← Back
PhishingRapid7 Blog·6 days ago

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 researchers uncovered Operation ASTERIX, an active cryptocurrency fraud pipeline that combined phishing, vishing, and counterfeit wallet applications to steal recovery phrases from crypto users across 54 countries. The exposed infrastructure revealed the operator extensively leveraged AI coding assistants for development—and when one model resisted obfuscation tasks, switched providers and deployed a sophisticated multi-stage jailbreak prompt targeting the new model's safety controls. The campaign demonstrates how threat actors are integrating AI tools throughout malware development workflows rather than using them for isolated code snippets, with account enumeration, enriched lead databases, and coordinated voice-calling automation all supporting the theft operation.

Read full article at Rapid7 Blog

Related Articles

PhishingSecurityWeek·2 days ago

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers have identified iAuthFlow V2, a phishing toolkit that exploits passkey authentication by registering attacker-controlled passkeys to maintain persistent access to compromised accounts. This capability allows attackers to retain access even after victims reset their passwords or revoke active sessions, representing a significant evolution in phishing attack sophistication that targets modern authentication mechanisms.

PhishingHelp Net Security·2 days ago

A $25 template helped scammers build hundreds of phantom bank domains

Researchers at Allure Security discovered a widespread scam operation leveraging a cheap website template to create hundreds of fraudulent bank domains designed to deceive victims. The investigation began when a suspicious domain mimicking a legitimate financial services client was found hosting an unrelated bank's branding, ultimately revealing a coordinated scheme to build phantom banking sites for scamming purposes. The $25 template appears to have been a key tool enabling scammers to rapidly deploy deceptive financial websites at scale.

PhishingThe Register·2 days ago

Russian snoops add OAuth abuse to targeted phishing campaigns

Russian threat actors are incorporating OAuth abuse tactics into their targeted phishing campaigns, leveraging legitimate authentication mechanisms to compromise victims. The attacks specifically impersonate State Department communications, making them particularly credible to government and diplomatic personnel.

PhishingUnit 42·3 days ago

Identity Abuse Through Trusted Communication Channels

Attackers are exploiting trusted enterprise collaboration tools to conduct identity phishing and steal credentials from organizations. Unit 42 provides analysis of these attack techniques and outlines key defensive strategies to mitigate the threat.