Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Imported from official source

Cybersecurity Classified by Officially

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution. When one model began resisting parts of that workflow, the operator switched providers and attempted to bypass the next model's safety controls with a custom jailbreak prompt. Together, these artifacts provide an unusual view into how AI was integrated into the development of an active phishing operation rather than simply being used to generate isolated snippets of code.

We track this activity as Operation ASTERIX, named after the Asterisk open-source telephony platform recovered on the server. The operator used Asterisk to automate the campaign's vishing infrastructure, coordinating phone calls with phishing emails and counterfeit wallet applications.

The recovered material shows how the operator combined several techniques:

Bulk account enumeration against cryptocurrency platforms

Phishing emails that created fake support cases

Vishing calls that referenced details from those emails

Counterfeit Ledger, Trezor, and Exodus applications

Seed-phrase theft and Telegram exfiltration

AI-assisted development, including an attempt to bypass an LLM’s safety controls

This is an extract. The publication continues at the source.

Read the original at the source: https://www.rapid7.com/blog/post/tr-operation-asterix-crypto-fraud-vishing-phishing

Officially imported this from Rapid7’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Rapid7 — imported from official source
Official source
https://blog.rapid7.com/rss/ RSS
Imported
September 18, 2026 11:35
Versions
1 recorded
Identity
bltaa2a3fb749678dcb

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.