Listen to this Post

A New Generation of Crypto Fraud
Cryptocurrency scams are becoming less dependent on mass spam and increasingly focused on precision. Instead of sending the same malicious message to thousands of strangers, modern fraud operations can first identify who is likely to own digital assets, enrich those records with personal information, and then approach victims through multiple channels that reinforce one another.
That is the disturbing picture uncovered by Rapid7 in an operation dubbed Operation ASTERIX. The campaign combined cryptocurrency-account discovery, phishing, voice phishing (vishing), fake hardware-wallet applications, automated telephone systems, and Telegram-based data exfiltration into a single fraud ecosystem.
The operation demonstrates an important evolution in cybercrime: attackers are no longer relying on one convincing phishing email. They are building entire customer-support impersonation operations around information stolen or purchased beforehand.
Why the Operation Was Called ASTERIX
The name ASTERIX was derived from Asterisk, the open-source telephony platform discovered on an exposed server associated with the campaign.
Asterisk was not simply sitting there as an ordinary communications component. Investigators found evidence suggesting that the phone infrastructure helped the attackers conduct vishing operations and connect telephone calls with other parts of the scam.
The combination was particularly dangerous.
A victim could first receive an email warning about suspicious cryptocurrency activity. Shortly afterward, an alleged support representative could call, reference the same incident, provide a fabricated case number, and ask the victim to follow instructions involving a cryptocurrency wallet.
The result is a carefully constructed illusion of legitimacy.
The Exposed Server Became a Window Into the Criminal Operation
One of the most valuable discoveries came from an exposed directory that provided researchers with an unusually detailed view of the attackers’ infrastructure.
The directory reportedly contained raw telephone-number databases, account-validation tools, phishing panels, lead databases, dialer scripts, fake cryptocurrency-wallet applications, and code designed to transmit stolen wallet recovery phrases to Telegram bots.
This is significant because investigators normally see only fragments of a cybercriminal operation.
A phishing page might be visible.
A malicious application might be recovered.
A suspicious telephone number might be reported.
But the exposed infrastructure connected these individual pieces and showed how they could work together as a complete fraud pipeline.
The Attackers Started With Reconnaissance
The most important feature of ASTERIX was that the criminals apparently did not begin by calling random people.
They first attempted to determine whether telephone numbers were associated with cryptocurrency services.
This gave the attackers an opportunity to separate potentially valuable victims from ordinary numbers.
A person with no apparent connection to cryptocurrency might receive nothing.
Someone whose number appeared connected to a crypto exchange or wallet ecosystem could instead become a high-priority lead.
That distinction dramatically improves the economics of social engineering.
Thousands of Numbers Could Be Tested Automatically
One recovered account-checking tool reportedly targeted a Crypto.com account-verification endpoint.
The tool was designed for high-volume processing, using approximately 300 concurrent threads, retry mechanisms, and rotating residential proxies.
In one reported example, a dataset containing 316,002 German mobile numbers produced approximately 43,066 suspected cryptocurrency-linked accounts.
That represents a hit rate of roughly 13.6%.
The significance is not merely the number itself.
The larger lesson is that criminals can use automated validation to transform a huge pool of ordinary telephone numbers into a much smaller database of potentially profitable targets.
The Targeting Extended Beyond One Cryptocurrency Platform
The infrastructure reportedly contained evidence of additional targeting.
Investigators found indications of a Kraken account checker as well as datasets connected to Ledger users, United Kingdom targets, Canadian fintech users, Hong Kong residents, and other geographic or service-specific groups.
Ledger-related information was reportedly divided into 54 country-specific files.
That suggests the operation was not built around a single narrow victim profile.
Instead, the criminals appeared to maintain multiple targeting categories that could be used depending on geography, cryptocurrency platform, or available information about a prospective victim.
From Phone Number to High-Value Lead
Finding a potentially valuable telephone number was only the beginning.
The attackers reportedly enriched selected records with additional information, including names, email addresses, telephone numbers, location information, account context, and in some cases payment-card information.
