The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted vishing/phishing operation targeting cryptocurrency users, showing how attackers are scaling outreach and targeting.
How the attacks worked
This roundup covers three distinct social engineering patterns that share a common thread: manipulating people rather than exploiting software alone. In the first, attackers posed as a bank fraud team calling to warn victims of suspicious account activity. Victims were pressured to install an app that was actually the SpyNote remote access Trojan, giving attackers control of the phone and enabling remote NFC transactions, unauthorized loans, and contactless payment fraud.
In the second pattern, fake software download pages used a ClickFix-style technique, instructing users to run commands in order to complete an installation or fix an error. Instead, these commands installed malware that stole credentials and browser data, with hijacked Chromium sessions potentially giving attackers access to corporate email, cloud services, and administrative accounts.
The third pattern, tied to what the article calls Operation ASTERIX, used AI tooling (Claude Code) to screen more than 100,000 phone numbers before targeting cryptocurrency users with phishing, voice phishing, and fake wallet software.
Why these lures succeeded
Each scenario relied on urgency and authority. A call claiming to be from a bank's fraud team creates immediate pressure to act, especially when it involves potential loss of money. Fake download pages exploit the routine trust users place in software installation prompts. Crypto-themed outreach plays on fear of losing funds. In all three cases, victims were pushed toward one action: install something or run a command, at the direction of someone they did not independently verify.
What to watch for
- Unsolicited calls claiming to be from a bank's fraud or security team
- Requests to install an app or software during a call, rather than through official channels
- Download pages or pop-ups that ask you to run terminal or command-line instructions to "fix" an install
- Unsolicited outreach about cryptocurrency wallet security issues, especially paired with urgency about potential loss
Building resistance
Organizations can reduce exposure to these tactics with a few practical steps:
- Train employees to hang up and call back using a known, independently verified number rather than one provided by a caller
- Establish a clear policy against installing apps or software at the direction of an unsolicited caller
- Educate staff that instructions to run commands to "fix" a download are a common malware delivery method
- Brief finance and executive teams specifically on crypto-themed phishing and vishing, since these roles are frequent targets for fake wallet software schemes
These incidents illustrate that sophistication in modern social engineering often comes not from complex malware alone, but from convincing pretexts that get a person to take one small, seemingly reasonable action.
Key findings
- Attackers used a fake bank call plus Android malware (SpyNote) to take control of phones and perform remote NFC fraud.
- Fake software downloads used a “ClickFix-style technique” to persuade Mac users to execute malicious commands, leading to credential theft and session hijacking.
- Operation ASTERIX used AI tooling (Claude Code) to screen large phone-number sets and then targeted cryptocurrency users via phishing, vishing, and fake wallet software.
- The article notes that stolen/old identity datasets can still be used for phishing and impersonation, increasing risk after data exposure events.
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Executives, IT helpdesk/service desk.
- Affected industries: Finance and banking, Cryptocurrency and financial services, Government, Telecommunications, Software and IT, Energy.
- Attack channels: vishing, website, email.
- Impersonated: Bank fraud/support representative, Software download/support site, Cryptocurrency wallet support.
Red flags to watch for
- Unsolicited call claiming urgent fraud
- Caller directs you to install an app
- Pressure to act immediately rather than verify independently
- A site instructs you to run commands to ‘fix’ a download/install
- Software obtained outside approved channels
- Unexpected prompts to bypass normal security controls
- Unsolicited support outreach about crypto ‘security issues’
- Requests to install software from a link provided by the caller/sender
- Sense of urgency tied to potential loss of funds
Frequently asked questions
What is the fake bank call attack described in this breakdown?
Attackers called victims posing as a bank fraud team, claimed suspicious activity was occurring, and convinced them to install an app that led to the SpyNote remote access Trojan, enabling remote NFC fraud and unauthorized transactions.
What is a ClickFix-style attack?
It is a technique where a fake software download page instructs users to run commands to complete or fix an installation, which instead installs malware that steals credentials and browser data.
How did AI tooling factor into the crypto-targeted attacks?
Operation ASTERIX reportedly used Claude Code to screen more than 100,000 phone numbers, then targeted cryptocurrency users through phishing, voice phishing, and fake wallet software.
How can employees protect themselves from these tactics?
Independently verify calls claiming to be from financial institutions using a known number, avoid installing apps at a caller's direction, and be wary of instructions to run commands to fix a download.
Read the video transcript
Imagine this: your phone rings, “Hi, this is the bank’s fraud team, we see suspicious activity on your account.” They sound legit, then tell you to install a “security app.” In real attacks, that app was SpyNote, letting them take over phones and run NFC payments and even loans remotely. Same play on Macs: a fake download page says, “Your download is ready, if installation fails, run these Terminal commands to complete the fix.” That ClickFix-style trick has been used to steal browser logins and hijack Chromium sessions into corporate email and cloud. Here’s the move: if anyone, on a call, in a pop-up, or a download page, tells you to install an app or run commands, stop and verify through a known-good channel you choose, not the one they give you.