
Researchers have discovered a new phishing-as-a-service (PhaaS) platform called AnonyMousKIT. This leverages AI-powered phishing to steal iPhone passcode to help threat actors unlock stolen devices and bypass Apple’s Activation Lock. The service has been active since early 2024. It is part of a wider operation involving stolen iPhones, Apple ID theft, iCloud backups, and Keychain data. Researchers at threat intelligence platform SOCRadar uncovered details about how the service works, its operators, and its infrastructure.
AnonyMousKIT uses AI voice agents to phish victims for iPhone passcodes
SOCRadar says that AnonyMousKIT links to 506 domains and operates a large network of 168 storefront brands that act as resellers. The researchers found records of 200 calls to victims between August 2025 and May 2026. The calls used 55 different conversation scripts handled by a voice AI agent posing as five different personas.
SOCRadar notes that the calls cost the operator about $0.10 per attempt, with 90% of the calls made to Brazil. Apple’s Activation Lock turns on automatically when users enable Find My and link an iPhone to its owner’s Apple Account. Even after a factory reset, Activation Lock keeps the stolen iPhone linked to its original owner, and the device needs the owner’s authorization code for setup. This means bad actors sell stolen iPhones for parts. But their value can increase if they manage to unlock them and access the owner’s data.
AnonyMousKIT retrieves information from stolen devices, including contact details provided through Lost Mode, to reach owners by email, SMS, WhatsApp, or phone calls. The phishing messages pretend to be from Apple and claim to have found the lost iPhone. They also include things like what model it is and the IMEI number to make the emails look legitimate.
Posing as Apple Support
The email sends victims to a fake Find My or Apple page. They are asked to enter their iPhone passcode, Apple Account details, and two-factor authentication code. In some cases, SOCRadar found an AI voice agent posing as “Alice from Apple Support.” The agent tells victims that someone is trying to unlock the phone and brought it to an Apple store, where the device is being held. The AI agent then asks the victims to confirm ownership by dictating the passcode, then directs them to the phishing page.
Once threat actors have these codes, they can access the victim’s personal data, reset the iPhone, remove it from Find My, and also sell the unlocked device. A compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other sensitive company data, SOCRadar warns. The researchers also found that a small number of phishing emails from the platform targeted government and corporate organizations. Although AnonyMousKIT campaigns targeted victims worldwide, they were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil.
The post AnonyMousKIT Uses AI Voice Calls to Steal iPhone Passcodes appeared first on Android Headlines.