New Phishing Platform Uses AI Voice Agents to Unlock Stolen iPhones
Cybersecurity researchers have uncovered a sophisticated phishing-as-a-service platform designed to bypass Apple’s Activation Lock on stolen iPhones using AI voice agents. The platform, tracked as AnonyMousKIT, rents AI voice agents that impersonate Apple Support and call theft victims requesting their device passcode—a tactic that represents a significant evolution in Apple AI voice phishing attacks. The discovery highlights how criminals are now combining technical exploits with social engineering to unlock stolen devices at scale.
How the AnonyMousKIT Platform Operates
SOCRadar Threat Research Unit describes AnonyMousKIT as less a traditional phishing kit and more a criminal software business, complete with credit bundles, published pricing, tiered subscriptions, and customer support. The platform distributes lures across five channels—email, SMS, WhatsApp, recorded voice calls, and AI voice agents—each priced separately. The AI voice channel costs 2 credits per call, making it one of the more expensive options but also the most sophisticated vector for Apple AI voice phishing.
Victims receive communications citing their device’s internal Apple model identifier and live Find My status, both pulled from the stolen device itself. The lures direct users to an Apple-branded capture page displaying an animated map of the handset’s location. Once connected, the AI voice agent—operating under the persona “Alice from Apple Support” in English, Spanish, and Portuguese—requests the device passcode, Apple ID credentials, and a live two-factor authentication code. Apple has repeatedly stated it never requests passwords, device passcodes, or 2FA codes during support interactions.
Scale and Technical Details of the AI Voice Phishing Campaign
Researchers recovered 200 call records and 55 transcripts from the operator’s account with commercial voice platform Vapi. The calls ran between August 31, 2025 and May 30, 2026, with 179 of the 200 directed to numbers in Brazil. The total cost for those 200 calls came to approximately $19.24, or about 9.6 cents each—demonstrating how economically viable large-scale Apple AI voice phishing has become.
المصدر: The Hacker News