AI Security AI安全 3h ago Updated 47m ago 更新于 47分钟前 45

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes 假冒苹果客服的AI语音电话针对被盗设备机主骗取密码和双重验证码

AnonyMousKIT is a phishing-as-a-service (PhaaS) platform that uses AI voice agents to call owners of stolen Apple devices, posing as Apple Support to extract device passcodes, Apple ID credentials, and 2FA codes to bypass Activation Lock. The platform operates on a credit-metered subscription model with published pricing across five attack channels: email, SMS, WhatsApp, recorded voice calls, and AI voice agents, with the latter costing 2 credits per call. SOCRadar recovered 200 AI voice call re AnonyMousKIT是首个规模化AI语音钓鱼平台,利用LLM驱动语音代理冒充Apple Support骗取设备密码和2FA验证码 攻击成本极低:200次AI语音通话仅花费19.24美元(约9.6美分/次),通过商业语音平台Vapi实现 目标锁定A12及以上芯片设备(占92.7%),技术绕过已失效但社会工程仍有效 支持5种语言(英/西/葡等)和5个攻击渠道(邮件/SMS/WhatsApp/录音电话/AI语音) 攻击者利用被盗设备的Find My位置和型号信息增强钓鱼可信度

65
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • AnonyMousKIT is a phishing-as-a-service (PhaaS) platform that uses AI voice agents to call owners of stolen Apple devices, posing as Apple Support to extract device passcodes, Apple ID credentials, and 2FA codes to bypass Activation Lock.
  • The platform operates on a credit-metered subscription model with published pricing across five attack channels: email, SMS, WhatsApp, recorded voice calls, and AI voice agents, with the latter costing 2 credits per call.
  • SOCRadar recovered 200 AI voice call records and 55 transcripts showing calls primarily targeting Brazilian numbers, with each call costing approximately 9.6 cents and using a persona named "Alice from Apple Support" across English, Spanish, and Portuguese.
  • The attack lures leverage real-time device data including Apple model identifiers and live Find My status, directing victims to Apple-branded capture pages with animated location maps to increase credibility.
  • While the platform also advertises technical unlock tools, 92.7% of targeted devices run A12 silicon or newer, which are immune to the checkm8 bootrom exploit, suggesting the technical tools serve primarily as bait while social engineering remains the primary attack vector.

Why It Matters

This represents a significant escalation in AI-powered social engineering, demonstrating how commercially available voice AI platforms like Vapi can be weaponized at scale for credential theft. The PhaaS model lowers the barrier to entry for cybercriminals, turning what was once a technically demanding attack into an affordable, subscription-based service that can be deployed against thousands of victims with minimal expertise.

Technical Details

  • AnonyMousKIT operates as a credit-based platform with tiered pricing: email at 1.50 credits, SMS per sender ID, WhatsApp, recorded voice calls at 1 credit, and AI voice agents at 2 credits, with infrastructure replacement protocols and customer support typical of legitimate SaaS products.
  • The AI voice channel was built on the commercial voice platform Vapi, with five configured personas all carrying the translated identity of "Alice from Apple Support" across English, Spanish, and Portuguese, running between August 31, 2025 and May 30, 2026.
  • Lures incorporate device-specific intelligence including internal Apple model identifiers and live Find My status pulled directly from stolen devices, with victim-facing capture pages served from tokenized /help?TOKEN URLs displaying animated maps of reported device locations.
  • A scan of 506 kit-family domains identified 30 distinct installations across 42 domains with 188 live instances, while the specific AnonyMousKIT installation logged 691 send attempts between March and July 2026, with logs accessible via unauthenticated HTTP paths in the shared codebase.
  • The platform's advertised unlock tools are largely ineffective against modern devices: checkm8 targets only A5-A11 chips, and while a public A12/A13 bootrom exploit was released on June 18, 2026, it requires physical possession and DFU mode without compromising the Secure Enclave or removing Activation Lock.

Industry Insight

  • The commoditization of AI vishing through platforms like Vapi demonstrates that legitimate voice AI infrastructure is being rapidly repurposed for large-scale social engineering, prompting the need for voice authentication protocols and call-origin verification systems to distinguish legitimate support calls from AI-driven phishing.
  • The PhaaS business model—with credit bundles, published pricing, and customer support—mirrors legitimate software commerce, suggesting that enforcement should target the payment and infrastructure layer rather than individual threat actors, while device manufacturers should consider hardware-level protections against remote credential harvesting.
  • The geographic targeting patterns (179 of 200 calls to Brazil, heavy South African email presence including government addresses) indicate that threat operators are concentrating resources on regions with high device theft rates and potentially weaker reporting infrastructure, suggesting that regional threat intelligence sharing and localized user education campaigns should be prioritized.

TL;DR

  • AnonyMousKIT是首个规模化AI语音钓鱼平台,利用LLM驱动语音代理冒充Apple Support骗取设备密码和2FA验证码
  • 攻击成本极低:200次AI语音通话仅花费19.24美元(约9.6美分/次),通过商业语音平台Vapi实现
  • 目标锁定A12及以上芯片设备(占92.7%),技术绕过已失效但社会工程仍有效
  • 支持5种语言(英/西/葡等)和5个攻击渠道(邮件/SMS/WhatsApp/录音电话/AI语音)
  • 攻击者利用被盗设备的Find My位置和型号信息增强钓鱼可信度

为什么值得看

本文揭示了AI语音钓鱼技术从概念验证走向规模化商业化的关键转折,展示了攻击者如何将LLM语音代理与PhaaS模式结合,以极低成本实现针对特定硬件的安全绕过。对AI安全从业者和设备制造商而言,这标志着社会工程攻击进入自动化、个性化新阶段,传统安全边界正在被AI驱动的语音交互重新定义。

技术解析

  • 架构设计:平台采用信用计量系统,AI语音代理(2 credits/次)作为核心创新点,通过Vapi商业语音平台实现。攻击者使用5个预设人格(均为"Apple Support的Alice"),支持英语、西班牙语和葡萄牙语,通话流程标准化:确认所有权→获取4/6位设备密码→读取Apple ID凭证→请求2FA验证码。
  • 目标设备分析:92.7%的目标设备运行A12及以上芯片,checkm8 bootrom漏洞(仅支持A5-A11)已失效,2026年6月发布的A12/A13漏洞需物理接触和DFU模式,无法直接移除Activation Lock。
  • 钓鱼链路:攻击者从被盗设备提取内部型号标识和Find My实时状态,生成个性化钓鱼邮件(主题如"Your device has been found"),受害者点击后进入Apple品牌页面显示动画地图,最终引导至凭证收集页面。
  • 基础设施:627封钓鱼邮件通过单一免费Gmail账户(noreplyapple00000@gmail.com)发送,678封邮件包含城市定位令牌(约翰内斯堡、阿布贾等),30个独立部署实例分布在42个域名上。

行业启示

  • AI语音钓鱼将成为新型规模化攻击向量:当LLM语音代理成本降至10美分/次且支持多语言实时交互时,传统电话钓鱼的社会工程学优势将被技术自动化取代,安全厂商需将AI语音检测纳入威胁情报体系。
  • 设备安全架构需重新评估:Activation Lock等硬件绑定机制虽能抵御技术绕过,但面对AI驱动的精准社会工程仍显脆弱,建议厂商在用户教育中强化"Apple永不主动索要密码"的警示,并探索生物识别替代密码验证。
  • PhaaS平台监管面临新挑战:AnonyMousKIT展现的"信用计量+多渠道+订阅制"商业模式,使攻击基础设施商品化程度接近合法SaaS服务,需要建立针对AI钓鱼工具链的专项监测和快速响应机制。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Speech 语音 Agent Agent LLM 大模型