Operation ASTERIX: Fake support call leads to counterfeit wallet app theft

Security firm Rapid7 reports Operation ASTERIX, a vishing-led scam chain targeting crypto users after support calls. Attackers exposed an open Asterisk phone-server on port 8080 that hosted phishing interfaces, dialling scripts, and cloned wallet installers. The server contained a large Germany phone-number dataset: 316,002 numbers. After an account check, Rapid7 states a 13.6% hit rate, yielding 43,066 confirmed trading-venue accounts. The attackers then used voice calls (vishing) to build trust with personal details (name, email, location, account context). Victims were pushed to install counterfeit versions of Trezor Suite, Ledger Live, and Exodus for Windows/macOS (including Trezor builds for Intel and Arm). During entry, the fake app triggers an invented validation error and asks for the recovery (seed) phrase again—designed as a “quality control” to improve the chance of correct phrase capture. Rapid7 says the recovery phrase and optional passphrase were exfiltrated immediately via a Telegram bot. The campaign may not have been mass-scale: logs showed only 20 successful data queries and six phishing emails over ~two weeks. Rapid7 also found a trojanized installer that bundled the counterfeit Ledger Live app. Trader takeaway: treat any unsolicited support call as potentially part of Operation ASTERIX, hang up, and use official bookmarks only. Never enter a seed phrase in normal software flows.
Neutral
This is a security and fraud report, not a protocol change or market-structure event. Operation ASTERIX targets individual users via vishing and counterfeit wallet apps, so it is unlikely to directly move Bitcoin/altcoin spot prices or liquidity in the short term. The most likely market effect is indirect: heightened scam awareness can temporarily reduce speculative behavior among retail, while exchanges/wallet providers may see more support and incident-report traffic. In the short run, the key risk is operational: if users’ wallets are compromised, it can create sporadic sell pressure on the specific affected assets. However, Rapid7’s logged scale (20 successful queries and six emails over ~two weeks) suggests the campaign, while sophisticated, may be limited in reach versus large historical phishing waves. In the long run, repeated high-profile wallet-impersonation incidents typically lead to tighter user behavior (bookmark-only downloads, hanging up on unsolicited calls) and potential tooling improvements (better app integrity checks, warning banners). That tends to be net-neutral for the market price but can reinforce a cautious retail posture similar to past seed-phrase phishing outbreaks, where recovery efforts and user education matter more than macro pricing dynamics.