Crypto Scammer Operation 'ASTERIX' Leveraged Claude AI for Advanced Victim Targeting
A sophisticated cryptocurrency scam operation, dubbed Operation ASTERIX, utilized AI coding tools like Claude to process over 100,000 phone numbers for highly targeted attacks, employing a multi-channel approach to steal digital assets.

A cryptocurrency fraud operation, tracked as Operation ASTERIX, has been uncovered using advanced AI coding tools to refine massive phone lists into a highly effective victim-targeting system. This campaign integrated account validation, phishing emails, phone calls, and counterfeit wallet software to systematically target individuals likely to possess digital assets. The operation provided an unusually comprehensive view into a scammer's operational infrastructure, with its server containing raw contact lists, lead databases, email panels, calling tools, and fake applications.
Security researchers at Rapid7 discovered the activity after identifying an exposed web directory utilized by the operators. Their analysis revealed a meticulously planned, multi-channel operation where each component reinforced the others, lending credibility to seemingly legitimate support requests. The impact extends beyond simple "one-shot" wallet theft attempts. By first validating account ownership before initiating contact, the threat actor could bypass random cold calls and concentrate resources on individuals with confirmed connections to cryptocurrency exchanges or hardware wallets.
The exposed server held approximately 885,000 phone numbers from various global regions, including a significant dataset of 316,002 German mobile numbers, alongside lists associated with Hong Kong, Bulgaria, the UK, the US, and Canadian financial services. The attack chain involved the use of specialized tools to verify if phone numbers belonged to users of cryptocurrency platforms. In one instance, tooling confirmed 43,066 accounts within a German dataset, representing about 13.6 percent of the numbers checked, transforming these into richer profiles with names, email addresses, and account details.
Anthropic's Claude AI played a crucial role in this workflow. Recovered session logs indicated the operator instructing Claude to clean and format a file containing over 100,000 Polish phone numbers, append country prefixes, and manage scripts for account checking, which were integrated with proxy pools. This demonstrates the AI's use throughout the development lifecycle, not just for isolated code generation. The broader pattern aligns with attacks involving fake AI code installers, where convincing documentation lures users into downloading malicious software.
Further analysis showed the operator leveraging AI assistants for packaging Electron applications, modifying phishing infrastructure, troubleshooting software builds, and attempting code obfuscation. When Claude initially resisted assisting with certain aspects of the wallet malware development, the operator reportedly switched to another AI provider and employed a custom jailbreak prompt to bypass safety controls.
Following the enrichment of leads, the threat actor employed branded email panels to generate fraudulent support cases and verification codes. This was often followed by a direct phone call that cited the same details, enabling the caller to convincingly impersonate support staff. This technique amplifies the effectiveness of traditional phone-based malware delivery by applying it specifically to cryptocurrency theft. The calling infrastructure included Asterisk and scripts for automated outbound dialing.
Victims were directed to counterfeit applications designed to mimic legitimate wallet software such as Trezor Suite, Ledger Live, or Exodus. The fake Trezor application, for example, would terminate the genuine application upon launch and present a convincing recovery-phrase screen, capturing the user's seed phrase, passphrase, and IP address. In some cases, a trojanized installer for a fake Claude code site was found to deploy a hidden Ledger Live lookalike before launching the legitimate Claude installer.
This layered deception highlights the evolving tactics of cybercriminals who are increasingly integrating AI into their operations. Users are strongly advised to treat unexpected support emails, verification codes, and follow-up calls with extreme caution. It is critical to download applications only from official sources, verify caller identities through independently obtained contact channels, and never execute commands from unfamiliar websites or advertisements. These precautions are essential to defend against sophisticated scams that leverage AI for enhanced targeting and deception.
This new analysis from Rapid7 provides a deeper dive into the technical infrastructure and development process behind Operation ASTERIX. It details the use of AI coding assistants for packaging applications, obfuscating code, and bypassing LLM safety controls, alongside the specific exploitation of the Asterisk telephony platform for vishing. The report also elaborates on the account validation techniques used against platforms like Crypto.com and Kraken, revealing the multi-stage social engineering funnel designed to steal cryptocurrency seed phrases.