Files such as valids.txt and valid_leads.db reportedly helped organize this information.
This is where the campaign became especially dangerous.
A telephone call is much easier to believe when the person on the other end already knows your name, your email address, the cryptocurrency service you may use, and details surrounding an alleged security incident.
The Psychology Behind the Scam
Imagine receiving an email claiming that suspicious activity has been detected on your cryptocurrency account.
You are then contacted by telephone.
The caller knows your name.
They know which service you supposedly use.
They provide a case number that matches the email.
They may even ask you to confirm information that appears to be already known by legitimate customer support.
At that point, the victim is no longer evaluating an isolated email.
They are evaluating an entire story.
That is exactly why multi-channel social engineering can be so effective.
Phishing and Vishing Worked Together
The campaign reportedly used phishing panels designed to imitate cryptocurrency brands, including Crypto.com and Binance.
Telephone infrastructure based on Asterisk and 3CX reportedly supported the voice side of the operation.
Scripts with names such as autodialer.sh and power_dialer.sh suggested that portions of the calling process could be automated.
This creates an important distinction between conventional phishing and coordinated social engineering.
The attackers were not simply trying to convince victims to click a link.
They were attempting to create a complete customer-support experience.
Fake Wallet Applications Added Another Layer
The operation also involved fraudulent wallet applications masquerading as legitimate cryptocurrency software.
Recovered files reportedly included fake versions associated with well-known wallet brands such as Ledger, Trezor, and Exodus.
The danger of fake wallet applications is obvious: cryptocurrency users are trained to treat their recovery phrase as the ultimate key to their funds.
A malicious application that convincingly imitates a trusted wallet can exploit that trust at exactly the moment a victim believes they are protecting their assets.
Recovery Phrases Were a Primary Prize
A cryptocurrency wallet recovery phrase can provide access to digital assets.
That makes it one of the most valuable pieces of information a crypto-focused criminal can obtain.
According to the investigation, code found in the exposed infrastructure was designed to transmit stolen wallet recovery phrases to Telegram bots.
This is particularly concerning because Telegram can provide criminals with a convenient mechanism for receiving stolen information and coordinating activity.
The attack chain therefore potentially moved from:
Victim identification → social engineering → fake support interaction → malicious wallet software → recovery-phrase theft → attacker-controlled infrastructure.
Telegram Became Part of the Data Pipeline
Telegram was reportedly used not only as a communication platform but also as an exfiltration destination.
Malicious code could send stolen wallet information to attacker-controlled Telegram bots.
This approach can be attractive to criminals because messaging platforms can be easier to integrate into lightweight malware than a custom data-management system.
It also illustrates a broader cybersecurity problem: legitimate communication services can be abused as infrastructure for criminal operations.
ASTERIX Was Not Purely Automated
Despite the presence of automation, Rapid7 reportedly observed relatively limited email and lead-lookup activity over a two-week period.
That finding is important.
The campaign appears to have combined automated reconnaissance with comparatively hands-on victim engagement.
In other words, the attackers could automate the boring parts while reserving human attention for targets that looked valuable.
This is often more effective than blindly attacking everyone.
The Economics of Precision Fraud
Cybercriminals operate businesses, even when those businesses are illegal.
Every telephone call costs time.
Every phishing interaction requires infrastructure.
Every fake application has to be distributed.
Human operators cannot realistically spend the same amount of effort on every potential victim.
Account validation and lead enrichment solve that problem.
By identifying promising targets first, criminals can allocate their most convincing social-engineering techniques to people who appear more likely to own valuable cryptocurrency assets.
Why This Matters Beyond Cryptocurrency
Although ASTERIX focused heavily on cryptocurrency users, the underlying strategy is not limited to crypto.
The same model could theoretically be applied to banking customers, investment platforms, payment services, enterprise software users, or online marketplaces.
The core technique is simple:
Identify the customer first. Then construct the scam around what you already know.
That is considerably more dangerous than generic spam.
The Human Element Remains the Weakest Link
Modern cybersecurity often focuses on technical controls, endpoint protection, authentication, encryption, and network monitoring.
