A new phishing-as-a-service platform called AnonyMousKIT has been uncovered that leverages voice AI agents to automate the theft of iPhone passcodes. The platform targets stolen Apple devices, specifically attempting to retrieve unlock codes and disable Apple's Activation Lock feature. By using AI-driven voice agents, the service automates the social engineering process traditionally performed by human attackers. This represents an evolution in PhaaS offerings, combining voice phishing (vishing) with artificial intelligence to scale attacks. The platform lowers the barrier for criminals to exploit stolen iPhones, potentially enabling large-scale operations against Apple device owners. The Activation Lock bypass capability makes this especially concerning as it allows stolen devices to be fully unlocked and resold or reused.
AnonyMousKIT is a Phishing-as-a-Service (PhaaS) platform active since early 2024 that automates the retrieval of codes to unlock stolen Apple devices and bypass Apple Activation Lock. The platform is connected to 506 domains and operates through 168 storefront reseller brands. It harvests device information (owner contact details, IMEI, model) from stolen iPhones via Apple's Lost Mode feature, then contacts victims via email, SMS, WhatsApp, or phone calls impersonating Apple. Phishing emails include accurate device model and IMEI details to appear legitimate and direct victims to fake Apple/Find My pages where they are prompted to enter their device passcode, Apple Account credentials, and 2FA codes. The platform employs a voice AI agent operating under five personas (e.g., 'Alice from Apple Support') that calls victims, claims the stolen device was brought to an Apple store, and asks the victim to dictate their passcode before directing them to the phishing page. Researchers recorded 200 calls made between August 2025 and May 2026, using 55 distinct interaction transcripts. Each call costs the operator approximately $0.10. 90% of calls were made to Brazil. The platform's operators were partially exposed due to use of bare relative paths in their infrastructure. Compromised credentials enable access to iCloud backups, Keychain passwords, work email, and other corporate data. A small percentage of targeted emails were sent to government and corporate organizations. Global campaign footprint concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil.
1. Do not provide your iPhone passcode, Apple ID credentials, or 2FA codes to anyone via phone, SMS, email, or any website reached through unsolicited links - Apple will never ask for these. 2. If you receive a call or message claiming your lost device has been found, verify directly through official Apple channels (apple.com or the official Apple Support app) rather than clicking links in messages. 3. Be suspicious of AI-sounding phone calls asking you to dictate your device passcode, even if the caller appears knowledgeable about your device model and IMEI. 4. Enable strong Apple ID security including hardware security keys where possible, as standard 2FA codes can be phished. 5. Organizations should monitor for compromised Apple IDs associated with corporate-issued or BYOD Apple devices, as iCloud backups and Keychain may expose corporate credentials. 6. Security teams should monitor for phishing domains impersonating Apple Find My and Apple Support pages. 7. Educate users about voice AI phishing (vishing) attacks that convincingly impersonate legitimate support agents. 8. If your device is stolen, consider remotely erasing it via Find My rather than waiting, to prevent data exposure even if credentials are phished.
506 domains associated with AnonyMousKIT infrastructure, 168 storefront reseller brands operated by AnonyMousKIT, Voice AI agent personas including 'Alice from Apple Support', Fake Apple/Find My phishing pages harvesting passcodes, Apple ID credentials, and 2FA codes, Phishing communications via email, SMS, WhatsApp, and phone calls impersonating Apple, Phishing messages containing victim's correct iPhone model and IMEI details