AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Threat Actors Use Voice AI Agents to Phish iPhone Passcodes in Sophisticated Scheme

A new phishing-as-a-service (PhaaS) platform called AnonyMousKIT has been uncovered, using voice artificial intelligence agents to trick victims into revealing their iPhone passcodes. This brazen scheme allows threat actors to unlock and resell stolen Apple devices, while also accessing sensitive data stored on the device.

The platform, which has been active since early 2024, is a highly organized operation that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials. Researchers at SOCRadar, a threat intelligence platform, gained insight into how AnonyMousKIT operates by exploiting its use of bare relative paths. This allowed them to gather information on the platform’s infrastructure, operators, and scope.

The platform is connected to 506 domains and has created a sprawling business with 168 storefront brands acting as resellers. According to SOCRadar, these storefronts sell stolen iPhones, often without revealing that they are compromised devices. The researchers also discovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.

These AI-powered calls cost the operator approximately $0.10 per attempt, with 90% of the calls being made to Brazil. The calls are designed to appear as if they are from Apple Support or an authorized representative, claiming that the missing device has been located and requesting the victim’s passcode to verify ownership.

Once the threat actors obtain the passcodes, they can access the victim’s personal data, factory reset the device, and remove it from the Find My app before selling it. A compromised Apple ID could expose sensitive information stored on iCloud backups, Keychain passwords, work email, and other corporate accounts.

SOCRadar warns that a small percentage of the emails sent by AnonyMousKIT were targeted at government and corporate organizations, highlighting the potential for significant data breaches. The campaigns facilitated by the platform have a global footprint, but are more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil.

The use of voice AI agents in this scheme is particularly concerning, as it adds an extra layer of sophistication to the phishing attacks. Once attackers gain valid credentials, their success rate increases significantly, with only 37% of actions being blocked by prevention measures.

For individuals and organizations, this serves as a stark reminder to remain vigilant against phishing attacks. With the rise of PhaaS platforms like AnonyMousKIT, it’s essential to educate users on the risks associated with sharing sensitive information over unsecured channels. By staying informed and taking proactive steps to protect their data, individuals can significantly reduce the risk of falling victim to such sophisticated schemes.

Practical takeaway: Be cautious when receiving unsolicited calls or emails claiming to be from Apple Support or an authorized representative. Legitimate organizations will never ask for sensitive information, including passcodes, via email or phone call. If in doubt, contact the organization directly through official channels to verify the authenticity of the request.


Source: Bleeping Computer — 2026-08-25