AnonyMousKIT Uses AI Calls to Phish iPhone Passcodes
SOCRadar Threat Research Unit disclosed details of AnonyMousKIT on August 25-26, 2026, revealing a phishing-as-a-service platform that uses AI voice agents posing as Apple Support to seek passcodes and 2FA codes from owners of lost or stolen devices. Reports linked it to 506 domains, 168 reseller storefronts, and 200 calls, about 90% to Brazilian numbers.
Security researchers have disclosed AnonyMousKIT, a phishing-as-a-service platform used to obtain credentials needed to remove Apple's Activation Lock from stolen devices. Reporting by The Hacker News and BleepingComputer, based on SOCRadar Threat Research Unit findings, describes a credit-metered operation that sends lures through email, SMS, WhatsApp, recorded calls, and AI voice agents impersonating Apple Support.
The platform targets people whose Apple devices have recently been lost or stolen. According to The Hacker News, its phishing pages and calls ask victims in sequence for a four- or six-digit device passcode, Apple Account credentials, and a live two-factor authentication code. Apple's support guidance states that Apple does not ask customers for passwords, device passcodes, or two-factor authentication codes when providing support.
Multi-channel credential capture
Activation Lock links an Apple device to its owner's Apple Account when Find My is enabled, leaving a reset device unusable without authorization from that account. BleepingComputer reports that AnonyMousKIT extracts owner contact details from a stolen device and uses device-specific information, including model and IMEI details, to make messages claiming the missing handset has been found appear credible.
The Hacker News reports that the service assigns credits to attack channels, including 1.5 credits for email, one credit for a recorded voice call, and two credits for an AI voice-agent call. CyberInsider reported that SOCRadar identified 6,092 phishing emails across 30 related backends, aimed at 5,031 devices marked online and 1,035 marked locked.
Victims who follow a link are directed to Apple-branded pages that, according to CyberInsider, use localized content, anti-bot checks, and animated maps before requesting authentication material. The collected information can enable an attacker to remove the original account association and increase the resale value of a stolen device.
Voice-agent evidence
BleepingComputer reported that SOCRadar recovered records for 200 victim calls made between August 2025 and May 2026, along with 55 interaction transcripts using five voice-agent personas. The Hacker News reported that 179 of the 200 calls were placed to Brazilian numbers and that the recovered personas used the translated identity "Alice from Apple Support" in English, Spanish, and Portuguese.
According to BleepingComputer, the calls cost the operator about $0.10 per attempt. SOCRadar linked the operation to 506 domains and 168 storefront brands acting as resellers, the outlet reported. Cybernews separately reported that the operation remained active when its article was published, citing continuing backend and domain activity.
The Hacker News reported that the voice infrastructure used a commercial platform, Vapi, and that SOCRadar's report did not state whether the relevant account had been reported to Vapi. The outlet also reported that neither Vapi nor the platform operators had publicly addressed whether the account remained active.
The case illustrates how stolen-device fraud can combine physical theft, device-derived context, phishing infrastructure, and low-cost conversational automation. Comparable multi-channel campaigns can be harder for users to recognize because a phone call can reinforce a previously received email or SMS, while legitimate device details lend credibility to the social-engineering pretext.
Key Points
- 1SOCRadar linked AnonyMousKIT to AI voice phishing that captures passcodes, Apple Account credentials, and live two-factor authentication codes from theft victims.
- 2The reported 506 domains and 168 reseller brands show how phishing-as-a-service operations can distribute infrastructure and monetization across affiliates.
- 3Comparable multi-channel social-engineering campaigns can compound credibility by pairing device-specific emails, messages, and automated voice calls at low marginal cost.
Scoring Rationale
This is a notable security development because it documents AI voice agents integrated into an active, scaled phishing-as-a-service operation. It is especially relevant to practitioners working on identity security, fraud detection, mobile-device protection, and AI-enabled social-engineering defenses.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
