• security
  • news
  • 1 hour

Scammers Stole Seed Phrases Using Fake Crypto Wallets — Investigation

Scammers identified crypto users by their phone numbers and then impersonated exchange support staff.

0

nft.eu
  • rating +26
  • subscribers 113

Cybersecurity solutions developer Rapid7 Labs revealed details of Operation ASTERIX, a multi-stage scheme designed to steal seed phrases. The attackers first checked phone numbers to see whether they were linked to accounts on crypto platforms. They then sent victims phishing emails and called them. Eventually, they convinced users to install fake versions of popular wallets.

Scammers Researched Their Victims in Advance

Researchers found about 885,000 phone numbers on the group’s server. The German database alone contained around 316,000 mobile numbers, about 43,000 of which were linked to Crypto.com accounts.

The operators enriched the data they found with names, email addresses, geolocation information, and account details. They then sent emails posing as support staff from Crypto.com, Binance, and other services.

The messages included verification codes or support ticket numbers, which the attackers later referenced during phone calls. This made the conversation appear to be a continuation of an existing support request.

The Goal Was to Steal the Seed Phrase

During the calls, the scammers persuaded users to install an “update” or a wallet verification app, or to enter their recovery phrase.

Fake versions of Trezor Suite, Ledger Live, and Exodus mimicked the legitimate applications for macOS and Windows. Some of them replaced the original wallet window and asked users to enter a 12-, 18-, 20-, or 24-word seed phrase.

The stolen data, along with the victim’s IP address, was sent to a Telegram bot. One version of Ledger Live for Windows also replaced copied wallet addresses with addresses controlled by the attackers.

Researchers also discovered fake documentation for Claude Code. Presented as instructions for installing the tool, it actually deployed a hidden version of Ledger Live.

The Role of AI in the Scheme

Logs showed that the operators used GitHub Copilot and Claude Code to develop malicious applications, build phishing infrastructure, and process databases of phone numbers.

When one of the models refused to comply with a request involving code obfuscation, the operator tried to bypass its restrictions with a specially crafted prompt.

Rapid7 shared information about the discovered infrastructure with law enforcement and Apple’s security team. The researchers also published indicators of compromise and the prompt used to bypass the AI model’s restrictions.

This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.

0

Comments

0