AnonyMousKIT PhaaS Uses AI Voice Agents to Phish iPhone Passcodes

Reviewed byNidhi Govil

3 Sources

Share

A phishing-as-a-service platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices. Active since early 2024, it operates across 506 domains with 168 storefront brands as resellers, using AI-powered voice calls that impersonate Apple Support to trick victims into revealing device passcodes and Apple ID credentials.

AnonyMousKIT Emerges as Sophisticated Phishing-as-a-Service Platform

A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT has been operating since early 2024, automating the retrieval of codes used to bypass Apple's Activation Lock and unlock stolen devices

1

. Researchers at threat intelligence platform SOCRadar discovered the illegal service while investigating bare relative paths that exposed operational details about the platform's infrastructure and operators

1

. The platform represents a structured ecosystem that sells stolen iPhones, harvests Apple ID credentials, accesses iCloud backups, and retrieves Keychain credentials

1

. SOCRadar found that AnonyMousKIT is connected to 506 domains and fuels a sprawling business with 168 storefront brands acting as resellers

1

. The platform operates like a small software business with a criminal customer base, featuring credit bundles, published pricing, tiered subscriptions, customer support, status tracking, and infrastructure replacement protocols

2

.

AI Voice Agents Drive AI-Driven Social Engineering Attacks

The platform's primary innovation lies in its use of AI voice agents to conduct fake Apple Support AI calls targeting owners of stolen devices

2

. SOCRadar recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by AI voice agents operating under five personas

1

. The calls cost the operator approximately $0.10 per attempt, making this cybercriminal tactic both scalable and cost-effective

1

. All five personas carry the same translated identity, "Alice from Apple Support," across English, Spanish, and Portuguese

2

. During these AI-powered voice calls, the agent informs victims that someone trying to unlock the phone brought it to an Apple store where the device was retained, then asks the victim to confirm ownership by dictating the passcode

1

. The platform is credit-metered and drives lures across five channels from a single victim record: email at 1.50 credits, SMS priced per sender ID, WhatsApp, a recorded voice call at 1 credit, and an AI voice agent at 2 credits

2

.

Source: Hacker News

Source: Hacker News

How Attackers Exploit Lost Mode to Phish iPhone Passcodes

AnonyMousKIT retrieves information from stolen devices, such as the owner's contact information supplied through the Lost Mode feature, and uses it to contact the owner through email, SMS, WhatsApp, or phone calls

1

. The phishing messages impersonate Apple and claim that the missing device has been located, providing the correct model and IMEI details to make the communication appear legitimate

1

. The email takes the victim to fake Find My pages or Apple pages where they are prompted to enter their device passcode, Apple ID credentials, and the two-factor authentication code

1

. Lures cite the handset's internal Apple model identifier and its live Find My status, both pulled from the stolen device itself

2

. Victims who follow the link reach an Apple-branded capture page that renders an animated map of the handset's reported location

2

. Once threat actors obtain those codes, they can access the victim's personal data, factory reset the device, and remove it from the Find My app before selling it

1

.

Source: BleepingComputer

Source: BleepingComputer

Global Reach with Concentrated Focus on Brazil and South Africa

The campaigns facilitated by AnonyMousKIT had a global footprint but were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil

1

. Notably, 90% of the 200 documented calls were made to Brazil, with 179 of 200 going to numbers in that country

1

2

. South Africa accounts for 1,735 of the 6,092 family-wide sends across all tracked installations

2

. The researchers found that a small percentage of emails from the platform were sent to government and corporate organizations

1

. Just under 30 attempts were made toward South African government domains, and three to a local university

3

. The top two subject lines used in email lures were "Your device has been found" with 308 of 691 sends, and "Alert" with 157 sends

2

.

Cybersecurity Threat Extends Beyond Device Theft

A compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices, SOCRadar warns

1

. This cybersecurity threat matters because Apple's Activation Lock feature, which activates automatically when the Find My tracking service is turned on, links the iPhone device to the owner's Apple Account

1

. Even if a stolen device is factory-reset, it remains linked to the original owner's account and requires a valid authorization code during first setup before it can be used

1

. Because of this protection feature, many stolen iPhones are sold for parts, but their value increases significantly if they can be unlocked for resale of unlocked devices, especially when sensitive data belonging to the owner can also be recovered

1

. The platform's ability to unlock stolen devices at scale transforms what would otherwise be low-value parts into high-value functioning smartphones. A scan of 506 kit-family domains identified 30 distinct installations reachable on 42 domains, with 188 of the 506 live

2

. The logs reached SOCRadar via two bare relative file paths in the shared codebase that resolve to the web root and allow unauthenticated HTTP access, meaning every deployment of that codebase inherits the flaw

2

. At the time the report was published, the campaign was still ongoing, and researchers continue tracking this evolving vishing operation

3

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved