AnonyMousKIT PhaaS Platform Uses Voice AI Agents to Phish iPhone Passcodes at Scale
Security researchers at SOCRadar documented AnonyMousKIT, an automated Phishing-as-a-Service (PhaaS) platform operating since early 2024 designed to systematically bypass Apple device protections on stolen iPhones using conversational voice AI agents.
Overview
| Attribute | Detail |
|---|---|
| Threat Platform | AnonyMousKIT PhaaS |
| Active Since | Early 2024 |
| Infrastructure | 506 connected phishing domains, 168 reseller storefronts |
| Attack Vector | Voice AI vishing agents impersonating Apple Support ("Alice" and 4 other personas) |
| Cost / Economics | ~$0.10 per call attempt |
| Target Demographics | 90% of observed calls directed to Brazil; corporate and government mailboxes also targeted |
| Date | 2026-08-25 |
Operational Mechanism
- Pre-Call Reconnaissance: Criminals feed stolen iPhone identifiers (exact device model, serial number, and IMEI) into the platform.
- AI Vishing Call: The automated voice AI agent calls the device owner, presenting tailored device details to build credibility and posing as Apple Support personnel investigating device recovery.
- Harvesting Sequence: The agent deceives victims into providing device passcodes, Apple Account credentials, and multi-factor authentication (MFA) codes.
- Account Compromise & Device Resale: Stolen credentials enable attackers to unlock iCloud activation locks, access iCloud backups, extract Keychain passwords, and wipe devices for unrestricted resale on secondary markets.
Significance
AnonyMousKIT demonstrates the industrialisation and commoditisation of autonomous voice AI agents for real-time social engineering. At approximately ten cents per attempt, highly convincing, interactive voice attacks are now available to low-tier cybercrime syndicates at massive scale.
Australian Context
The platform's capability to extract Apple Account credentials and passcodes poses direct risks to Australian individuals and enterprise executive fleets. Australian organisations should emphasise vishing awareness and verify lost device communications exclusively through official, out-of-band enterprise channels.