Skip to main content
Emerging ThreatsMalware & Ransomware

Phishing Platform Targets Apple Device Owners with AI Voice Scams

Person holds Apple device with concerned expression in urban setting.

"AnonyMousKIT is best understood not as a phishing kit but a small software business with a criminal customer base," SOCRadar Threat Research Unit (STRU) wrote in its Monday report — a precise description of a platform that packages social engineering, paid AI voice agents, and a multi-channel delivery system to target owners of recently lost or stolen Apple devices.

AnonyMousKIT: a credit‑metered, multi-channel service

SOCRadar's analysis shows AnonyMousKIT is built like a commercial service: published pricing, credit bundles, tiered subscriptions, customer support, status tracking and infrastructure replacement protocols. From a single victim record the platform drives lures across five channels: email (priced at 1.50 credits), SMS (priced per sender ID), WhatsApp, a recorded voice call (1 credit), and an AI voice agent (2 credits). The panel also lists four advertised "unlock tools" — marketing that researchers say functions as bait.

Activation Lock, introduced in iOS 7, ties hardware to an Apple ID and renders a stolen handset unusable until the account is removed. SOCRadar noted that 5,649 of the 6,092 devices targeted across the kit family (92.7%) run A12 silicon or newer, a fact that makes advertised technical bypasses an unlikely promise rather than an actual capability for most targets.

AI voice calls: the recorded evidence

The AI voice channel is the best documented. Researchers recovered 200 call records, 55 transcripts and five configured personas from an operator account on the commercial voice platform Vapi. All five personas carried the same translated identity, "Alice from Apple Support," in English, Spanish and Portuguese. The calls took place between August 31, 2025 and May 30, 2026; 179 of the 200 calls went to numbers in Brazil.

Transcripts show the agent asking the recipient to confirm ownership, requesting the four- or six-digit device passcode and reading the digits back for confirmation, then asking for Apple ID credentials and a live two‑factor authentication code while referencing a supposed Apple Store visit to remove Activation Lock. SOCRadar calculated the total cost of the 200 calls at $19.24 — about $0.096 per call. The outcome table assigns each call to one of four results: 100 victims hung up, 48 timed out in silence, 24 did not answer, and 28 returned platform errors or busy signals.

The researchers did not report whether the Vapi account was flagged or taken down, and neither company has said publicly whether it remains active.

Email, SMS and global infrastructure: volume, patterns and misconfiguration

SOCRadar logged 691 send attempts from AnonyMousKIT between March and July 2026, against 6,092 sends across 30 related backends. A scan of 506 kit‑family domains identified 30 distinct installations reachable on 42 domains, with 188 domains still live. Three storefronts — i‑Blocker, Key Unlock and KG‑KING — launched in the same second on April 10, 2026 and shared the same Gmail relay accounts, a pattern SOCRadar assessed as a single buyer operating multiple brands.

The email lures exhibit consistent tactics: the top two subject lines were "Your device has been found" (308 of 691) and "Alert" (157); display names spoofed Apple, Find My, Apple Support and Apple Assistance; and 627 of the logged sends relayed through a single free Gmail account, noreplyapple00000[@]gmail[.]com. Nearly all of the lures (678 of 691) included a location token naming a city — Johannesburg, Abuja, Buenos Aires, Maputo and Mumbai among them — and victim-facing capture pages were served from tokenized /help?TOKEN URLs.

Geography and targeting patterns matter: South Africa accounted for 1,735 of the 6,092 family‑wide sends, and 64 of AnonyMousKIT's 691 sends reached non‑consumer domains — including 27 to South African government addresses — selected because those recipients’ devices were stolen, the report says. The researchers also found that the kit's distributed codebase exposes bare relative file paths that resolve to the web root and permit unauthenticated HTTP access; every deployment that inherits the codebase carries the flaw.

Technical bypasses versus reality: bootrom exploits and limits

SOCRadar contrasted the social engineering funnel with the technical reality. The long‑documented checkm8 bootrom exploit reaches only A5 through A11 chips. A public bootrom exploit for A12 and A13 was released on June 18, 2026 and its proof of concept remains live, but its authors describe it as a tethered exploit that requires physical possession and device firmware update (DFU) mode. SOCRadar's review found no evidence the public exploit compromises the Secure Enclave; the control tool can demote a device to production mode or boot a raw iBoot image, but "neither action recovers a device passcode or removes Activation Lock."

In short, the report treats many advertised "unlock" tools as social‑engineering bait: the operators need the passcode, Apple ID and 2FA code in real time to defeat protections, and that is what the multi‑channel campaign is engineered to obtain.

What this means for technologists, end users, and law enforcement

  • Technologists and security teams: SOCRadar's finding that the shared codebase exposes unauthenticated web paths and that dozens of installations are reachable across hundreds of domains suggests defenders should prioritize domain and URL telemetry (including patterns like tokenized /help?TOKEN pages) and blacklist the kit‑family domains identified by telemetry vendors such as Infoblox Threat Intel.
  • End users and device owners: Apple explicitly states in support documentation published June 15, 2026, "Apple will never ask you to log in to any website, or to tap Accept in the two‑factor authentication dialog, or to provide your password, device passcode, or two‑factor authentication code or to enter it into any website." The researchers also recommended moving high‑value Apple IDs to physical hardware security keys, which they said "completely mitigates the real‑time 2FA interception" the fraud funnel seeks.
  • Law enforcement and platform operators: Infoblox Threat Intel documented 4,244 malicious domains in the ecosystem between March 2022 and May 2026, and previous law‑enforcement action has shown takedowns can occur: German and U.S. authorities dismantled Kratos in July, pulling more than 200 servers offline while Indonesian authorities arrested the man they say developed and ran it. SOCRadar reported the platform was still running on the last day of its analysis and said it would continue to track the kit, sibling storefronts and the shared codebase.

By combining affordable automated voice agents, mass email and messaging lures, and a commercialized interface for buyers, the AnonyMousKIT family highlights a simple, stark equation: social engineering plus cheap AI at scale can convert stolen hardware into exploitable value. Infoblox researchers Maël Le Touz and Elena Puga put it crisply: "By combining technical tooling and social engineering, thieves now have a way to unlock devices at scale and make phone theft profitable." SOCRadar's recommendations — including hardware security keys and aggressive domain and telemetry blocking — are concrete mitigations; what remains open is whether the commercial voice platforms and mail relays used in these campaigns will take sustained action to disrupt the flow.

Source: The Hacker News — Fake Apple Support AI Calls Target Stolen‑Device Owners for Passcodes and 2FA Codes