Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
AnonyMousKIT is a phishing-as-a-service (PhaaS) platform that uses AI voice agents to call owners of stolen Apple devices, posing as Apple Support to extract device passcodes, Apple ID credentials, and 2FA codes to bypass Activation Lock. The platform operates on a credit-metered subscription model with published pricing across five attack channels: email, SMS, WhatsApp, recorded voice calls, and AI voice agents, with the latter costing 2 credits per call. SOCRadar recovered 200 AI voice call re
Analysis
TL;DR
- AnonyMousKIT is a phishing-as-a-service (PhaaS) platform that uses AI voice agents to call owners of stolen Apple devices, posing as Apple Support to extract device passcodes, Apple ID credentials, and 2FA codes to bypass Activation Lock.
- The platform operates on a credit-metered subscription model with published pricing across five attack channels: email, SMS, WhatsApp, recorded voice calls, and AI voice agents, with the latter costing 2 credits per call.
- SOCRadar recovered 200 AI voice call records and 55 transcripts showing calls primarily targeting Brazilian numbers, with each call costing approximately 9.6 cents and using a persona named "Alice from Apple Support" across English, Spanish, and Portuguese.
- The attack lures leverage real-time device data including Apple model identifiers and live Find My status, directing victims to Apple-branded capture pages with animated location maps to increase credibility.
- While the platform also advertises technical unlock tools, 92.7% of targeted devices run A12 silicon or newer, which are immune to the checkm8 bootrom exploit, suggesting the technical tools serve primarily as bait while social engineering remains the primary attack vector.
Why It Matters
This represents a significant escalation in AI-powered social engineering, demonstrating how commercially available voice AI platforms like Vapi can be weaponized at scale for credential theft. The PhaaS model lowers the barrier to entry for cybercriminals, turning what was once a technically demanding attack into an affordable, subscription-based service that can be deployed against thousands of victims with minimal expertise.
Technical Details
- AnonyMousKIT operates as a credit-based platform with tiered pricing: email at 1.50 credits, SMS per sender ID, WhatsApp, recorded voice calls at 1 credit, and AI voice agents at 2 credits, with infrastructure replacement protocols and customer support typical of legitimate SaaS products.
- The AI voice channel was built on the commercial voice platform Vapi, with five configured personas all carrying the translated identity of "Alice from Apple Support" across English, Spanish, and Portuguese, running between August 31, 2025 and May 30, 2026.
- Lures incorporate device-specific intelligence including internal Apple model identifiers and live Find My status pulled directly from stolen devices, with victim-facing capture pages served from tokenized /help?TOKEN URLs displaying animated maps of reported device locations.
- A scan of 506 kit-family domains identified 30 distinct installations across 42 domains with 188 live instances, while the specific AnonyMousKIT installation logged 691 send attempts between March and July 2026, with logs accessible via unauthenticated HTTP paths in the shared codebase.
- The platform's advertised unlock tools are largely ineffective against modern devices: checkm8 targets only A5-A11 chips, and while a public A12/A13 bootrom exploit was released on June 18, 2026, it requires physical possession and DFU mode without compromising the Secure Enclave or removing Activation Lock.
Industry Insight
- The commoditization of AI vishing through platforms like Vapi demonstrates that legitimate voice AI infrastructure is being rapidly repurposed for large-scale social engineering, prompting the need for voice authentication protocols and call-origin verification systems to distinguish legitimate support calls from AI-driven phishing.
- The PhaaS business model—with credit bundles, published pricing, and customer support—mirrors legitimate software commerce, suggesting that enforcement should target the payment and infrastructure layer rather than individual threat actors, while device manufacturers should consider hardware-level protections against remote credential harvesting.
- The geographic targeting patterns (179 of 200 calls to Brazil, heavy South African email presence including government addresses) indicate that threat operators are concentrating resources on regions with high device theft rates and potentially weaker reporting infrastructure, suggesting that regional threat intelligence sharing and localized user education campaigns should be prioritized.
Disclaimer: The above content is generated by AI and is for reference only.