Researchers have uncovered a sophisticated Phishing-as-a-Service platform using rented AI voice agents to impersonate Apple Support. The goal is to steal passcodes and 2FA codes to strip stolen iPhones of their Activation Lock.
- The 'AnonyMousKIT' platform provides Phishing-as-a-Service (PhaaS) capabilities.
- Attackers use rented AI voice agents to mimic real Apple Support staff.
- The primary objective is to bypass Apple's Activation Lock on stolen devices.
- Victims are manipulated into revealing device passcodes and 2FA codes.
A sophisticated new threat has emerged in the cybersecurity landscape, leveraging advanced artificial intelligence to facilitate device theft. The SOCRadar Threat Research Unit (STRU) has identified a malicious platform known as AnonyMousKIT. This platform operates on a 'Phishing-as-a-Service' (PhaaS) model, allowing criminals to rent sophisticated tools to target Apple users.
The core of this attack involves the deployment of rented AI voice agents. These agents are designed to sound indistinguishable from legitimate Apple Support representatives. By conducting highly convincing voice calls, the attackers aim to deceive victims into disclosing sensitive information, specifically their device passcodes and two-factor authentication (2FA) codes.
Why This Matters
BozokMedia analysis shows that the integration of AI into phishing campaigns marks a paradigm shift in cybercrime. The ability to automate high-quality, convincing voice interactions allows attackers to scale their operations globally with minimal human intervention, significantly increasing the success rate of social engineering attacks.
The weaponization of AI voice technology represents a critical evolution in social engineering, making traditional skepticism insufficient.
AnonyMousKIT functions through a credit-metered system, making it highly accessible to low-level cybercriminals. The platform provides various 'lures' to maximize the likelihood of a successful breach. Once the attackers obtain the necessary credentials, they can effectively strip the Activation Lock from stolen devices, rendering them ready for resale on the black market.
Historical Background
Apple's Activation Lock has long been the gold standard for preventing the use of stolen iOS devices. However, as security measures have evolved, so have the methods used by thieves. From hardware-based exploits to sophisticated social engineering like this AI-driven scheme, the battle between device security and criminal ingenuity continues to intensify.
Frequently Asked Questions
Question 1: Will Apple ever ask for my passcode over the phone?
Answer: No, legitimate Apple Support will never ask for your device passcode or 2FA codes via phone call.
Question 2: How can I protect myself from AI voice scams?
Answer: Always remain skeptical of unsolicited calls and verify any support request through official Apple channels.