All of those remain essential.
But ASTERIX highlights another uncomfortable reality: an attacker does not necessarily need to defeat a security system if they can persuade the user to defeat it for them.
A convincing caller can manipulate trust.
A fake application can manipulate familiarity.
A fabricated security incident can manipulate fear.
Together, these psychological techniques can become more powerful than a conventional exploit.
Why Fake Customer Support Is So Effective
Customer-support impersonation works because people expect companies to contact them about security problems.
Banks send fraud alerts.
Cryptocurrency exchanges send account warnings.
Wallet providers publish security notifications.
Technology companies investigate suspicious activity.
The criminal does not have to invent an entirely unrealistic scenario.
They only need to imitate something that could plausibly happen.
The Importance of Caller Verification
A telephone number should never be treated as proof of identity.
Even when a caller knows personal information, that information does not prove that the caller represents the company they claim to represent.
Users should independently navigate to the official website or application of the relevant service and contact support through an authenticated channel.
They should not use telephone numbers supplied by unexpected callers.
They should also be suspicious of anyone requesting passwords, authentication codes, wallet recovery phrases, private keys, or remote access.
Recovery Phrases Must Be Treated as Untouchable
A legitimate cryptocurrency-support representative should never need a user’s wallet recovery phrase.
Not by telephone.
Not through email.
Not through Telegram.
Not through a support ticket.
Not through a supposedly official wallet application.
Anyone requesting a recovery phrase should be treated as hostile until proven otherwise.
Once exposed, the phrase may give an attacker the ability to control the associated wallet.
Deep Analysis
Inspecting Suspicious Files Safely
Security teams investigating similar campaigns can begin by calculating hashes rather than executing suspicious binaries.
sha256sum suspicious-file
For a suspicious macOS application bundle:
find suspicious.app -type f -print0 | xargs -0 shasum -a 256
These hashes can then be compared against internal threat-intelligence systems and controlled malware-analysis platforms.
Searching for Telegram Exfiltration
Defenders should search application and endpoint telemetry for suspicious Telegram-related connections, especially when they occur from unexpected processes.
Example Linux investigation:
grep -RniE 'api.telegram.org|t.me|sendMessage|bot[0-9]+:' /var/log 2>/dev/null
Network monitoring can also help identify endpoints repeatedly communicating with messaging infrastructure in unusual circumstances.
Looking for Suspicious Dialer Activity
Organizations operating Asterisk or 3CX should investigate unexpected outbound-call patterns.
Useful checks can include:
grep -RniE 'originate|dial|callfile|outbound' /var/log/asterisk/ 2>/dev/null
The exact log locations and commands will vary according to deployment.
Hunting for Credential and Recovery-Phrase Theft
Defenders should search endpoint telemetry for applications accessing wallet directories unexpectedly.
For Linux systems, a basic filesystem investigation might begin with:
find ~ -type f ( -iname 'wallet' -o -iname 'seed' -o -iname 'keystore' ) 2>/dev/null
This is an investigative starting point rather than a definitive malware-detection rule.
Monitoring for Suspicious Script Execution
Shell scripts with names suggesting automated dialing or mass processing deserve additional scrutiny when discovered on infrastructure that should not perform those functions.
find / -type f ( -name 'autodialer.sh' -o -name 'power_dialer.sh' ) 2>/dev/null
Organizations should correlate such findings with process execution, network connections, file creation, and authentication logs.
Protecting Crypto Users
The strongest defense is often procedural.
Users should independently open their cryptocurrency
They should never install wallet software from a link supplied during an unsolicited call.
They should never disclose recovery phrases.
They should never transfer funds merely because a caller claims that doing so will “protect” them.
Threat Intelligence Indicators
One reported shared app.asar SHA-256 associated with fake Trezor builds was:
ba9d459169a303067a4fe36c8b8582a5ea023b9c270dafe89613bab840501b19
A reported macOS integrity value was:
918fa540126b7db6424652d84a5ce7e968947136db3d6e3e0cab30ea309e25a2
These indicators should be treated as investigation artifacts rather than standalone detection mechanisms.
