A recent cryptocurrency fraud operation, dubbed Operation ASTERIX, has been uncovered utilizing AI coding tools to process extensive phone number lists, enhancing their victim-targeting capabilities. This campaign integrated account verification, phishing emails, phone calls, and counterfeit wallet software to focus on individuals likely to possess digital assets.
Analysts at Rapid7 discovered the operation after identifying an exposed web directory containing raw contact lists, lead databases, email panels, calling tools, and fake applications. The evidence suggests a coordinated effort where each communication channel reinforced the others, making fraudulent support requests appear legitimate.
The server held approximately 885,000 phone numbers from various regions, including a file with 316,002 German mobile numbers. Account-checking tools were employed to determine if these numbers were associated with cryptocurrency platforms. In one dataset, 43,066 accounts were confirmed, representing about 13.6% of the numbers checked. These verified contacts were then enriched with additional details such as names, email addresses, locations, and account information.
AI tools like Claude Code played a significant role in this workflow. Recovered session logs revealed that the operators used Claude Code to clean and format files containing over 100,000 Polish phone numbers, add country prefixes, and manage checking scripts connected to proxy pools. This indicates that AI was integrated throughout the development process, not just for isolated code creation.
The operation also utilized AI assistants for packaging Electron applications, modifying phishing infrastructure, troubleshooting builds, and attempting code obfuscation. When Claude Code resisted assisting with certain parts of the wallet-malware workflow, the operators switched to another provider and used a custom jailbreak prompt to bypass safety controls.
After creating enriched leads, the scammers used branded email panels to generate fake support cases and verification codes. Follow-up calls cited the same details, allowing callers to convincingly impersonate support staff. This technique mirrors previous phone-based malware delivery methods but is now applied to cryptocurrency theft.
The calling environment included Asterisk and scripts for outbound dialing. While not all call logs were recovered, one panel recorded 20 successful lead lookups and six phishing emails over approximately two weeks, indicating deliberate targeting rather than indiscriminate mass calling.
Victims were directed to counterfeit applications designed to mimic legitimate ones like Trezor Suite, Ledger Live, or Exodus. The fake Trezor program, for instance, would wait for the genuine application to open, terminate it, and display a lookalike recovery-phrase screen, prompting users to enter their recovery phrases, which were then sent to the attackers.
This layered deception resembles previous attacks where malicious Claude Code ads relied on trusted-looking setup instructions to deceive users.
The integration of AI tools in cybercriminal operations like Operation ASTERIX highlights the evolving sophistication of such schemes. By leveraging AI for data processing and automation, scammers can efficiently target and deceive victims. This underscores the need for continuous advancements in cybersecurity measures to counteract these increasingly complex threats.