Researchers have uncovered AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents to target owners of stolen iPhones.

The service reportedly helps criminals obtain passcodes, Apple Account credentials and two-factor authentication codes. Attackers can then unlock stolen devices, remove Activation Lock and access sensitive data.

Researchers at SOCRadar say the platform has operated since early 2024.

AI agents impersonate Apple support

AnonyMousKIT phishing campaigns use emails, text messages, WhatsApp messages and phone calls that impersonate Apple.

The attackers first collect contact details from information displayed when an owner marks a device as lost. They then send convincing messages that claim someone has found the missing iPhone.

These messages may include accurate device details, such as the model and IMEI number. That information can make the scam appear legitimate.

In some cases, an AI voice agent claims to work for Apple support and asks the owner to confirm device ownership by sharing a passcode.

Fake websites collect Apple Account details

The campaign directs victims to fake pages that imitate Apple or Find My services. The pages ask users to enter their device passcode, Apple Account credentials and two-factor authentication code.

Once attackers obtain those details, they can access the owner’s personal information. They may also remove the device from Find My, reset it and sell it as an unlocked phone.

A compromised Apple Account may expose iCloud backups, saved Keychain passwords, work email and other sensitive information linked to the device.

Researchers link the platform to hundreds of domains

SOCRadar linked AnonyMousKIT to 506 domains and 168 storefront brands that allegedly resell the service.

Researchers also reviewed records of 200 calls to victims between August 2025 and May 2026. The platform used 55 interaction transcripts and five AI voice personas.

SOCRadar estimates that operators spent around $0.10 per call attempt. Most recorded calls targeted people in Brazil.

Campaign reaches victims worldwide

The AnonyMousKIT phishing operation has targeted victims worldwide. Researchers found stronger activity in Brazil, South Africa, Indonesia, Italy, India and Kenya.

Some messages also reached government and corporate organisations. That creates additional risks when a victim uses a personal or work-issued iPhone to access company systems.

Apple users should never share a device passcode or verification code during an unexpected phone call. They should also avoid signing in through links received in messages about a lost device.


0 responses to “AnonyMousKIT Phishing Uses AI Calls to Steal iPhone Passcodes”