Threat actors can rebuild applications, change infrastructure, rotate domains, and generate new binaries.
Security teams should therefore combine hashes with behavioral detection, endpoint telemetry, network intelligence, and user reports.
What Undercode Say:
Precision Is Becoming the New Phishing
The most important lesson from ASTERIX is not that criminals discovered another phishing technique.
It is that phishing is becoming increasingly data-driven.
Validation Comes Before Manipulation
The attackers reportedly attempted to establish which telephone numbers were connected to valuable services before investing additional effort.
Personal Data Makes Social Engineering Stronger
A scam becomes significantly more believable when attackers already know a victim’s identity and service relationships.
Multi-Channel Attacks Create False Confirmation
An email followed by a phone call can make the second communication appear to validate the first.
Familiar Brands Are Being Weaponized
Crypto users recognize names such as Binance, Crypto.com, Ledger, Trezor, and Exodus.
Attackers exploit that recognition rather than trying to establish a completely unfamiliar identity.
Fake Software Can Be More Dangerous Than Fake Websites
A website may steal credentials.
A malicious wallet application can potentially expose the secrets controlling cryptocurrency assets.
Recovery Phrases Are High-Value Targets
Attackers do not necessarily need to steal cryptocurrency directly.
They can steal the information that gives them control over it.
Automation Makes Criminal Operations Scalable
Threaded validation, proxies, scripts, dialers, and databases allow criminals to process enormous datasets.
Human Operators Still Matter
The campaign reportedly showed signs of hands-on targeting rather than completely automated victim interaction.
Criminals Can Automate Selection and Humanize the Scam
This is perhaps the most dangerous combination.
Machines identify promising victims.
Humans conduct convincing conversations.
Customer Support Is a Powerful Disguise
People are conditioned to trust support representatives when something appears wrong with an account.
Fear Is a Social-Engineering Accelerator
A warning about suspicious activity can make victims act before they have time to verify the claim.
Urgency Reduces Critical Thinking
When people believe their funds are at immediate risk, they become more willing to follow instructions.
Cryptocurrency Adds Financial Pressure
The possibility of losing digital assets can make an otherwise cautious person react emotionally.
Telegram Shows the Abuse of Legitimate Services
Attackers can use common communication platforms as components in criminal infrastructure.
Exposed Infrastructure Can Reveal the Entire Business Model
Misconfigured servers occasionally provide investigators with information that would otherwise remain hidden.
Operational Errors Continue to Help Defenders
Even sophisticated criminals can leave databases, scripts, credentials, logs, or applications exposed.
Threat Hunting Must Go Beyond Hashes
A single indicator can disappear quickly.
Behavioral patterns are harder for attackers to eliminate.
Endpoint Security Is Essential
Fake wallet applications should be investigated as potential credential and secret-stealing malware.
Network Monitoring Is Equally Important
Unexpected outbound connections can reveal command-and-control or exfiltration behavior.
Identity Security Matters Too
Users need clear procedures for independently verifying support communications.
Cryptocurrency Companies Face a Trust Problem
Security teams must anticipate that criminals will impersonate their employees and support processes.
Support Channels Should Be Difficult to Spoof
Authenticated communication inside official applications can provide stronger assurance than unsolicited telephone calls.
Users Need Better Security Education
Generic warnings about “phishing” are not always enough.
People should be taught specifically that attackers may already know personal information about them.
Caller Knowledge Is Not Proof of Legitimacy
A criminal who possesses a database can sound remarkably convincing.
Case Numbers Can Be Fake
A reference number shared between email and telephone does not automatically establish authenticity.
Verification Must Be Independent
The safest approach is to initiate contact through a trusted channel rather than following the attacker’s instructions.
Wallet Security Should Assume Social Engineering
Technical protections cannot compensate for a victim willingly handing over a recovery phrase.
Organizations Should Monitor High-Risk Administrative Infrastructure
Asterisk and 3CX deployments should be monitored for abnormal outbound calling behavior.
