AnonyMousKIT , a phishing-as-a-service (PhaaS) platform , uses AI voice agents to call victims of stolen Apple devices , impersonating Apple Support . The goal is to steal passwords and 2FA codes . According to The Hacker News, the platform was discovered by the SOCRadar Threat Research Unit (STRU) and is a fully commercialized criminal activity tool targeting owners of stolen iPhones.

AnonyMousKIT operates on a credit , with pricing per communication channel: email at 1.50 credits, recorded voice call at 1 credit and AI voice agent at 2 credits, while SMS is priced per sender ID. The platform uses a single victim file to trigger attacks via five channels: email, SMS, WhatsApp, recorded voice call and AI voice agent. This level of automation makes the platform particularly dangerous, as it drastically reduces the cost and effort required for a social engineering attack.
The goal of the attack is clear: to first extract the 4-digit or 6-digit passcode , then the Apple ID , and finally a live two-factor authentication (2FA). With these elements, attackers can bypass Activation Lock — the security feature introduced in iOS 7 that binds the device to a specific Apple ID, rendering it useless to the thief without the proper credentials.
See also: 26 FakeWallet apps discovered in Apple App Store
How AnonyMousKIT works: Technical details
AnonyMousKIT exploits Apple ’s Lost Mode workflow : when a stolen device is put into Lost Mode, the owner can provide contact information, which criminals use to target the victim with persuasive messages. The decoys list the device’s internal model ID and current Find My status , which are pulled from the stolen device itself. Victims who follow the link end up on a page that mimics Apple and displays an animated map of the device’s last known location .
The AI voice agent is the most documented after email, with 200 call logs, 55 transcripts , and 5 configured personas retrieved from the operator’s account on the commercial voice platform Vapi. All five personas carry the same identity: “Alice from Apple Support,”in three languages—English, Spanish, and Portuguese. This shows that the use of multilingual synthetic voice is no longer just a theoretical proof of concept, but an operational fraud tool.
The calls were made between August 31, 2025 , and May 30, 2026, with 179 of the 200 calls being made to numbers in Brazil. In the recovered transcripts, the agent asks the victim to confirm ownership, then asks for the 4-digit or 6-digit passcode and repeats it for confirmation. It then explains that someone visited an Apple Store to remove Activation Lock and asks if a recovery link has arrived via SMS.

AnonyMousKIT: Enterprise scale and infrastructure vulnerabilities
The logs reached SOCRadar via two exposed relative file paths in the shared code, which resolve to the server root and allow unauthorized HTTP. Every installation of this codebase inherits this vulnerability. A scan of 506 kit-family domains found 30 distinct installations accessible on 42 domains, with 188 of the 506 active.
See also: Apple Store: 'Early preview' of AI shopping assistant
Three online stores — i-Blocker, Key Unlock , and KG-KING — were launched at the same second on April 10, 2026, using the same Gmail relay. SOCRadar assessed this pattern as one buyer managing three brands, rather than three separate customers. In terms of email decoys, the two most common subject lines were “Your device has been found” (308 out of 691) and “Alert” (157), while sender names included Apple, Find My, Apple Support , and Apple Assistance. Notably, 627 of the recorded shipments were routed through a single free Gmail.
How to protect yourself from AnonyMousKIT-type attacks
Apple has made it clear that it never asks for your password, device passcode, or 2FA code to provide support. If you receive a call, email, or message claiming to be from Apple Support and asking for such information, it’s phishing . The most effective defense is behavioral: never share your device passcode, Apple ID password, or 2FA codes with anyone who contacts you by phone, SMS, email, or WhatsApp .

If your device is lost or stolen, immediately put it in Lost Mode , change your Apple Account password from a secure device, and watch for phishing attempts that claim to be stolen. Turn on Stolen Device Protection on supported iPhones , which significantly increases the difficulty of getting your account back after it's stolen. Use a strong password and biometrics, and make sure two-factor authentication is enabled on your account. If you suspect a phishing attack, report it to Apple.
See also: Apple Event 2026: iPhone 18 Pro Max coming on September 9 with A20 Pro and variable aperture
The AnonyMousKIT incident is a stark reminder that physical device theft is no longer an isolated event, but the beginning of a multi-channel social engineering campaign. Security teams and ordinary users should treat any communication following a device theft with extreme suspicion, no matter how convincing the identity of the caller or sender appears.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
