Cyber threats of the week: phishing targeting 885,000 investors, spy trojan, and an attack on the Rust ecosystem

Analyzing the latest cybersecurity data, I have identified several alarming trends that require close attention from every participant in the crypto market. From large-scale phishing operations to attacks on software supply chains, threats are becoming increasingly sophisticated and widespread.
Operation "Asterix": Nearly a Million Investors Under Attack
I have managed to uncover details of a large-scale phishing campaign in which attackers gained access to a database of 885,000 phone numbers of crypto investors worldwide. The attack scheme included phone calls impersonating support services and fake emails mimicking communications from major platforms like Crypto.com. The ultimate goal is to trick the victim into visiting a phishing site or installing a fake app visually indistinguishable from legitimate wallets such as Ledger, Trezor, or Exodus, in order to steal seed phrases.
What is particularly concerning is the automation of the process: hackers used scripts to mass-verify numbers against databases of major exchanges, including Binance and Kraken. The effectiveness proved frighteningly high: in a sample from Germany, matches reached 13.6%, allowing them to identify over 43,000 actual cryptocurrency holders. Notably, AI tools were actively used to generate phishing content, making the attacks even more personalized and dangerous.
Fake AML Services: A New Trap for Wallets
A network of fake AML checkers imitating popular wallet verification services has been discovered online. Scammers copy the design of legitimate platforms such as AMLBot and request permission to connect a wallet for "scanning." The user sees a realistic analysis process with loading indicators and receives a false result of "Clean, low risk." However, under the guise of paying a fee or during the connection process, the victim is prompted to sign a transaction that grants the malicious smart contract full access to their funds.
Attack on the Rust Ecosystem: Infection of arrayref
A critical vulnerability has been identified in the popular Rust library arrayref, which boasts over 245 million downloads. Attackers compromised the developer's account and injected malicious code that executed at the moment of project compilation. The malware, disguised as the dependency proc-macro1, collected system information and stole password databases from browsers. There are serious grounds to believe that the North Korean group Sapphire Sleet, previously observed in similar operations, is behind this attack.
Massive Dahua Camera Hack and the Manic Trojan
Special attention deserves the CameraSwarm operation, during which 14,530 Dahua surveillance cameras were hacked in 35 days, primarily in Russia and Ukraine. The attackers used three attack vectors, including exploitation of outdated vulnerabilities and hidden accounts. In parallel, the new Android trojan Manic targets 169 applications, including banking and cryptocurrency ones. Its uniqueness lies in its ability to transmit stolen data through neighboring infected devices via Wi-Fi Direct or Bluetooth, creating a mesh network to bypass offline restrictions.
My analysis: This week demonstrates a consolidation of cybercriminal efforts around the crypto industry. The combination of phishing with AI, supply chain attacks, and spy trojans points to the professionalization of hacker groups. Investors should exercise maximum caution: do not connect wallets to unverified services, ignore suspicious calls and emails, and regularly update software and watch for hidden accounts on their devices.