Operation Asterix hit 885,000 phone numbers, Rapid7 finds

Rapid7 reports Operation Asterix used fake Ledger, Trezor and Exodus apps plus fraudulent emails and calls to target about 885,000 phone numbers to steal crypto.

Cybersecurity firm Rapid7 reported that a phishing campaign dubbed Operation Asterix targeted roughly 885,000 phone numbers across multiple countries to steal cryptocurrency. The campaign directed victims to counterfeit wallet apps and contacted targets with fraudulent support emails and phone calls.

Rapid7 analysts Anna Sirokova and Jan Recinsky said the campaign began with the collection of large phone directories. The largest file contained 316,002 German mobile numbers. Other directories held contacts from Hong Kong, Bulgaria, the UK, the US, Canadian fintech companies and additional Ledger-related lists. The attackers used those lists to validate numbers against exchange accounts and to prioritize high-value targets.

From the German dataset, attackers matched 43,066 entries to cryptocurrency exchange accounts, a hit rate Rapid7 estimated at about 13.6 percent. The report identified 5,576 accounts matched to Binance users that were queued for attack. Recovered logs showed fake emails impersonating Crypto.com and a “checker” tool used to bulk-validate phone numbers against Kraken accounts. Artifacts recovered by Rapid7 indicate attackers used automated tools and artificial intelligence components as part of the operation.

The campaign used multiple social engineering vectors. Victims were lured to fake mobile and desktop wallet applications impersonating hardware and software wallets such as Ledger, Trezor and Exodus. The attackers aimed to obtain seed phrases and other credentials. They followed up with fraudulent support emails and phone inquiries to extract information or prompt unsafe actions.

Phishing and social engineering have driven a large share of recent crypto losses. Data from blockchain security firm Hacken shows phishing and social-engineering scams accounted for $306 million of $482 million lost in the first quarter of the year. Rapid7’s report adds to recent incidents affecting users: in August a Trezor shipping partner reported a personal data breach affecting about 14,000 customers; in July an investor lost nearly $1 million after signing a malicious token approval on Ethereum; and in November 2023 a fake Ledger Live app led to the theft of $588,000 across 38 transactions.

Rapid7 outlined the campaign’s sequence as acquisition of phone directories, bulk validation against exchange accounts, prioritization of matched accounts, deployment of spoofed wallet apps and support channels, and exfiltration of credentials and seed phrases. The firm recommended heightened caution with unsolicited communications, verifying app downloads directly from vendor websites, and never entering seed phrases or approving transactions in response to emails or phone calls.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author