Fake Trezor Wallet administration
At a glance
| Actor | Unnamed crypto fraud operator (single host) |
| Activity type | Phishing, vishing, fake wallet malware, AI-assisted development |
| Targets | Cryptocurrency holders across 54 countries |
| Scale | About 885,000 phone numbers; thousands of validated accounts (claimed) |
| Status | Reported to authorities and Apple; no arrests announced |
| Source | Rapid7 Labs |
TL;DR
Rapid7 Labs found an exposed server behind a crypto fraud operation it calls Operation ASTERIX. The operator paired phishing emails with live scam calls to steal wallet recovery phrases. Notably, the campaign used AI coding assistants to build and obfuscate its malware.
What happened
Rapid7 researchers spotted an open web directory on port 8080. That mistake exposed the operator’s full toolkit. Inside sat phone datasets, phishing panels, dialer scripts, and fake wallet apps.
The timing was rare. Much of the crypto fraud infrastructure was still active or under construction. As a result, Rapid7 could alert providers and authorities while the operation ran. As the report notes, the operator relied on AI throughout development, “rather than simply being used to generate isolated snippets of code.”
A two-channel trap
The scam combined email and phone in one play. First, a phishing email posed as support from firms like Binance or Crypto.com. It carried a case ID and a six-digit code. Then a caller phoned the victim and repeated those same details.
That match built trust fast. The email made the call seem expected. Meanwhile, the caller’s knowledge of the code made the email look real. Both channels then pushed the victim toward a fake wallet app.
How the fraud narrowed its targets
The operator did not cold-call random people. Instead, the campaign filtered a raw list of roughly 885,000 numbers. The largest single file held 316,002 German mobile numbers.
Account-checking tools then confirmed which numbers owned crypto accounts. Recovered logs claim a 13.6% hit rate against the German set. Enriched records added names, emails, and locations. Consequently, each call could reference real personal details.
Fake wallets that swapped the real app
The team recovered counterfeit builds of Trezor Suite, Ledger Live, and Exodus. The Trezor fake ran as a hidden Electron process. Every five seconds, it scanned for the genuine wallet. When the user opened the real app, the malware killed it and showed its own window instead.
The fake screen asked for the recovery phrase. It then sent the seed phrase to a Telegram bot. Each stolen message started with a fixed label. The Ledger fake went further, swapping copied crypto addresses through a clipboard hijacker.
Who is behind it
Rapid7 does not name a person or group. The report treats this as a single operator running a targeted crypto fraud effort. One panel logged just 20 lead lookups and six emails over two weeks. That low volume points to hands-on calling, not mass spam.
You can read the full technical breakdown in Rapid7 Labs’ Operation ASTERIX report. The firm published its indicators of compromise on GitHub.
AI became part of the toolchain
The recovered logs show AI woven into the build process. The operator used AI to clean lead lists, format numbers, and write validation scripts. When one model refused to help obfuscate malware, the operator switched providers. Then they submitted a long jailbreak prompt to bypass the next model’s safety controls.
That prompt tried to rewrite the model’s identity and reasoning. However, it referenced XML tags meant for a different vendor’s system. The operator reused it without adapting it, so those tags carried no authority there. Rapid7 could not confirm whether the second model complied.
Impact and scale
The figures come from the operator’s own files, so treat them as claims. One Binance lead panel showed 5,576 validated targets queued for attack. The datasets spanned 54 countries and several exchanges. Losses to victims remain unconfirmed.
How to stay protected
Real wallet vendors never ask for your recovery phrase. Treat any such request as fraud. Be wary when an email and a call share the same case code, since that pairing is the core trick here.
Download wallet software only from official sites. Verify install commands before pasting them into a terminal. Finally, unexpected support contact about your crypto account should raise alarm, not trust.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.