TechNewsReel
Live

Operation ASTERIX: AI-Driven Phishing Campaign Targets 885,000 Crypto Users

Cybersecurity firm Rapid7 has exposed a sophisticated operation using AI to verify cryptocurrency ownership before launching targeted attacks.

TechNewsReel Newsroom · August 20, 2026

Cybersecurity firm Rapid7 has uncovered a sophisticated phishing operation, codenamed Operation ASTERIX, that targeted approximately 885,000 phone numbers. The campaign marks a dangerous evolution in social engineering by using artificial intelligence to identify and verify active cryptocurrency exchange users before attempting to steal their assets.

According to Rapid7, the attackers moved away from traditional bulk phishing in favor of a highly targeted multichannel approach. The operation utilized vishing (voice phishing), phishing emails, and the distribution of counterfeit software designed to mimic popular hardware wallets, including Trezor, Ledger, and Exodus. The ultimate goal of these tactics was to trick victims into revealing their mnemonic seed phrases, granting attackers full access to their funds.

To increase their success rate, the scammers employed AI to filter massive datasets of phone numbers to find high-value targets. In one German dataset containing 316,002 numbers, the attackers successfully identified 43,066 active Crypto.com accounts, a hit rate of approximately 13.6%. Additionally, investigators discovered a specialized database for Binance users containing 5,576 validated and enriched investor profiles. The attackers also used AI coding assistants to develop the campaign's infrastructure, specifically for obfuscating code and packaging Electron applications.

The Shift to Precision Phishing

This operation represents a fundamental shift from "spray-and-pray" tactics to precision targeting. By integrating AI, attackers can enrich victim profiles with names, emails, and geolocation data harvested from previous leaks. This allows vishing calls and emails to appear legitimate, as the scammers can reference specific personal details to gain the victim's trust. The automatic verification of leaks through neural networks is a primary challenge for investor security this year, as scammers no longer need to guess who holds cryptocurrency.

Industry Implications

Operation ASTERIX demonstrates that the possession of personal data by a caller is no longer a reliable indicator of legitimacy. The ability to automate the verification of crypto-asset ownership significantly increases the efficiency of phishing campaigns, rendering traditional security warnings obsolete. This trend forces a broader industry move toward zero-trust communication and encourages the adoption of non-custodial, cold-storage solutions to mitigate the risk of seed phrase theft.

Mitigation and Next Steps

In response to the threat, Rapid7 collaborated with Apple's security service to block several of the campaign's command and control servers. This intervention prevented the further distribution of fake macOS applications used to harvest credentials. While these blocks disrupt the current infrastructure, the use of AI to scale such attacks suggests that similar, evolved campaigns are likely to emerge as attackers refine their verification methods.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.