Rapid7: Operation ASTERIX Used AI for Crypto Phishing Tools and Wallet Apps
Rapid7 identified an exposed web directory supporting the fraud operation and recovered phone-number datasets, account-validation tools, phishing panels, vishing scripts,...
Rapid7 says a cryptocurrency fraud operation it tracks as Operation ASTERIX used AI coding assistants to build crypto phishing tools and malicious wallet apps, after the security firm recovered the operator’s tooling from an exposed web directory that was still active at the time of disclosure.
Rapid7 identified an exposed web directory supporting the fraud operation and recovered phone-number datasets, account-validation tools, phishing panels, vishing scripts, fake wallet apps, and Telegram exfiltration code, according to its incident report. For related coverage, see Bitcoin’s 2 p.m. Fed Risk Signals a Bigger Hawkish Camp.
How Operation ASTERIX allegedly used AI to build crypto phishing tools
Operation ASTERIX is Rapid7’s name for a single crypto-fraud operation whose full workflow was exposed on a misconfigured server. The name comes from the Asterisk telephony platform found on that server, which Rapid7 said the operator used to automate voice-phishing calls alongside phishing emails and counterfeit wallet applications. For related coverage, see Deribit Stock and ETF Perpetuals Launch on August 31.
The AI angle sits at the center of the report. Rapid7 said recovered prompts, shell history, and project files show AI coding assistants were used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution. In plain terms, the operator appeared to lean on AI as a development aid across the toolchain rather than for a single task.
KEY POINTS
- Rapid7 says AI coding assistants helped build and obfuscate the operation’s phishing and malware tooling.
- The campaign paired vishing via the Asterisk platform with phishing emails and fake wallet apps.
- Rapid7 disclosed the infrastructure to authorities, including Apple’s security team, while it was still live.
The malicious wallet software was the payload. Rapid7 recovered fake Trezor Suite, Ledger Live, and Exodus applications for macOS and Windows that were designed to steal cryptocurrency wallets and recovery phrases from victims who installed them.
The operation also invested heavily in targeting. The exposed server held roughly 885,000 phone numbers tied to the fraud workflow, including a German dataset of 316,002 mobile numbers used to identify potential victims.
Those numbers were not used blindly. Rapid7 said a Crypto.com checker submitted phone numbers to an account-existence endpoint with 300 concurrent threads, retry logic, and rotating residential proxies to confirm which numbers belonged to real exchange users before any outreach.
The validation step worked. Rapid7 said 43,066 accounts were confirmed from the German dataset, an approximately 13.6% hit rate that told the operator which targets were worth a phishing email or a scripted support call.
Rapid7 said it disclosed the identified infrastructure to relevant authorities, including Apple’s security team, while the operation was still active. Christiaan Beek, tied to the disclosure, wrote that researchers “also found evidence of AI being woven directly into the attacker’s development workflow.”
The reported use of AI to find and weaponize software weaknesses echoes recent research on the other side of the fence, including BitBox’s disclosure that AI surfaced severe firmware flaws in a hardware wallet, underscoring how the same tooling is now cutting in both directions.
Why the Operation ASTERIX campaign matters for crypto users and wallet security
Fake wallet apps are among the most dangerous vectors in crypto because a wallet’s job is to hold the keys. The counterfeit Trezor Suite, Ledger Live, and Exodus builds were engineered to capture recovery phrases, and a stolen seed phrase gives an attacker permanent, irreversible control of the funds it protects.
The AI dimension matters because it lowers the barrier to producing convincing tooling at speed. Rapid7’s evidence that assistants helped package Electron apps and obfuscate code suggests a lone operator can now assemble cross-platform malware and phishing infrastructure that once required a team, a dynamic that concerns regulators already scrutinizing how AI models intersect with crypto operations.
The telemetry also reframes the threat as targeted, not mass-spam. One Rapid7 panel logged only a handful of successful lead lookups and phishing emails over roughly two weeks, indicating the validation step lets operators focus effort on confirmed exchange users rather than blasting everyone.
That maps directly to consumer guidance. Apple’s support material says social-engineering scams commonly use fraudulent emails, spoofed support calls, misleading pop-ups, and software downloads to steal credentials or data, warning users to treat unsolicited “support” contact with suspicion.
For wallet users, the practical takeaways are narrow and specific: download wallet software only from the vendor’s verified channels rather than links delivered by email or a phone call, never enter a recovery phrase into any app that requests it, and treat an inbound call claiming to be exchange or Apple support as a phishing attempt until independently verified. Interest in AI-driven crypto tooling is rising across the sector, with platforms like Coinbase’s Base funding AI agent projects, which makes distinguishing legitimate apps from convincing fakes harder for everyday users.
This piece is news analysis of Rapid7’s disclosure, not a full incident-response guide. Rapid7 published no confirmed stolen-funds total or victim count in the released materials, and no public regulator filing tied specifically to Operation ASTERIX had surfaced as of publication.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
