An elaborate cryptocurrency scam has been uncovered, utilizing artificial intelligence coding tools to refine victim targeting by processing extensive phone lists. This operation, known as Operation ASTERIX, has adapted a multifaceted approach combining phishing emails, phone calls, and counterfeit wallet applications to deceive individuals likely to possess digital assets.
Understanding the Operation ASTERIX Framework
Operation ASTERIX has provided a rare glimpse into the inner workings of a scammer’s toolkit. Investigators discovered a server hosting raw contact lists, databases, email systems, and fake software applications. Rapid7 analysts identified these activities after accessing an exposed web directory used by the perpetrators. According to a report shared with Cyber Security News (CSN), the operation utilized multiple channels that reinforced each other, lending credibility to fraudulent support requests.
A particularly concerning aspect of the operation is its ability to validate account ownership before initiating contact. This ensures the scammers avoid random cold calls and focus on individuals with potential connections to cryptocurrency platforms or hardware wallets, enhancing their chances of success.
The Role of Claude Code in the Scam
The operation’s server contained approximately 885,000 phone numbers from various regions, including a dataset of 316,002 German mobile numbers. Tools were used to determine if these numbers belonged to cryptocurrency platform users, with one dataset confirming 43,066 accounts, about 13.6% of the German numbers checked. Claude Code was instrumental in this process, assisting in formatting phone numbers and managing scripts linked to proxy pools.
Furthermore, AI was integrated throughout the development stages, not just in isolated code creation. This mirrors tactics seen in fake Claude Code installer attacks, where documentation is exploited to facilitate malicious downloads.
Phishing Techniques and Protective Measures
Once enriched leads were created, the scammers employed branded email panels to produce fake support cases and verification codes. These were followed by phone calls that referenced the same details, making the impersonation of support staff highly convincing. This tactic aligns with traditional phone-based malware delivery methods but is tailored for cryptocurrency theft.
The call environment included tools like Asterisk and outbound dialing scripts. Despite limited call log recovery, records indicated targeted rather than mass calling, with victims directed to counterfeit applications designed to mimic legitimate ones like Trezor Suite and Ledger Live. These fake programs attempted to harvest recovery phrases and other sensitive information.
Users are advised to be cautious of unexpected support communications and to only download applications from verified sources. Verifying caller identities through independent channels and refraining from executing commands from unfamiliar webpages can also protect against such scams.
In conclusion, the exposure of Operation ASTERIX highlights the growing sophistication of cybercriminals leveraging AI to enhance the effectiveness of their scams. Vigilance and adherence to security best practices remain crucial in safeguarding against such threats.
