Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Cybersecurity Classified by Officially
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution. When one model began resisting parts of that workflow, the operator switched providers and attempted to bypass the next model's safety controls with a custom jailbreak prompt. Together, these artifacts provide an unusual view into how AI was integrated into the development of an active phishing operation rather than simply being used to generate isolated snippets of code.
We track this activity as Operation ASTERIX, named after the Asterisk open-source telephony platform recovered on the server. The operator used Asterisk to automate the campaign's vishing infrastructure, coordinating phone calls with phishing emails and counterfeit wallet applications.
The recovered material shows how the operator combined several techniques:
Bulk account enumeration against cryptocurrency platforms
Phishing emails that created fake support cases
Vishing calls that referenced details from those emails
Counterfeit Ledger, Trezor, and Exodus applications
Seed-phrase theft and Telegram exfiltration
AI-assisted development, including an attempt to bypass an LLM’s safety controls
This is an extract. The publication continues at the source.
Read the original at the source: https://www.rapid7.com/blog/post/tr-operation-asterix-crypto-fraud-vishing-phishing
Officially imported this from Rapid7’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Rapid7 — imported from official source
- Official source
- https://blog.rapid7.com/rss/ RSS
- Imported
- September 18, 2026 11:35
- Versions
- 1 recorded
- Identity
bltaa2a3fb749678dcb