Cybersecurity researchers have uncovered AnonyMousKIT, a sophisticated Phishing-as-a-Service (PhaaS) platform that uses AI voice agents to bypass Apple's security features.
- AnonyMousKIT is a PhaaS platform designed to unlock stolen Apple devices using AI.
- The service uses AI voice agents with distinct personas to deceive victims into revealing passcodes.
- The platform enables the resale of stolen iPhones by disabling Apple's Activation Lock.
A sophisticated new threat has emerged in the cybersecurity landscape. Researchers at SOCRadar have uncovered AnonyMousKIT, a highly organized Phishing-as-a-Service (PhaaS) platform that automates the theft of iPhone passcodes and Apple ID credentials.
Operating since early 2024, AnonyMousKIT powers a sprawling criminal ecosystem. It doesn't just steal codes; it facilitates the sale of stolen iPhones, harvests iCloud backups, and accesses sensitive Keychain credentials, effectively turning locked, stolen devices into high-value resale items.
The Mechanics of AI-Driven Deception
What sets AnonyMousKIT apart is its use of voice AI agents. Instead of relying solely on text-based phishing, the platform employs AI personas—such as 'Alice from Apple Support'—to conduct phone calls. These agents interact with victims, often claiming that a lost device has been located at an Apple store, thereby building a false sense of legitimacy.
Once the victim is engaged, the AI directs them to a fraudulent 'Find My' or Apple login page. Victims are then prompted to enter their device passcode, Apple Account credentials, and two-factor authentication (2FA) codes, giving attackers full access to the user's digital life.
Why This Matters
BozokMedia analysis shows that the danger of these attacks escalates once the initial breach occurs. While security software might flag suspicious activity, once attackers obtain valid credentials, the effectiveness of traditional prevention drops sharply. According to industry data, only about 37% of actions taken with valid credentials are blocked by standard security measures.
The integration of generative AI into phishing workflows marks a paradigm shift, making social engineering attacks nearly indistinguishable from legitimate support interactions.
The operation is massive, connected to over 500 domains and supported by 168 reseller brands. While the attacks have a global footprint, they are heavily concentrated in regions like Brazil, India, South Africa, and Indonesia. Notably, some phishing campaigns have even targeted government and corporate organizations.
Frequently Asked Questions
1. How can I identify an AI phishing call?
Be wary of any caller asking for sensitive information like passcodes or 2FA codes, even if they claim to be from Apple. Legitimate companies will never ask for these via phone.
2. What is Apple's Activation Lock?
It is a security feature that links a device to an Apple ID, preventing anyone else from using it even after a factory reset. AnonyMousKIT aims to bypass this via credential theft.