Skip to main content
Emerging ThreatsMalware & Ransomware

AnonyMousKIT Phishing Service Exploits Voice AI to Harvest iPhone Passcodes

Smartphone sits on retail store counter amidst blurred customer activity.

"SOCRadar found that AnonyMousKIT is connected to 506 domains and is fueling a sprawling business with 168 storefront brands acting as resellers," the researchers report — a striking measure of reach for a service that automates phishing to unlock stolen Apple devices.

How AnonyMousKIT retrieves unlocking codes

According to research published by SOCRadar, AnonyMousKIT is a phishing-as-a-service (PhaaS) platform that automates the retrieval of codes used to unlock stolen Apple devices and disable Apple’s Activation Lock. The service has been active since early 2024 and builds its lure from information stolen directly off devices — for example, owner contact details supplied through the iPhone Lost Mode feature. Operators use that information to reach owners by email, SMS, WhatsApp, or phone call.

The phishing messages impersonate Apple, include correct device model and IMEI details to appear legitimate, and direct victims to fake Find My or Apple pages. On those pages victims are prompted to enter their device passcode, Apple Account credentials, and the two-factor authentication code. Once obtained, SOCRadar says, the attackers can access personal data, factory-reset the device, and remove it from the Find My app before selling the phone.

Voice AI agents, interaction transcripts, and operational scale

SOCRadar recovered records showing 200 calls made to victims between August 2025 and May 2026. Those calls used 55 distinct interaction transcripts handled by a voice AI agent operating under five personas — including an agent identified in the report as “Alice from Apple Support.” In at least some cases the AI agent told victims an Apple store had retained the device and asked them to confirm ownership by dictating their passcode before directing them to the phishing page.

The researchers found the calls cost the operator about $0.10 per attempt and that roughly 90% of the calls were made to Brazil. SOCRadar's observations show voice AI is being used to scale social-engineering steps that previously required a human caller.

Activation Lock, value to thieves, and data exposure

SOCRadar outlines how Apple’s Activation Lock — which activates when the Find My service is turned on and links a device to an Apple Account — is central to the attackers’ calculus. Even after a factory reset, a device remains linked to the original owner’s account and demands a valid authorization code during setup. Because of this, many stolen iPhones are sold for parts. However, the report notes, their value rises sharply if attackers can unlock the device and recover sensitive owner data.

A compromised Apple ID, SOCRadar warns, can expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices. The research adds that a small percentage of the platform’s emails were sent to government and corporate organizations, indicating the operation occasionally reaches accounts tied to institutional functions.

Domains, resellers, and geographic footprint

SOCRadar mapped the platform’s infrastructure and found a sprawling business model: 506 connected domains and 168 storefront brands acting as resellers. Campaigns facilitated by AnonyMousKIT had a global footprint but were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil, the researchers report.

The scale implied by hundreds of domains and many storefronts suggests the platform is designed to support an ecosystem — not just isolated actors — where unlocking and resale are components of a broader criminal supply chain.

What this means for technologists, enterprises, and end users

  • Technologists and security teams: SOCRadar’s report highlights a common failure mode documented in the Blue Report 2026: overall prevention scores can hide what happens after initial access. The Blue Report notes that once attackers are using valid credentials, prevention drops sharply — a risk that is directly relevant where stolen device credentials are in play.
  • Affected enterprises and procurement leaders: The report’s finding that a small percentage of emails were sent to government and corporate organizations signals exposure beyond consumer accounts; organizations with employees who use Apple devices may face data leakage if personal devices are compromised and linked to corporate resources.
  • End users and the general public: The recovered transcripts show attackers leveraging authentic device details and scripted voice interactions to convince owners to reveal passcodes and authentication codes. For owners of devices with Find My and Activation Lock enabled, that combination can lead to both device loss and the exposure of iCloud backups and Keychain data, according to SOCRadar.

SOCRadar’s documentation of AnonyMousKIT — its domains, storefronts, recorded calls, and voice-AI transcripts — paints a precise portrait of how voice agents and automated phishing are being operationalized to monetize stolen hardware and harvest credentials. The central question the record leaves on the table is practical: how to disrupt an operation spread across 506 domains and 168 reseller brands while voice-AI lowers the marginal cost of targeted social engineering.

Source: https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/