Counterfeit wallet apps are not a new threat, but Operation ASTERIX shows how much more precise these schemes have become. Rapid7 uncovered a campaign built around roughly 885,000 phone numbers, crypto account-validation tools, phishing emails, vishing calls, and fake Trezor, Ledger, and Exodus apps designed to capture recovery phrases, according to the original report.
The most striking detail is not the volume of phone numbers. It is the validation layer. In one German dataset, operators identified 43,066 CryptoCom accounts from 316,002 phone numbers. That is a hit rate high enough to justify the infrastructure. After confirming which numbers were tied to exchange accounts, the group enriched those targets with personal details, making support impersonation calls much harder to detect. A public list of phone numbers is a nuisance; a list that has been cross-checked against exchange account data is an operational asset.
AI tools compressed the production cycle
Rapid7 found signs that the operators used GitHub Copilot and Claude Code across multiple stages of the campaign. Those tools were applied to process target data, develop and debug malicious software, and build phishing infrastructure. That matters because it shrinks the distance between target discovery and an active fake wallet app or phone scam. Tasks that once required a dedicated developer can now be handled by smaller crews using AI coding assistants.
blockchainreporter.net