AI-Powered Phishing Operation Targets 885,000 Phone Numbers
A sophisticated crypto phishing operation, dubbed Operation ASTERIX, has been uncovered by Rapid7 Labs. The campaign leveraged AI coding assistants to create fake Ledger, Trezor, and Exodus apps, targeting users who self-custody their cryptocurrencies.
The researchers discovered a misconfigured server that exposed the entire playbook of the operation, including phone-number datasets, account-validation tools, phishing panels, voice-dialing scripts, and code to siphon stolen data through Telegram. The exposed web directory contained around 885,000 phone numbers, with 43,066 German mobile numbers confirmed to be associated with crypto exchange users.
The fake apps mimicked Trezor Suite and Ledger Live, asking users to enter a recovery phrase of 12 to 24 words that controls a hardware wallet. The stolen phrases were then exfiltrated via Telegram. Rapid7 found that AI coding assistants were used across the entire development process, including packaging the Electron apps, obfuscating code, fixing builds, and preparing malware for distribution.
The operation's reliance on AI tools highlights the growing threat of sophisticated phishing attacks in the crypto space. The discovery also raises concerns about the security of self-custodied funds and the potential for large-scale thefts.