Rapid7 uncovered an active cryptocurrency fraud operation, tracked as Operation ASTERIX, after finding an exposed attacker server containing phone-number datasets, account-validation tools, phishing panels, Asterisk-based dialing infrastructure, and counterfeit wallet applications impersonating Trezor, Ledger, and Exodus. The campaign validated more than 100,000 phone numbers against cryptocurrency services including Crypto.com and Kraken, enriched confirmed leads with personal details, and then used coordinated phishing emails and vishing calls to direct victims to fake wallet software or recovery-phrase entry pages.
The malware and infrastructure were built to steal wallet seed phrases and other victim data, with artifacts showing Telegram bot exfiltration, deceptive domains, trojanized installers, and macOS persistence via LaunchAgents. Rapid7 said the fake Trezor malware used Electron, process replacement, hidden windows, and local logging, while a trojanized Claude Code installer secretly deployed a fake Ledger Live payload alongside the legitimate tool to reduce suspicion. Recovered logs also showed the operator relied heavily on AI coding assistants including GitHub Copilot, Claude Code, and Kimi to develop, obfuscate, and host components of the scam infrastructure.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
While the operation was still active or under development, Rapid7 disclosed the identified infrastructure and findings to relevant providers and authorities, including Apple’s security team. This disclosure followed Rapid7’s analysis of the exposed server and recovered tooling.
Rapid7 found a trojanized Claude Code installer site that installed the legitimate Claude tool while also deploying a hidden fake Ledger Live payload to reduce suspicion. Related infrastructure included the suspicious domain macos-claude[.]com.
Recovered prompts, shell history, and project files showed the operator used AI assistants including GitHub Copilot, Claude Code, and Kimi to package Electron apps, obfuscate code, troubleshoot builds, and modify phishing infrastructure. When one model resisted, the operator switched providers and attempted to jailbreak another model’s safety controls.
The recovered fake Exodus application used a trojanized jquery.min.js file to retrieve its real payload from a remote server after installation. Associated artifacts also showed macOS persistence masquerading as Exodus software.
Rapid7 found that the fake Ledger Live build included a Windows clipboard hijacker that swapped copied cryptocurrency addresses for attacker-controlled ones. Related artifacts also included impersonated Ledger installers and macOS persistence paths.
The fake Trezor application ran as a hidden Electron process, replaced the legitimate app, displayed a counterfeit recovery-phrase window, and exfiltrated entered seed phrases and victim IP data to a Telegram bot under the label "TREZOR SECRET PHRASE." On macOS it used LaunchAgent persistence including com.trezormovement.agent.plist and io.trezor.agent.plist.
Rapid7 recovered counterfeit wallet applications for Trezor Suite, Ledger Live, and Exodus on macOS and Windows. The malware used trojanized installers, persistence mechanisms, and remote payload delivery to target cryptocurrency users across multiple wallet brands.
Operation ASTERIX combined phishing emails with coordinated phone calls using Asterisk, 3CX, and scripts such as autodialer.sh and telegram_dialer_bot.py. The phishing infrastructure impersonated cryptocurrency and financial brands and generated fake support cases and verification codes for use during calls.
The exposed infrastructure showed the operator used account-checking tools to determine which phone numbers were tied to active cryptocurrency accounts, including Crypto.com and Kraken. Recovered logs showed 43,066 confirmed accounts from a German dataset of 316,002 numbers, and the server held about 885,000 phone numbers across multiple regions.
Rapid7 researchers discovered an exposed web directory on infrastructure supporting a cryptocurrency fraud campaign they named Operation ASTERIX. The server exposed phone-number datasets, account-validation tools, phishing panels, dialing infrastructure, counterfeit wallet apps, and Telegram-based seed-phrase exfiltration components.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.