Cybersecurity researchers have uncovered a phishing-as-a-service platform that uses AI-powered voice agents to target people whose iPhones have recently been lost or stolen.
The platform, tracked as AnonyMousKIT by SOCRadar Threat Research Unit (STRU), is designed to trick victims into handing over their device passcodes, Apple ID credentials and two-factor authentication codes.
Unlike a simple phishing kit, AnonyMousKIT operates more like a commercial service for cybercriminals. The platform uses a credit-based system that allows customers to launch different types of attacks against a victim from a single record. Options include email messages, SMS, WhatsApp messages, recorded voice calls, and AI-powered voice calls, each carrying its own credit cost.
The attackers primarily target owners of stolen Apple devices. Their messages and calls typically claim that the device has been located or recovered and ask the victim to complete a verification process. The ultimate goal is to obtain the four- or six-digit device passcode, Apple ID login information and a live two-factor authentication code.
Apple has repeatedly warned users that genuine Apple Support will never ask for a password, device passcode or two-factor authentication code.
AnonyMousKIT makes its phishing campaigns more convincing by using information associated with the stolen device. Researchers found that the lures can include the device’s internal Apple model identifier and its current Find My status. When victims click the supplied link, they are taken to an Apple-themed page that can display an animated map showing the reported location of the device.
The platform’s AI voice functionality is one of its most notable features. SOCRadar found 200 voice call records and 55 transcripts associated with five AI voice personas hosted through the commercial voice platform Vapi. The personas used the same translated identity, presenting themselves as Alice from Apple Support in English, Spanish and Portuguese.
The recovered calls took place between August 31, 2025, and May 30, 2026. Most of the calls, 179 out of 200, were made to numbers in Brazil. In one recovered conversation, the AI agent asked the victim to confirm ownership of the device before requesting the four- or six-digit passcode and repeating the numbers back for confirmation.
The conversation then claimed that someone had visited an Apple Store to remove the device’s Activation Lock. The victim was subsequently asked whether they had received a recovery link by text message.
Despite the large number of calls, the available records do not show how many victims actually handed over their passcodes, Apple IDs or two-factor authentication codes. Of the 200 recorded calls, 100 ended when the victim hung up, 48 resulted in silence timeouts, 24 were unanswered and 28 ended because of platform errors or busy signals.
SOCRadar estimated that the 200 calls cost the operators only $19.24, making each call roughly 9.6 cents. The low cost demonstrates why automated voice phishing could become attractive to criminals looking to conduct large-scale social engineering campaigns.
The researchers also discovered exposed logs through two relative file paths in the platform’s shared codebase. Because the paths resolved to the web root and did not require authentication, the files could be accessed over HTTP. According to SOCRadar, the same weakness was inherited by every deployment using that codebase.
Researchers identified 506 domains associated with the wider kit family. Of those, 30 separate installations were reachable across 42 domains, while 188 of the 506 domains were still live during the investigation.
AnonyMousKIT itself recorded 691 email send attempts between March and July 2026. Across the wider family of 30 backends, researchers counted 6,092 sends.
The email campaigns used several recurring techniques. The two most common subject lines were “Your device has been found” and “Alert.” Attackers used display names such as Apple, Find My, Apple Support and Apple Assistance to make the messages appear legitimate.
Most of the recorded emails were also routed through a single free Gmail account, while hundreds of messages included location information identifying cities such as Johannesburg, Abuja, Buenos Aires, Maputo and Mumbai. Victims were directed to tokenized links leading to fake support and device-recovery pages.
South Africa accounted for 1,735 of the 6,092 messages observed across the wider kit family. SOCRadar also found 64 AnonyMousKIT messages sent to non-consumer domains, including 27 South African government addresses. Researchers said the recipients appeared to have been selected because their devices were stolen rather than because of their government roles.
The platform also promotes several supposed device-unlocking tools. However, researchers believe these tools largely function as bait. Of the 6,092 devices targeted across the wider ecosystem, 5,649, or 92.7%, used Apple’s A12 chip or newer hardware.
Older techniques such as the checkm8 bootrom exploit only apply to devices using A5 through A11 chips. A newer public bootrom exploit for A12 and A13 devices was released in June 2026, but the research indicates that it requires physical possession of the device and does not recover the victim’s passcode or remove Activation Lock.
The main innovation in AnonyMousKIT therefore appears to be its combination of automated infrastructure and AI-powered social engineering rather than a technical method for directly breaking Apple’s Activation Lock.
The campaign reflects a broader shift toward criminal services that use commercial AI voice technology to automate convincing phone-based scams. Researchers have previously documented other phishing and vishing platforms incorporating commercial text-to-speech and AI-driven calling capabilities.
Infoblox Threat Intel also documented the same broader iPhone-unlocking ecosystem, identifying thousands of malicious domains connected to campaigns targeting stolen Apple devices.
For victims, the most important warning is that a message claiming an iPhone has been found does not mean the request is legitimate. Apple says it will never ask users to enter their password, device passcode or two-factor authentication code into a website, nor will legitimate support ask users to approve an unexpected two-factor authentication request.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Apple recommends forwarding suspicious Apple-branded emails and text messages to [email protected].
Security researchers also recommend protecting high-value Apple accounts with physical hardware security keys, which can provide stronger protection against real-time phishing attempts designed to intercept authentication codes.
AnonyMousKIT Uses AI Voice Agents to Target Stolen iPhones





