THREAT OPS › Threat News › Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
<h2><span style="font-size: undefined;">Operation ASTERIX overview</span></h2><p><span style="font-size: undefined;">Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet application
MITRE ATT&CK techniques
- Acquire InfrastructureT1583
- IP AddressesT1590.005
- JavaScriptT1059.007
- Create or Modify System ProcessT1543
- Match Legitimate Resource Name or LocationT1036.005
- Service StopT1489
- MalwareT1587.001
- Hide ArtifactsT1564
- Malicious FileT1204.002
- Spearphishing LinkT1566.002
- Spearphishing LinkT1598.003
- Clipboard DataT1115
- Gatekeeper BypassT1553.001
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- AppleScriptT1059.002
- Virtual Private ServerT1584.003
- Upload MalwareT1608.001
- Exfiltration Over Web ServiceT1567
- Social EngineeringT1684
- MasqueradingT1036
- Process InjectionT1055
- Gather Victim Identity InformationT1589
- Browser Session HijackingT1185
- Electron ApplicationsT1218.015
- Web Portal CaptureT1056.003
- Email AddressesT1589.002
- Command and Scripting InterpreterT1059
- Virtual Private ServerT1583.003
- Shell HistoryT1552.003
- Web ServiceT1102
- Stage CapabilitiesT1608
- Financial TheftT1657
- Process DiscoveryT1057
- PowerShellT1059.001
- Registry Run Keys / Startup FolderT1547.001
- ToolT1588.002
- Unix ShellT1059.004
- Modify System ImageT1601
- Non-Standard PortT1571
- Obfuscated Files or InformationT1027
- Subvert Trust ControlsT1553
- Input CaptureT1056
- CredentialsT1589.001
- Hidden WindowT1564.003
- Obtain CapabilitiesT1588
- Launch AgentT1543.001
- Drive-by CompromiseT1189
- Web ProtocolsT1071.001
- Develop CapabilitiesT1587
- Dead Drop ResolverT1102.001
- Acquire InfrastructureAML.T0008
- Obtain CapabilitiesAML.T0016
- Develop CapabilitiesAML.T0017
- Craft Adversarial DataAML.T0043
- Command and Scripting InterpreterAML.T0050
- LLM Prompt InjectionAML.T0051
- LLM JailbreakAML.T0054
- LLM Prompt CraftingAML.T0065
- System PromptAML.T0069.002
- MasqueradingAML.T0074
- Drive-by CompromiseAML.T0078
- Stage CapabilitiesAML.T0079
- Gather Victim Identity InformationAML.T0087
- Process DiscoveryAML.T0089
Indicators of compromise
- ba9d459169a303067a4fe36c8b8582a5ea023b9c270dafe89613bab840501b19sha256
- 918fa540126b7db6424652d84a5ce7e968947136db3d6e3e0cab30ea309e25a2sha256
- 961a398a5c71e837626b5fce68e44b14a5d220e3bd74a3d0ecd61a2762c38176sha256
- 7073b2a3a34525c5969921dd17ef1fa5607af92be78b3fc6129cdea73216691asha256
- 0f2c7194f1f577e73460db9ec2e75fc0c7f845588cbd4246333b7a4fbec90d9fsha256
- 4bee9affff9fa718a2c94f02ebe6a75143d4d461d291c2df9b769920fc927bf8sha256
- https://app.mona.co/api/passkeys/verify_option/url
- https://app.mona.courl
- https://app.mona.co/url
- http://136.0.213.184:1337/api/kraken-numiourl
- https://atechservicecentre.co.uk/url
- http://redacted:8080/install.shurl
- 120.0.0.0ipv4
- 82.25.35.77ipv4
- 82.25.35.200ipv4
- 31.57.35.88ipv4
- 136.0.213.184ipv4
- images.contentstack.iodomain
- crypto.comdomain
- api.ipify.orgdomain
- api.telegram.orgdomain
- macos-claude.comdomain
- 36mcrypto.comdomain
- ledgerhelp.comdomain
- ledger.comdomain
- code.kimi.comdomain
- smtpdm-ap-southeast-1.aliyun.comdomain
- ses-noreply.comdomain
- xcjnrucne9xfvmci.comdomain