Description

Operation ASTERIX is a targeted cryptocurrency fraud campaign that combines account enumeration, phishing, vishing, and fraudulent wallet applications to obtain victims’ cryptocurrency recovery phrases. Instead of sending generic messages, the operators reportedly identify users associated with cryptocurrency platforms and enrich available information before contacting selected targets with personalized social-engineering lures. Researchers identified approximately 885,000 phone numbers across datasets linked to Germany, Hong Kong, Bulgaria, the United Kingdom, the United States, Canada, cryptocurrency platforms, and financial services. Automated tools and proxy infrastructure were reportedly used to determine which numbers were associated with cryptocurrency accounts, allowing attackers to prioritize potentially valuable targets. The campaign used coordinated phishing emails and follow-up telephone calls designed to impersonate cryptocurrency or financial-service representatives. Attackers could reference information from earlier emails, verification codes, account details, or supposed security incidents to make the interaction appear legitimate. Victims were then encouraged to install a security update, verify their wallet, or provide their recovery phrase. Researchers recovered fraudulent versions of Trezor Suite, Ledger Live, and Exodus targeting Windows and macOS systems. A fake Trezor application could replace the legitimate wallet interface and request recovery phrases and passphrases. The stolen information was transmitted to attacker-controlled infrastructure. The Ledger Live variant could also manipulate copied cryptocurrency addresses, potentially redirecting funds to wallets controlled by the attackers. The campaign demonstrates the effectiveness of combining targeted intelligence gathering, social engineering, and malicious software in cryptocurrency theft. Users should never share wallet recovery phrases or install applications provided during unsolicited support calls. Cryptocurrency software should be downloaded only from verified official sources, while security teams should monitor for suspicious wallet applications, unauthorized persistence, clipboard manipulation, and unusual cryptocurrency-related activity.