Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Kimsuky APT Uses Local AI Dev Environment for Cyber Espionage
August 18, 2026
Apple Patches macOS, iOS, iPadOS: 28 Vulnerabilities Fixed
August 18, 2026
Scammer Uses Claude AI to Process 100,000+ Phone Numbers for Crypto Scam Targeting
August 18, 2026
Home/CyberSecurity News/Scammer Uses Claude AI to Process 100,000+ Phone Numbers for Crypto Scam Targeting
CyberSecurity News

Scammer Uses Claude AI to Process 100,000+ Phone Numbers for Crypto Scam Targeting

Key Takeaways A sophisticated cryptocurrency fraud operation, dubbed “Operation ASTERIX,” has been exposed, revealing a comprehensive scam toolkit. The attackers leveraged AI coding...

Sarah simpson
Sarah simpson
August 18, 2026 5 Min Read
3 0

Key Takeaways

  • A sophisticated cryptocurrency fraud operation, dubbed “Operation ASTERIX,” has been exposed, revealing a comprehensive scam toolkit.
  • The attackers leveraged AI coding tools, specifically Claude AI, to process and enrich vast lists of phone numbers, creating highly targeted victim profiles.
  • The multi-stage attack combined account validation, phishing emails, vishing calls, and malicious fake cryptocurrency wallet applications (Trezor Suite, Ledger Live, Exodus) to steal digital assets.
  • The operation demonstrated a high degree of automation and a clear strategy to focus efforts on individuals likely to own cryptocurrency.

Sophisticated Crypto Fraud Leverages AI for Targeted Attacks

A cryptocurrency fraud campaign, identified as “Operation ASTERIX,” has been uncovered, showcasing an advanced methodology that integrates artificial intelligence with traditional social engineering tactics to pinpoint and defraud digital asset holders. This multi-pronged operation utilized AI to transform raw contact data into refined target lists, enhancing the efficiency and success rate of its fraudulent activities.

Table Of Content

  • Key Takeaways
  • Sophisticated Crypto Fraud Leverages AI for Targeted Attacks
  • Inside the Scammer’s Arsenal: Operation ASTERIX Exposed
  • Claude AI at the Core of Data Enrichment
  • Phishing Calls and Malicious Wallet Applications
  • What You Should Do

The campaign’s intricate design involved a combination of automated account validation, deceptive phishing emails, persuasive vishing (voice phishing) calls, and the distribution of counterfeit cryptocurrency wallet software. This layered approach aimed to ensnare individuals with a high probability of possessing digital assets, creating a compelling illusion of legitimate support interactions.

Inside the Scammer’s Arsenal: Operation ASTERIX Exposed

Investigators gained an unprecedented look into the operational infrastructure of Operation ASTERIX, discovering an exposed web directory that laid bare the scammer’s complete workspace. This treasure trove of illicit tools included extensive raw contact lists, meticulously curated lead databases, email phishing panels, dedicated calling utilities, and a suite of fake cryptocurrency applications.

Analysts at Rapid7 said in a report that their discovery of this exposed directory provided critical insights into the campaign. The evidence strongly suggests a highly targeted and synergistic operation where each attack vector reinforced the others, lending a veneer of credibility to what were, in fact, fraudulent support requests. By pre-validating account ownership, the threat actor could bypass indiscriminate outreach, focusing their efforts on individuals likely connected to cryptocurrency exchanges or hardware wallets, significantly increasing their chances of success.

Claude AI at the Core of Data Enrichment

The compromised server contained an astonishing volume of personal data, including approximately 885,000 phone numbers from various global regions. Notable among these was a file containing 316,002 German mobile numbers, alongside lists associated with financial services in Hong Kong, Bulgaria, the UK, the US, and Canada.

The attackers employed specialized account-checking tools to verify if these phone numbers were linked to active users on cryptocurrency platforms. For instance, within one German dataset, the tooling confirmed 43,066 active accounts, representing about 13.6% of the 316,002 numbers analyzed. These validated matches were then enriched with additional personal details such as names, email addresses, geographical locations, and specific account information.

