Skip to content
Bleeping Computer

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes


A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.

The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials.

Researchers at threat intelligence platform SOCRadar took advantage of the platform operator’s use of bare relative paths to gather information on how the service works, its operators, and infrastructure.

image

SOCRadar found that AnonyMousKIT is connected to 506 domains and is fueling a sprawling business with 168 storefront brands acting as resellers.

Overview of the operation
Overview of the operation
Source: SOCRadar

The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.

SOCRadar notes that the calls cost the operator about $0.10 per attempt, adding that 90% of the calls were made to Brazil.

The AnonyMousKIT panel
The AnonyMousKIT panel
Source: SOCRadar

Retrieving unlocking codes

Apple’s Activation Lock feature activates automatically when the Find My tracking service is turned on, and links the iPhone device to the owner’s Apple Account.

Even if a stolen device is factory-reset, it remains linked to the original owner’s account and requires a valid authorization code during first setup before it can be used.

Because of this protection feature, many stolen iPhones are sold for parts. However, their value increases significantly if they can be unlocked, especially when sensitive data belonging to the owner can also be recovered.

AnonyMousKIT retrieves information from stolen devices, such as the owner’s contact information supplied through the Lost Mode feature, and uses it to contact the owner through email, SMS, WhatsApp, or a phone call.

The phishing messages impersonate Apple and claim that the missing device has been located, providing the correct model and IMEI details to make the email appear legitimate.

Phishing email
Phishing email
Source: SOCRadar

The email takes the victim to a fake Find My or Apple page where they are prompted to enter their device passcode, Apple Account credentials, and the two-factor authentication code.

In some cases examined by SOCRadar, an AI agent with an “Alice from Apple Support” persona informs victims that someone trying to unlock the phone brought it to an Apple store, where the device was retained.

The AI agent then asks the victim to confirm ownership by dictating the passcode, then directs them to the phishing page.

Once the threat actors obtain those codes, they can access the victim’s personal data, factory reset the device, and remove it from the Find My app before selling it.

Attack chain
Attack chain
Source: SOCRadar

A compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices, SOCRadar warns.

The researchers found that a small percentage of the emails from the platform were sent to government and corporate organizations.

SOCRadar reports that the campaigns facilitated by the AnonuMousKIT had a global footprint, but were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil.

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report



Source link