Breaking
August 20, 2026

Rapid7 Uncovers Operation ASTERIX, AI-Powered Crypto Phishing Campaign Brenda Mary | usagoldmines.com

TLDR:

  • Rapid7 found 885,000 phone numbers tied to datasets supporting Operation ASTERIX’s crypto targeting activity.
  • A German dataset produced 43,066 identified Crypto.com accounts from 316,002 phone numbers.
  • Recovered files showed AI tools supporting coding, debugging, data processing, and phishing infrastructure.
  • Attackers switched AI providers after safety refusals and attempted to bypass another model’s safeguards.

Rapid7 has uncovered Operation ASTERIX, a crypto fraud campaign that combined AI-assisted development with targeted phishing. The operation used phone datasets, account-validation tools, phishing emails, voice calls, and counterfeit wallet applications.

Researchers found evidence that attackers used AI coding tools throughout the campaign’s development. The exposed infrastructure gave Rapid7 an unusual view into an active crypto phishing operation.

Operation ASTERIX Used AI to Target Crypto Users

Rapid7 discovered roughly 885,000 phone numbers across multiple datasets linked to the operation. The attackers used validation tools to identify numbers connected to cryptocurrency accounts.

One German dataset contained 316,002 mobile numbers. The operators identified 43,066 associated Crypto.com accounts from that list.

The campaign then narrowed its target pool using enriched records. Those records included names, contact details, locations, and account-related information in some cases.

Rapid7 said this information helped attackers make support impersonation appear more convincing. The operation coordinated emails and follow-up calls around matching support details.

The phishing infrastructure impersonated brands including Crypto.com and Binance. Attackers also maintained counterfeit applications resembling Trezor Suite, Ledger Live, and Exodus.

Rapid7 also recovered evidence of AI-assisted development from the exposed server. The operators used GitHub Copilot and Claude Code for coding, scripting, data processing, and infrastructure work.

AI Tools and Fake Wallet Apps Expanded Operation ASTERIX

The investigation showed that AI tools supported several parts of the campaign. Recovered artifacts indicated their use for application packaging, debugging, code changes, and phishing infrastructure.

Rapid7 found that Claude refused some requests involving code obfuscation. The operator then switched to Kimi and attempted to bypass its safety controls.

However, Rapid7 could not confirm whether that bypass attempt succeeded. The recovered evidence instead documented the operator’s effort to switch tools after encountering model restrictions.

The fake wallet applications formed another major part of the campaign. Rapid7 recovered versions designed to imitate popular cryptocurrency wallet software across macOS and Windows.

The operation also hosted a counterfeit Claude Code installer. According to Rapid7, that distribution channel attempted to install a malicious wallet application alongside the legitimate software.

Rapid7 discovered the campaign while much of its infrastructure remained active or under development. The firm notified relevant providers and authorities, including Apple’s security team, after documenting the activity.

The post Rapid7 Uncovers Operation ASTERIX, AI-Powered Crypto Phishing Campaign appeared first on Blockonomi.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.