
Rapid7 uncovered ASTERIX, a crypto fraud pipeline that was live when discovered. Of 316,002 German numbers checked, 43,066 matched real exchange accounts. The operators sent only six phishing emails and logged 20 lookups in two weeks.
Alpha Score of 56 reflects moderate overall profile with moderate momentum, weak value, strong quality, moderate sentiment.
Researchers uncovered a crypto fraud operation called ASTERIX that was still running when they found it. Rapid7 analyst Anna Širokova hit an exposed web directory on campaign infrastructure in early August. Inside were phone-number datasets, account-validation tools, phishing panels, voice-dialing scripts, fake wallet apps, and code that siphoned stolen data out through Telegram.
The tooling was live or in development. Rapid7 said it reached out to providers and authorities, including Apple's security team, while the campaign was happening.
The largest file in the directory held 316,002 German mobile numbers. The operators ran those against an account checker and confirmed that 43,066, or about 13.6%, were linked to real crypto exchange accounts. That is roughly one in seven. A separate batch of 5,576 numbers was tied to Binance accounts and queued for attack. The report also listed a Kraken checker and fake emails impersonating Crypto.com.
The infection mechanism is direct. The apps mimic Trezor Suite, Ledger Live, and Exodus. When a user opens the fake app, it prompts for a recovery phrase of 12 to 24 words. That phrase is the master key to the hardware wallet. The stolen phrases were exfiltrated to a Telegram bot the operators controlled. Anyone who self-custodies their crypto is a potential target, Rapid7 said. The fake apps used AI coding assistants across the entire build process. Recovered prompts, shell history, and project files showed the operator relying on GitHub Copilot to package the Electron apps, obfuscate the code, fix broken builds, and prepare the malware for distribution, according to the report. When one model started refusing parts of the work, the operator switched providers and tried to jailbreak the next model with a custom prompt.
The volume of validated targets does not match the activity logs. The logs recorded only 20 lead lookups over roughly two weeks. Just six phishing emails were sent. That suggests the operators picked targets by hand rather than blasting the full list.
Earlier in August, Trezor warned 13,689 customers after a breach at shipping partner ShipMonk exposed names, emails, phone numbers, and addresses. Ledger and Trezor owners have also received physical letters with QR codes pointing to phishing sites, according to earlier reporting.
Phishing and social engineering made up $306 million of the crypto industry's roughly $482 million in first-quarter losses, according to blockchain security firm Hacken.
Rapid7 named the operation ASTERIX after Asterisk, the open-source telephony platform found on the server. The operators used Asterisk to make voice-phishing calls timed to arrive just after the fake support emails.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.