VYPR
researchPublished Aug 26, 2026· 1 source

AnonyMousKIT Phishing Service Uses AI Voice Agents to Steal Apple Device Passcodes

A new phishing-as-a-service platform, AnonyMousKIT, employs AI voice agents to impersonate Apple Support, targeting owners of stolen Apple devices to bypass Activation Lock.

Cybersecurity researchers have uncovered AnonyMousKIT, a sophisticated phishing-as-a-service (PhaaS) platform designed to strip Apple's Activation Lock from stolen devices. The service leverages rented AI voice agents that call victims, posing as Apple Support, with the ultimate goal of obtaining device passcodes and Apple ID credentials.

The AnonyMousKIT platform operates on a credit-metered model, offering multiple communication channels for a single victim record. These channels include email, SMS, WhatsApp, recorded voice calls, and the advanced AI voice agent, with varying credit costs for each. This multi-channel approach aims to maximize the chances of tricking victims into divulging sensitive information.

Targets are specifically owners of recently lost or stolen Apple devices. The fraudulent communications, whether via email or AI-driven calls, request the device passcode, followed by Apple ID credentials, and finally, a two-factor authentication (2FA) code. This information is crucial for bypassing Apple's Activation Lock, a security feature that renders stolen devices unusable.

Researchers describe AnonyMousKIT as a "small software business with a criminal customer base," featuring elements like credit bundles, tiered subscriptions, customer support, and infrastructure replacement protocols. This organized structure highlights the professionalization of cybercrime operations.

Activation Lock, a feature introduced with iOS 7, links a device to a specific Apple ID, making it a significant deterrent for thieves. However, AnonyMousKIT's methods directly target the human element, exploiting the trust victims might place in communications appearing to be from official Apple Support.

The AI voice channel, a key innovation of the platform, utilizes configured personas from a commercial voice platform. These AI agents, speaking in English, Spanish, and Portuguese, impersonate an Apple Support representative named Alice. The calls are designed to sound legitimate, guiding victims through a process that ultimately leads to the compromise of their device security.

While the platform has been observed to log numerous communication attempts, the researchers' report does not specify the exact number of successful passcode, Apple ID, or 2FA code captures across all channels. However, the existence and operational details of AnonyMousKIT underscore a growing trend of AI being weaponized for sophisticated social engineering attacks, particularly targeting high-value consumer electronics.

The platform's infrastructure has been identified across multiple domains, with a significant portion of targeted calls originating from Brazil. The sophistication of AnonyMousKIT, combining AI voice technology with established phishing techniques, presents a significant challenge for Apple and its users in combating device theft and unauthorized access.

Synthesized by Vypr AI