Operation ASTERIX exposed 885,000 phone numbers in crypto phishing scheme

Rapid7 Labs uncovered Operation ASTERIX, a multi-stage cryptocurrency fraud campaign that combined counterfeit wallet applications, automated exchange account validation, Asterisk-powered vishing and AI coding tools—including GitHub Copilot—to steal recovery phrases from validated users. A misconfigured server exposed roughly 885,000 phone numbers, led by 316,002 German mobiles plus directories covering Hong Kong, Bulgaria, the UK, the US, Canadian fintech customers and Ledger-related lists. Checkers for Crypto.com, Binance and Kraken produced a 13.6% hit rate on the German set, confirming 43,066 exchange users, with 5,576 Binance-matched numbers queued for attack. Fraudsters pushed fake Trezor Suite, Ledger Live and Exodus builds that requested 12- to 24-word seed phrases and exfiltrated them via Telegram, while activity logs showed only 20 lead lookups and six phishing emails over two weeks. Rapid7 analysts Anna Širokova and Jan Recinsky disclosed the infrastructure on August 17 while parts remained active. The findings sit against broader phishing losses of $306 million in Q1, a Trezor shipping-partner breach affecting 13,689 customers, and prior QR-code letter phishing aimed at hardware-wallet owners.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.