Cybersecurity researchers uncovered a phishing-as-a-service platform that deploys AI voice agents to impersonate Apple Support and extract passcodes from stolen device owners. The operation, tracked as AnonyMousKIT by SOCRadar's Threat Research Unit, represents an escalation in theft-related fraud and targets one of Apple's most effective security barriers.
Activation Lock is Apple's anti-theft measure that requires device authentication even after a factory reset. To bypass it, thieves need legitimate Apple credentials or the victim's passcode and two-factor authentication codes. AnonyMousKIT automates the social engineering process that yields these credentials.
The platform operates on a credit-metered subscription model. Operators purchase access and use it to conduct voice phishing campaigns against iPhone, iPad, and Mac owners. The AI system calls theft victims posing as Apple Support representatives, claiming suspicious activity detected on the account or that the device requires immediate verification. During these calls, the AI voice agent requests the passcode, two-factor authentication codes, or both.
The technical sophistication of this approach matters. Synthetic voice technology has improved enough that many users do not immediately recognize AI impersonation. Combined with social engineering psychology, victims often comply during moments of perceived urgency. Once the attacker obtains these credentials, they can remove Activation Lock and resell the device on the secondary market or extract payment from desperate owners seeking device recovery.
Stolen iPhones carry high resale value. A single device can yield hundreds of dollars in black market sales. For thieves operating in bulk, AnonyMousKIT dramatically reduces the manual labor required to bypass security. Instead of hiring staff to conduct phishing calls, operators simply rent the platform and launch automated campaigns.
This threat intersects with a broader ecosystem problem. Device theft remains endemic in major cities. Secondary markets for used electronics operate with minimal verification of legitimacy. Organized retail theft rings increasingly target high-value smartphones. AnonyMousKIT removes friction from the entire workflow.
Apple has implemented defenses against credential harvesting. Two-factor authentication, security keys, and improved phishing detection all complicate these attacks. However, no single defense stops a well-executed social engineering campaign. The company cannot prevent stolen devices from being registered as theft victims, and phishing success rates remain problematic across the industry.
Organizations and individuals face different risks. Businesses with corporate-issued Apple devices should enforce MDM solutions that prevent credential sharing and implement mandatory device tracking. Individuals should never provide passcodes or 2FA codes to support personnel contacting them unsolicited, even if the call appears legitimate. Apple Support never requests these credentials proactively.
Users should verify caller identity by hanging up and calling Apple directly through official channels. Enabling the "Find My" feature adds a recovery layer. Setting up a strong Apple ID password and disabling legacy authentication methods reduces exposure.
The emergence of AnonyMousKIT demonstrates how criminal infrastructure now commoditizes phishing. Threat actors need no technical expertise to conduct sophisticated social engineering. They simply rent access to a platform and scale attacks horizontally across thousands of potential victims. This model accelerates theft-related fraud and underscores why security must extend beyond technical controls to include user awareness and rapid incident response protocols.
