- Rapid7 Labs recovered roughly 885,000 phone numbers from an exposed server, the largest single file holding 316,002 German mobile numbers.
- Account-checking tools confirmed 43,066 of those German numbers as Crypto.com account holders, a hit rate Rapid7 puts at about 13.6%.
- Counterfeit Trezor Suite, Ledger Live and Exodus builds were made to drain wallets, with the Trezor clone sending stolen recovery phrases to a Telegram bot.
Rapid7 researchers Anna Širokova and Jan Recinsky have discovered Operation Asterix, finding a misconfigured web directory exposing a fraud operation’s entire working environment, including phone-number datasets, account-validation tools, phishing panels, dialler scripts, counterfeit wallet builds and AI session logs.
The server held about 885,000 phone numbers split into files by region and source. The largest covered 316,002 German mobiles, with further lists for Hong Kong, Bulgaria, the UK, US and Canadian fintech services, and Ledger customers across 54 country files.
A Go-based checker pushed those numbers through a Crypto.com account-existence endpoint using 300 concurrent threads and rotating residential proxies, confirming 43,066 accounts from the German set, and a separate checker targeted Kraken.
Matches were enriched with names, email addresses, locations, account details and sometimes payment-card context. One screenshot in the report shows the operator’s Binance lead panel holding 5,576 validated targets queued for attack.
Rapid7 describes a targeted operation: one panel logged 20 lead lookups and six phishing emails over roughly two weeks.
Read more: South Korea Orders Polymarket Blocked Over Illegal Gambling Concerns
The operators also cloned Anthropic’s Claude Code documentation page at macos-claude[.]com, swapping the macOS install command for one that fetched a hidden Ledger Live clone, then ran the genuine Claude installer so nothing looked wrong.
Rapid7 found the operator used GitHub Copilot and Claude Code during development. When Claude declined to obfuscate the Ledger builds, the operator moved to Kimi and submitted a jailbreak prompt.
“The recovered evidence does not confirm whether Kimi complied,” the report states. Rapid7 concludes that for this operator, model restrictions “became another engineering problem to solve”, and expects jailbreak attempts to become routine in malware pipelines.
It disclosed the infrastructure to authorities including Apple’s security team, and published the indicators of compromise on GitHub.
How the Wallet Apps Worked
The counterfeit Trezor Suite ran as a hidden one-pixel transparent window, scanned the process list every five seconds, killed the genuine app when the victim opened it and pushed its own window forward.
Stolen phrases went to a Telegram bot with the victim’s IP address before the victim was redirected to the real Trezor site. Its form accepted 12-, 18-, 20- or 24-word phrases, then returned a fake validation error so the victim typed the phrase again.
The Windows build was broken and worked only as a static seed-phrase collector. The fake Ledger Live swapped copied wallet addresses on Windows and hid from the macOS Dock.
Read also: Bitpanda Hit With €70,000 MiCA Fine in Austria’s First Published Enforcement Action
Cryptocurrency,Hackers#Operation #Asterix #Targets #Phone #Numbers #Crypto #Phishing #Campaign1787294413