Crucially, Claude AI played a central role in streamlining this data processing workflow. Recovered session logs revealed the operator instructing Claude to clean and format a file containing over 100,000 Polish phone numbers, add country-specific prefixes, and manage scripts for account checking that utilized proxy pools. This integration of AI extended beyond isolated code generation, with the exposed materials indicating its pervasive use throughout the development and operational phases of the campaign.

The researchers also documented the actor’s reliance on AI assistants for tasks such as packaging Electron applications, modifying phishing infrastructure, debugging software builds, and attempting code obfuscation. Interestingly, when Claude exhibited resistance to assisting with certain aspects of the wallet-malware development, the operator simply transitioned to an alternative AI provider, employing a custom “jailbreak” prompt to circumvent safety protocols and obtain the desired malicious code.

Phishing Calls and Malicious Wallet Applications

With enriched lead data in hand, the attackers proceeded to orchestrate sophisticated phishing attacks. They utilized branded email panels to generate convincing fake support cases and verification codes. These emails were often followed by vishing calls, where the caller would reference the details from the preceding email, effectively impersonating legitimate support staff and building trust with the victim. This tactic mirrors common malware delivery via phone calls but specifically targets cryptocurrency assets.

The calling infrastructure included Asterisk and scripts designed for outbound dialing. While a complete reconstruction of all interactions was not possible, one panel recorded 20 successful lead lookups and six phishing emails over a two-week period, underscoring the targeted nature of the campaign over broad, indiscriminate attacks. Victims were then directed to download and install malicious applications disguised as popular cryptocurrency wallet software, including Trezor Suite, Ledger Live, or Exodus.

The fake Trezor program, for example, was designed to detect the legitimate application’s launch, terminate it, and then display a convincing replica of a recovery phrase input screen. It would prompt for a 12-, 18-, 20-, or 24-word recovery phrase, subsequently exfiltrating the entered phrase, any passphrase, and the victim’s IP address to a Telegram chat. Another deceptive tactic involved a counterfeit Claude Code website offering a trojanized installer. This installer would deploy a hidden Ledger Live lookalike before launching the genuine Claude installer, adding another layer of deception.

These elaborate deceptions echo broader trends observed in malicious Claude Code advertising, where seemingly trustworthy setup instructions trick users into executing attacker-supplied commands. The operation’s ability to combine multiple attack vectors, from AI-powered data processing to sophisticated social engineering and malware delivery, highlights the evolving threat landscape in cryptocurrency fraud.

What You Should Do

  • Be Skeptical of Unexpected Communications: Treat unsolicited emails, verification codes, or phone calls, especially those referencing cryptocurrency accounts, as potential threats. Never consider them independent proof of legitimacy.
  • Verify Support Requests Independently: If contacted by someone claiming to be from your wallet provider or exchange, do not rely on the contact information they provide. Instead, independently obtain official contact details from the provider’s official website and verify the interaction.
  • Never Share Recovery Phrases: Legitimate wallet providers and exchanges will never ask for your recovery phrase (seed phrase) to secure an account or for any support purpose. Your recovery phrase is the master key to your funds.
  • Download Applications from Official Sources Only: Always download cryptocurrency wallet applications directly from the official website of the wallet provider. Avoid links from emails, ads, or unfamiliar websites.
  • Exercise Caution with Terminal Commands: Never paste terminal commands supplied by advertisements or unfamiliar webpages, as these can execute malicious scripts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Why Threat Intelligence Feeds Fall Short for SOCs

Next Post

Apple Patches macOS, iOS, iPadOS: 28 Vulnerabilities Fixed

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Warns AI Models Can Automate Cyberattacks and Exploit Vulnerabilities
August 18, 2026
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
August 18, 2026
Shadow hVNC Tool Grants Covert Remote Access, Bypassing User Detection
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us