Rapid7 reveals Operation ASTERIX: AI-assisted phishing used 885,000 phone numbers to harvest crypto seed phrases

Rapid7 reveals Operation ASTERIX: AI-assisted phishing used 885,000 phone numbers to harvest crypto seed phrases

Rapid7 described a phishing campaign targeting cryptocurrency users that combined large volumes of phone numbers, automation, and artificial intelligence tools to identify potential victims and deploy personalized attacks. The operation, dubbed Operation ASTERIX, used an infrastructure that included phishing panels, automated calling scripts, fake wallet applications, and targeting data.

A Campaign Built to Identify Cryptocurrency Users

According to Rapid7, investigators found an exposed web directory associated with the attackers’ infrastructure. It contained phone-number datasets, account-validation tools, enriched information on potential victims, source code, and components used to distribute malware.

The scale of the data was one of the most notable aspects of the operation. The campaign worked with approximately 885,000 phone numbers, which could then be cross-referenced with additional information to determine which numbers were linked to cryptocurrency users.

In a dataset corresponding to Germany, Rapid7 identified 43,066 verified cryptocurrency accounts from 316,002 phone numbers. This process allowed the attackers to move from a large pool of potential targets to a much more precise list for subsequent social-engineering attacks.

The second stage involved personalized emails and automated voice calls. The attackers also distributed fake applications impersonating products from well-known wallet manufacturers such as Trezor, Ledger, and Exodus, with the aim of obtaining credentials or recovery phrases.

AI Reduced the Cost of Building the Attack

Rapid7 also found evidence that the operators used programming assistants such as GitHub Copilot and Claude Code during different stages of development. The recovered artifacts showed these tools being used to package applications, modify phishing infrastructure, troubleshoot compilation issues, and prepare malicious software for distribution.

The finding does not mean that AI independently carried out the campaign. The significance lies in how these tools can accelerate tasks that previously required more time or specialized expertise, reducing the cost of adapting fake applications and other attack components to different targets.

The operation also relied on Telegram for certain communication and data-exfiltration functions, according to the investigation.

For cryptocurrency users, the campaign highlights a persistent weakness in self-custody: sophisticated technical defenses can still be bypassed when attackers persuade users to reveal their recovery phrases or install malicious software. Fake wallet applications are particularly dangerous because they can appear legitimate while directly targeting the credentials that control access to funds.

The operation also highlights a growing challenge for wallet developers and exchanges. As attackers combine large datasets with automation and AI-assisted development, traditional phishing defenses may have less time to identify and block increasingly targeted campaigns.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px