators enrich their successful matches with pertinent identifying information and account-related data before unfurling their phishing and vishing tactics.
Cybersecurity firm Rapid7 unearthed a staggering approximately 885,000 phone numbers linked to various datasets across multiple countries, including Germany, Hong Kong, Bulgaria, the UK, the US, and Canada. These numbers were often associated with notable cryptocurrency platforms, such as Ledger and various fintech services. Within one German dataset alone, which contained 316,002 numbers, a remarkable 43,066 accounts were validated, yielding an impressive hit rate of 13.6%.
To effectively target users most likely to hold cryptocurrency exchange accounts or wallets, the operators employed advanced technical strategies. These included concurrent requests, residential proxies, retry logic, and comprehensive lead databases. Such methodologies allowed fraudsters to present themselves as legitimate support agents. Callers would cite the victim’s name, affiliations with exchanges, purported support cases, and even verification codes that had been sent via email. This multi-channel approach created a deceptive atmosphere where incoming support calls seemed timely and expected, deepening the illusion that the call was a continuation of a legitimate account security process.
Victims were subsequently urged to install phony wallet-security updates, conduct account checks, or provide sensitive wallet recovery phrases. A suite of tools—including Asterisk, 3CX, and various automatic dialing scripts—facilitated the automation and coordination of this malicious campaign.
Rapid7’s analysis revealed that the campaign was not merely a random assortment of phishing attempts but a targeted effort led by operators with access to detailed insights. One panel logged 20 successful lead lookups and sent six phishing emails over a two-week period, highlighting its directed strategy. Notably, the campaign incorporated counterfeit applications resembling Trezor Suite, Ledger Live, and Exodus specifically designed for both macOS and Windows environments.
The operations employed distinct methods to orchestrate its fraud. For instance, the counterfeit Trezor application on macOS was engineered to work stealthily, utilizing a transparent window to lay in wait until the victim launched the legitimate app. Upon detection of genuine activity, the malware would terminate the authentic application, presenting the victim with a manipulative wallet interface designed to extract their recovery phrases.
Similarly, on Windows, the Ledger Live counterfeit included clipboard hijacking functionality to swap copied cryptocurrency addresses with those controlled by the fraudsters, increasing the likelihood of successful thefts as users unwittingly confirmed transactions. In some cases, the Exodus installer utilized a trojanized JavaScript component for payload retrieval post-installation.
A key finding was the exposed server’s logs and files, which demonstrated that the operators actively employed AI tools like GitHub Copilot and Claude Code to fine-tune their processes. This brought forth the alarming discovery that AI has become integral to operational development within criminal workflows, showcasing a shift from traditional coding practices to more advanced methods that streamline and enhance their criminal activities.
Rapid7’s swift response involved notifying pertinent service providers and authorities, including Apple’s security team, while parts of the nefarious infrastructure remained live. Additionally, the company made available various indicators of compromise (IOCs) and other findings through their GitHub resources, aiding broader cybersecurity efforts.
The multifaceted design and level of preparation behind Operation ASTERIX serve as a stark reminder of the evolving sophistication of cybercrime. As these fraudsters integrate advanced tools and techniques, the cybersecurity community must remain vigilant, continually adapting to the rapidly changing landscape of online threats. In this ongoing battle, collaboration among technology providers, law enforcement, and security experts will be critical to countering such sophisticated threats effectively.
