A phishing-as-a-service platform called AnonyMousKIT, active since early 2024, automates the process of retrieving Activation Lock unlock codes from stolen iPhones by using AI voice agents to impersonate Apple support staff, according to research from SOCRadar reported by BleepingComputer.
How the Scheme Works
AnonyMousKIT pulls information from a stolen device’s Lost Mode feature, including the owner’s contact details, then reaches out through email, SMS, WhatsApp or a phone call. The messages impersonate Apple and claim the missing device has been located, citing the correct model and IMEI details to make the outreach appear legitimate. When a victim engages by phone, a commercial voice AI agent built on the VAPI.ai platform takes over the call, running under a persona — researchers identified one named “Alice from Apple Support” speaking Portuguese — that asks the victim to confirm ownership by dictating their four- or six-digit device passcode before directing them to a fake Find My or Apple login page.
SOCRadar found the operation connected to 506 domains and 168 reseller storefronts, and recovered logs of roughly 200 calls made between August 2025 and May 2026 across 55 interaction transcripts, with call volume concentrated mostly in Brazil alongside activity in South Africa, Indonesia, Italy, India and Kenya. Each AI-driven call reportedly costs the operators only about $0.10.
The Stakes Extend Beyond a Single Stolen Phone
Once attackers obtain a victim’s passcode and Apple Account credentials, they can factory reset the device, remove it from the Find My network and resell it — the core business model the service is built around. But SOCRadar warns the exposure runs deeper than device resale: a compromised Apple ID can expose iCloud backups, Keychain-stored passwords, work email and other corporate data synced to the device, particularly on employer-issued phones enrolled in bring-your-own-device or corporate mobility programs.
The case adds to a growing pattern of cybercrime platforms integrating conversational AI to scale social-engineering operations that previously required human callers, following the earlier emergence of AI-driven voice phishing platforms such as ATHR, reported by Abnormal Security. For security teams, it underscores that mobile device management and lost-device response procedures now need to account for AI-generated voice impersonation as a credible, low-cost attack vector rather than a theoretical one.

Leave a Reply