You double-click Trezor Suite. A Trezor window opens and asks for your recovery phrase. Nothing looks wrong, because you started the application yourself.
What actually happened is that a hidden program had been running on your Mac since login, checking the process list every five seconds. The moment it saw the genuine wallet start it killed it, brought its own window to the front, and told macOS to activate an app named Trezor Suite. The window you are typing into is the counterfeit.
It is one artifact among many that Anna Sirokova and the Rapid7 Labs team recovered from an exposed web directory belonging to a live cryptocurrency fraud operation, published in their report on Operation ASTERIX, named after the Asterisk telephone platform running on the same server. Much of it was still in use when it was found, which let Rapid7 notify providers and authorities, including Apple's security team, while the operation ran.
885,000 numbers, filtered down
The server held approximately 885,000 phone numbers, split into files by region. The largest contained 316,002 German mobile numbers, with further lists covering Hong Kong and Bulgaria and directories referencing the UK, the US, Canadian fintech and Ledger customers across 54 countries.
Cold-calling that many people would be pointless, so the operator did not. A Go program submitted each number to a Crypto.com account-existence endpoint, hxxps://app[.]mona[.]co/api/passkeys/verify_option/, through 300 concurrent threads and rotating residential proxies, asking one question: does this number have an account? From the German dataset, 43,066 accounts were confirmed, a hit rate of approximately 13.6 percent. A separate checker targeted Kraken. Matches were then enriched into lead records carrying names, email addresses, locations, account details and in some cases payment-card context.
The email makes the call believable
Two channels then ran together. Flask phishing panels sent branded emails impersonating Crypto.com, Binance and other major financial institutions, each opening a fake support case with a verification code. Then the phone rang, the caller working from Asterisk and a 3CX business phone system, already holding the target's name, location and exchange and able to recite the case number from that email. Each channel makes the other look real. Volume stayed low: one panel logged 20 successful lead lookups and six phishing emails over roughly two weeks.
A one-pixel window that waits
Rapid7 recovered counterfeit builds of Trezor Suite, Ledger Live and Exodus for macOS and Windows, the Trezor samples being the most developed: three builds sharing one 5.87 MB payload. It opens an Electron window one pixel across, fully transparent, frameless and hidden from the taskbar, loads the phishing page into it, and waits. Closing it does not quit it. Only when the real wallet appears does it strike. The fake screen then rejects the first attempt with a generic error, so the victim assumes a typo and types the phrase again, and phrase, passphrase and public IP leave in one Telegram message.
The operator asked an AI for help
The unusual part of this haul is the development trail. Recovered prompts, shell history and project files show the operator using AI coding assistants throughout: packaging the Electron applications, obfuscating code, troubleshooting builds, modifying phishing infrastructure and preparing malware for distribution. When one model began resisting parts of that workflow, the operator switched providers and tried to bypass the next model's safety controls with a custom jailbreak prompt. That is AI woven through the build of a live phishing operation, not an operator pasting in the odd snippet. Whether it made the campaign faster is not something the artifacts settle.
Never type a seed phrase into software
The defence that survives every stage of this chain is the oldest one. A recovery phrase is entered on the hardware wallet itself and nowhere else. No legitimate application, support agent or verification step will ask for it, and any that does is the attack, however convincing the window. Treat an unexpected call about your crypto account as hostile even when the caller knows your name and case number, because those are the details this pipeline exists to collect.
The shared payload from the fake Trezor builds is SHA-256 ba9d459169a303067a4fe36c8b8582a5ea023b9c270dafe89613bab840501b19, and Rapid7 publishes the full indicator set with its report. Counterfeit macOS wallet apps are a pattern now rather than a novelty, after a fake BlueWallet build that swapped addresses mid-copy, and the telephone half of this operation runs the same trick as the helpdesk impersonation calls now ending in ransomware. The tooling changes. The moment somebody hands over the one secret that matters does not.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.