AnonyMousKIT, il phishing-as-a-service che usa voci IA per rubare i passcode degli iPhone
AI

Illustrative image generated with AI

AnonyMousKIT, the Phishing-as-a-Service Using AI Voices to Steal iPhone Passcodes

SOCRadar reveals AnonyMousKIT, a PhaaS using AI voices to phish iPhone owners for passcodes, bypassing Activation Lock and stealing data.

Text generated by artificial intelligence, published without human review. AI transparency

SOCRadar’s Discovery and the Platform

On August 25, 2026, threat intelligence firm SOCRadar published an analysis of AnonyMousKIT, a phishing-as-a-service platform active since early 2024. Researchers gathered information on its operations, operators, and infrastructure by leveraging the operator’s use of exposed relative paths. AnonyMousKIT automates the retrieval of the codes needed to unlock stolen iPhones and disable Apple’s Activation Lock. The platform includes a management panel that lets affiliates control campaigns. The business model relies on resellers: 168 branded storefronts operate as points of sale for the illicit service.

How the Attack Chain Works

Apple’s Activation Lock turns on automatically when Find My is enabled and ties the iPhone to the owner’s Apple Account. Even after a factory reset, the device remains linked to the account and requires a valid authorization code during initial setup. AnonyMousKIT bypasses this protection by targeting the owner rather than the device. The platform extracts victim contact information from stolen devices, such as details provided through Lost Mode. It then contacts the owner by email, SMS, WhatsApp, or phone call. The messages impersonate Apple and claim the lost device has been located. They include the correct model and IMEI to appear legitimate. The email leads to a fake Find My or Apple page where the victim must enter the device passcode, Apple Account credentials, and two-factor authentication code. In some cases examined by SOCRadar, an AI voice agent using the persona “Alice from Apple Support” tells the victim that someone brought the phone to an Apple Store and the device has been held. It then asks the victim to confirm ownership by speaking the passcode and later directs them to the phishing page. Once the codes are obtained, attackers can access the victim’s personal data, reset the device, remove it from Find My, and resell it.

Infrastructure, Costs, and Global Reach

AnonyMousKIT’s infrastructure is linked to 506 domains, a number reflecting the need for rapid rotation to evade blocking. SOCRadar recovered logs of 200 calls made to victims between August 2025 and May 2026. The 55 transcripts of distinct interactions show an AI voice agent configured with five personas, including “Alice from Apple Support.” Calls cost the operator about $0.10 per attempt, a low cost that makes telephony an accessible channel even for large-scale campaigns. 90% of calls were directed to Brazilian numbers. The campaigns have a global footprint but are more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil.

Impact on Private Users and Organizations

A compromised Apple ID can expose iCloud backups, Keychain passwords, corporate emails, and other enterprise information stored on personal or company-issued devices. SOCRadar notes that a small percentage of emails sent by the platform were addressed to government organizations and companies. Once unlocked, stolen iPhones gain greater value and can be resold with possible access to sensitive data. The damage is not limited to losing the device: it includes identity theft, access to services linked to the Apple Account, and potential corporate data breaches.

Limited Defenses: Activation Lock Is Not Enough

SOCRadar’s analysis does not list specific mitigations. Activation Lock exists as an Apple protection, but in the AnonyMousKIT service it is bypassed through phishing directed at the owner. The fundamental rule remains: never provide the passcode or two-factor authentication codes to anyone, even if the request appears to come from Apple. Apple never asks for the passcode by phone or email. If you receive a suspicious call or message, it is best to end the communication and contact Apple through official channels. Employees of government organizations and companies should receive specific training on this type of attack, as their accounts are attractive targets.

The Context: AI Voices and Defenses Under Pressure

The use of AI voice agents makes phishing more credible and scalable. AnonyMousKIT is not an isolated incident: it represents the evolution of PhaaS platforms, which turn complex attacks into low-cost services. A figure from the Blue Report 2026, cited in the same publication, indicates that once attackers have valid credentials, only 37% of their actions are blocked. The report measures defenses technique by technique across 338 million simulations run in customer production environments. In this scenario, the human factor remains the most exploited entry point.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsAnonyMousKITPhishing-as-a-ServiceAI Voice PhishingiPhone Passcode TheftActivation Lock BypassSOCRadarCybersecurity Threat
Back to home