Another week brought a series of serious cybersecurity incidents, prompting reflection on the reliability of even seemingly protected systems. From massive phishing attacks targeting crypto investors to the compromise of critical elements in the software supply chain, attackers continue to refine their methods, exploiting the most vulnerable points in the ecosystem.

Operation "Asterix": Nearly a Million Investors at Risk

I have discovered an extremely alarming trend: hackers gained access to a database containing approximately 885,000 phone numbers of crypto investors worldwide. This campaign, dubbed "Operation Asterix," is a combined attack using phone calls and phishing emails. Victims received calls supposedly from support services or fake messages sent on behalf of well-known platforms such as Crypto.com.

The main goal is to trick the user into visiting a fake website or installing a counterfeit app that mimics the interface of popular wallets like Ledger, Trezor, or Exodus, in order to extract the seed phrase. To increase effectiveness, attackers used automated scripts to cross-check numbers against the databases of major exchanges. The results are impressive: in a sample from Germany alone, the match rate was 13.6%, allowing them to identify 43,066 real investors. Over 5,500 confirmed Binance accounts were queued for attack. Notably, AI tools were actively used to generate phishing content, making the attacks even more convincing. The largest fragment of stolen data contains numbers of German citizens (316,002), with residents of the US, UK, Hong Kong, and Bulgaria also appearing on the lists.

Fake AML Services: A New Trap for Wallet Owners

Attackers are creating fake AML services to check crypto wallets for "cleanliness," copying the design of legitimate platforms like AMLBot. The scheme is simple: the site requests permission to connect the wallet for "scanning," then simulates the analysis process, showing fake loading indicators. Ultimately, the victim receives a reassuring result — "Clean, low risk." However, under the guise of paying a fee, the user is prompted to sign a transaction that grants the malicious smart contract the right to withdraw all funds.

Critical Vulnerability in the Rust Ecosystem

A serious incident occurred in the development world: hackers compromised the account of the programmer behind the popular Rust package arrayref, injecting malicious code that executed during project compilation. Within a 23-minute window, two other libraries by the author were also "poisoned." Given that arrayref has over 245 million downloads and is actively used in blockchain tools for Ethereum and Solana, the scale of potential damage is enormous. The malicious dependency proc-macro1 was disguised as the popular component proc-macro2. The code collected system information and stole password databases from browsers. Experts note similarities in the network infrastructure to attacks on Mastra and Axios, which are linked to the North Korean group Sapphire Sleet.

Dahua Camera Hacks and the Manic Trojan

Over 35 days, hackers breached 14,530 Dahua surveillance cameras, focusing on provider networks in Russia and Ukraine. They used three attack vectors, including password guessing and exploitation of outdated vulnerabilities. Owners are advised to check devices for hidden accounts and update firmware. Additionally, a new Android trojan named Manic was discovered, targeting 169 applications in the banking and cryptocurrency sectors. Its distinctive feature is a backup data transmission mechanism through neighboring infected devices via Wi-Fi Direct or Bluetooth, allowing it to operate even in offline mode.

My analysis: This week demonstrates that cybercriminals have shifted from targeted attacks to large-scale, complex operations, actively leveraging AI and automation. The compromise of the software supply chain is particularly concerning, threatening thousands of developers and their projects. Investors and developers need to exercise heightened vigilance, avoid trusting unverified links and services, and regularly update software while using hardware wallets with caution.