Security1 distinct publisher3 min readUpdated
Rapid7 recovered an exposed server running an active vishing operation. Alongside the phishing kit sat the operator's development trail, including a custom jailbreak written after one model pushed back.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Rapid7 researchers found an exposed web directory on infrastructure supporting a cryptocurrency fraud operation and pulled down its working files: raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms and Telegram exfiltration code [1][2]. The part that matters beyond the inventory is the development trail left in the same directory, which turns attacker use of AI coding assistants from an inference about writing style into a set of artifacts.
According to Rapid7, recovered prompts, shell history and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure and prepare malware for distribution [3]. That is not snippet generation at the margins; it is the assistant sitting in the build loop. And the loop had friction: when one model began resisting parts of the workflow, the operator switched providers and attempted to bypass the next model's safety controls with a custom jailbreak prompt [4]. Rapid7's account does not name the models or providers involved [4]. The refusal is worth noting as much as the workaround, because it puts a cost on the operator and leaves a record.
The campaign itself is unglamorous and well-organised. Rapid7 tracks it as Operation ASTERIX, after the Asterisk open-source telephony platform recovered on the server, which the operator used to automate vishing and coordinate calls with phishing emails and counterfeit wallet applications [5]. The chain ran from bulk account enumeration against cryptocurrency platforms, through phishing emails that opened fake support cases, into vishing calls that referenced details from those emails, and on to counterfeit Ledger, Trezor and Exodus applications built to steal seed phrases and exfiltrate them over Telegram [6].
Scale first. The server held roughly 885,000 phone numbers split into files by region and source, the largest being 316,002 German mobile numbers, with further lists covering Hong Kong and Bulgaria and directories referencing UK, US, Canadian fintech and Ledger-related lists across 54 countries [10][11]. The German file alone is about 36 percent of the total [16]. Those numbers were then run through validation tooling to find likely crypto holders [9]. In one directory, cdc/, Rapid7 found a Go-based tool that submitted numbers to a Crypto.com account-existence endpoint using 300 concurrent threads, retry logic and rotating residential proxies [12]. Files named extract_sg_numbers.py and sg_leads_server.py point to additional lead-management and direct-outreach capability [13]. Call logs were not recovered, so individual interactions cannot be reconstructed [14].
Each stage either narrowed the pool or built trust before the victim was asked to install software or hand over a recovery phrase, which Rapid7 notes gives defenders several points to interrupt the chain before seed phrases move [15]. Much of the infrastructure was still live or under development when it was exposed, so Rapid7 Labs was able to notify providers and authorities mid-campaign [7]. Disclosure included Apple's security team [8].
Watch whether refusal-then-switch becomes a documented pattern in other seizures, and whether the artifact type worth collecting in an incident is now the prompt log rather than the binary.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation.
The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code.
Recovered prompts, shell history and project files show AI coding assistants being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure and prepare malware for distribution.
When one model began resisting parts of the workflow, the operator switched providers and attempted to bypass the next model's safety controls with a custom jailbreak prompt. The source does not name the models or providers.
Rapid7 tracks the activity as Operation ASTERIX, named after the Asterisk open-source telephony platform recovered on the server; the operator used Asterisk to automate the campaign's vishing infrastructure, coordinating phone calls with phishing emails and counterfeit wallet applications.
The recovered material shows bulk account enumeration against cryptocurrency platforms, phishing emails that created fake support cases, vishing calls that referenced details from those emails, counterfeit Ledger, Trezor and Exodus applications, and seed-phrase theft with Telegram exfiltration.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor primary artifacts, no outside corroboration
The account is unusually concrete for a single-source story: recovered file names, a reproduced Go function and the abused endpoint, dataset counts, and a confirmed-account hit rate. That is first-hand artifact evidence rather than inference. It is capped by being one security vendor's self-reported recovery with no independent verification in this cluster, by the absence of call logs, and by the AI portion resting on paraphrased prompts and shell history with no model or provider named.
Live campaign at scale, but one documented operator
Real-world deployment is demonstrated, not projected: ~885,000 harvested numbers, 43,066 validated exchange accounts, working phishing panels, Asterisk vishing automation and counterfeit wallet apps, with infrastructure still active at exposure. Adoption is held below high because the evidence covers a single operator's pipeline; nothing here establishes how widespread assistant-driven fraud tooling is across other actors.
Slightly ahead of what the artifacts can pin down
The core narrative is well matched to the artifacts: the operational fraud chain and the presence of assistants in the build are directly evidenced. The mild overstatement sits in the AI framing, where the headline finding - a model refused, so the operator switched providers and jailbroken the next one - cannot be attributed to any named model or provider, and where no victim or loss figures anchor the campaign's actual impact. The vendor also foregrounds its own timely notification, which inflates perceived significance relative to what the report proves about outcomes.
Vendor publishing its own named operation and disclosure
The sole source is a commercial security vendor reporting research it conducted, branding the activity with its own tracking name and highlighting collaboration with Apple's security team and authorities. That is a strong reputational and marketing incentive shaping selection and emphasis. It is partly offset by the falsifiable specificity offered - endpoints, file names, code, counts - and by the report volunteering its own evidentiary gaps.
Solid on mechanics, thin on the AI attribution
Confidence is moderate-to-good for the fraud pipeline mechanics, which are supported by artifact-level detail and internal logs, and lower for the AI-assistant angle that drives the story's framing. One publisher, no corroboration, no named vendors and no victim data keep this out of high-confidence territory.
invest
Copilot built the fake Ledger app. A human still only made 20 lookups in two weeks.1 distinct publisher
build
A 12MB Go binary bets agent cost control is cache stickiness, not a dashboard1 distinct publisher
build
The bot returned 4.33%. Doing nothing returned 127.77%. The useful part is why.1 distinct publisher
build
Claude Desktop already ships the schema for handing meeting follow-ups to agents1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026