Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-26 ยท updated: 2026-08-26 ยท tags: [incident, cybercrime-group, technique, stealer, sector-technology, sector-government] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government] ยท au_impact: true

AnonyMousKIT PhaaS Platform Uses Voice AI Agents to Phish iPhone Passcodes at Scale

Security researchers at SOCRadar documented AnonyMousKIT, an automated Phishing-as-a-Service (PhaaS) platform operating since early 2024 designed to systematically bypass Apple device protections on stolen iPhones using conversational voice AI agents.

Overview

Attribute Detail
Threat Platform AnonyMousKIT PhaaS
Active Since Early 2024
Infrastructure 506 connected phishing domains, 168 reseller storefronts
Attack Vector Voice AI vishing agents impersonating Apple Support ("Alice" and 4 other personas)
Cost / Economics ~$0.10 per call attempt
Target Demographics 90% of observed calls directed to Brazil; corporate and government mailboxes also targeted
Date 2026-08-25

Operational Mechanism

  1. Pre-Call Reconnaissance: Criminals feed stolen iPhone identifiers (exact device model, serial number, and IMEI) into the platform.
  2. AI Vishing Call: The automated voice AI agent calls the device owner, presenting tailored device details to build credibility and posing as Apple Support personnel investigating device recovery.
  3. Harvesting Sequence: The agent deceives victims into providing device passcodes, Apple Account credentials, and multi-factor authentication (MFA) codes.
  4. Account Compromise & Device Resale: Stolen credentials enable attackers to unlock iCloud activation locks, access iCloud backups, extract Keychain passwords, and wipe devices for unrestricted resale on secondary markets.

Significance

AnonyMousKIT demonstrates the industrialisation and commoditisation of autonomous voice AI agents for real-time social engineering. At approximately ten cents per attempt, highly convincing, interactive voice attacks are now available to low-tier cybercrime syndicates at massive scale.

Australian Context

The platform's capability to extract Apple Account credentials and passcodes poses direct risks to Australian individuals and enterprise executive fleets. Australian organisations should emphasise vishing awareness and verify lost device communications exclusively through official, out-of-band enterprise channels.

Sources