Suspicious Automation Deserves Attention
Unexpected shell scripts, dialer utilities, proxy configurations, and bulk-validation tools can provide valuable detection signals.
Databases Are Security Assets
A file such as valid_leads.db may contain information that can become a weapon when exposed.
Data Minimization Reduces Attack Impact
The less unnecessary personal information stored, the less useful a breach or compromise becomes.
Criminal Intelligence Pipelines Are Becoming More Professional
ASTERIX resembles a commercial lead-generation operation adapted for fraud.
The Real Product Is Trust
The attackers were effectively manufacturing trust from stolen information.
Social Engineering Is Becoming Data-Backed
The era of obviously generic scam messages is giving way to personalized deception.
Crypto Users Should Assume Targeting Is Possible
Holding digital assets can make a person more attractive to specialized criminal groups.
Security Teams Should Prepare for Combined Attacks
Email, voice, malware, identity abuse, and data theft should not be investigated as completely separate events.
The Biggest Lesson Is Simple
If an unexpected caller knows everything about you, that does not mean they are legitimate.
It may mean your information has already been weaponized against you.
✅ The Campaign’s Multi-Stage Nature Is Consistent With the Reported Investigation
The supplied article accurately describes ASTERIX as combining account validation, phishing, telephone-based social engineering, fake wallet applications, and Telegram-based data handling.
✅ The Reported 13.6% Hit Rate Is Mathematically Consistent
43,066 suspected matches out of 316,002 numbers produces a rate of approximately 13.6%, so the percentage stated in the article is consistent with the supplied figures.
✅ The Campaign Demonstrates a Targeted Rather Than Purely Mass-Market Model
The reported lead enrichment, geographic datasets, account checkers, and human-assisted calling support the assessment that the operation sought to prioritize potentially valuable victims.
⚠️ Indicators Should Not Be Treated as Permanent Signatures
Hashes can help investigators identify known malicious files, but they do not prove that every related sample will share the same fingerprint.
⚠️ Account Validation Results Require Context
A “hit” from an account-checking system should be understood as evidence generated by the attacker’s tooling, not automatically as independent proof that every identified number belonged to an active cryptocurrency account.
Prediction
(+1) Precision-Based Crypto Fraud Will Become More Common
The next evolution of cryptocurrency scams is likely to involve greater use of stolen datasets, automated account discovery, AI-assisted personalization, and coordinated voice-and-phishing campaigns.
(+1) Fake Support Operations Will Become More Convincing
Criminal groups will increasingly imitate the complete customer-support experience rather than relying on a single malicious webpage.
(+1) Wallet Malware Will Remain a High-Value Threat
As cryptocurrency holdings remain attractive targets, fake wallet applications and recovery-phrase theft are likely to remain important attack techniques.
(+1) Threat Intelligence Will Become More Behavioral
Security teams will increasingly combine file hashes with network behavior, process execution, identity telemetry, and social-engineering indicators.
(-1) Generic Phishing Will Become Less Effective Against Better-Trained Users
As awareness improves, obvious cryptocurrency phishing messages are likely to lose effectiveness, encouraging attackers to invest more heavily in personalized and multi-channel deception.
The Bigger Warning
Operation ASTERIX is a reminder that the most dangerous scam may not look like a scam at all.
It may begin with a legitimate-looking email.
Then come a telephone call, a familiar brand name, a convincing case number, and a caller who knows information that only a genuine support representative supposedly should know.
That is the psychological advantage criminals are pursuing.
They do not necessarily need to break into the victim’s account if they can convince the victim that the attacker is already there to help.
For cryptocurrency users, the rule should remain absolute: never give a recovery phrase, private key, authentication code, or wallet secret to an unsolicited caller or application.
And for security teams, ASTERIX offers an even broader lesson: modern fraud operations increasingly look like data pipelines. They discover targets, validate them, enrich them, contact them, manipulate them, and finally monetize the information.
The more organizations understand that entire chain, the harder it becomes for attackers to hide behind the illusion of legitimate customer support.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




