
Rapid7 uncovered a crypto phishing campaign using AI tools, 885,000 phone numbers, and fake wallet apps to impersonate Crypto.com and Binance. The infrastructure was still active when discovered.
Rapid7 uncovered a crypto fraud campaign it calls Operation ASTERIX, combining AI-assisted development with targeted phishing. The operation used phone datasets, account-validation tools, phishing emails, voice calls, and counterfeit wallet applications.
Researchers found evidence that attackers used AI coding tools throughout the campaign's development. The exposed infrastructure gave Rapid7 an unusual view into an active crypto phishing operation.
Rapid7 discovered roughly 885,000 phone numbers across multiple datasets linked to the operation. Attackers used validation tools to identify numbers connected to cryptocurrency accounts. One German dataset contained 316,002 mobile numbers. The operators identified 43,066 associated Crypto.com accounts from that list.
The campaign narrowed its target pool using enriched records. Those records included names, contact details, locations, and account-related information in some cases. Rapid7 said this information helped attackers make support impersonation appear more convincing. The operation coordinated emails and follow-up calls around matching support details.
The phishing infrastructure impersonated brands including Crypto.com and Binance. Attackers also maintained counterfeit applications resembling Trezor Suite, Ledger Live, and Exodus.
Rapid7 recovered evidence of AI-assisted development from the exposed server. The operators used GitHub Copilot and Claude Code for coding, scripting, data processing, and infrastructure work. The investigation showed that AI tools supported several parts of the campaign. Recovered artifacts indicated their use for application packaging, debugging, code changes, and phishing infrastructure.
Rapid7 found that Claude refused some requests involving code obfuscation. The operator then switched to Kimi and attempted to bypass its safety controls. Rapid7 could not confirm whether that bypass attempt succeeded. The recovered evidence documented the operator's effort to switch tools after encountering model restrictions.
The fake wallet applications formed another major part of the campaign. Rapid7 recovered versions designed to imitate popular cryptocurrency wallet software across macOS and Windows. The operation also hosted a counterfeit Claude Code installer. According to Rapid7, that distribution channel attempted to install a malicious wallet application alongside the legitimate software.
Rapid7 discovered the campaign while much of its infrastructure remained active or under development. The firm notified relevant providers and authorities, including Apple's security team, after documenting the activity.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.