AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Cybersecurity experts have uncovered a sophisticated PhaaS platform that uses voice AI agents to phish iPhone passcodes, exploiting vulnerabilities in Apple’s Activation Lock feature. The platform, known as AnonyMousKIT, has been active since early 2024 and is linked to a sprawling ecosystem of stolen iPhones, compromised Apple IDs, and accessed iCloud backups.

At its core, AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices, allowing threat actors to access sensitive data and disable Activation Lock. The platform’s operators use voice AI agents to impersonate Apple support staff, contacting victims via email, SMS, WhatsApp, or phone call. These agents assume various personas, including “Alice from Apple Support,” which are designed to build trust with the victim.

The AI-powered phishing campaign is particularly insidious, as it uses a fake Find My or Apple page to prompt victims to enter their device passcode, Apple Account credentials, and two-factor authentication code. Once threat actors obtain these codes, they can access personal data, factory reset the device, and remove it from the Find My app before selling it.

Researchers at SOCRadar, who discovered AnonyMousKIT’s infrastructure, note that the platform is connected to 506 domains and fuels a business with 168 storefront brands acting as resellers. The researchers also recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by the voice AI agent.

The campaigns facilitated by AnonyMousKIT have a global footprint, but are more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil. SOCRadar warns that compromised Apple IDs could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices.

The use of AI-powered phishing tactics is a concerning trend in the cybersecurity landscape, as it allows threat actors to adapt and improve their campaigns in real-time. As SOCRadar notes, once attackers have valid credentials, only 37% of their actions are blocked by overall prevention scores, which can hide what happens after initial access.

For Apple users, this highlights the importance of staying vigilant against phishing attacks, especially when contacted via email or phone call by individuals claiming to be from Apple. It is essential to verify the authenticity of these messages and never enter sensitive information on unfamiliar websites or pages. Users should also ensure that their devices are up-to-date with the latest security patches and consider enabling two-factor authentication whenever possible.

In conclusion, the AnonyMousKIT PhaaS platform serves as a stark reminder of the evolving nature of cyber threats. As AI-powered phishing tactics become increasingly sophisticated, it is crucial for individuals and organizations to stay informed about these risks and take proactive steps to protect themselves against these types of attacks.


Source: Bleeping Computer — 2026-08-25