AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
Description
AnonyMousKIT is a phishing-as-a-service platform that uses voice AI agents to trick victims into revealing iPhone passcodes and Apple account credentials. The service automates the retrieval of unlocking codes to bypass Apple's Activation Lock, enabling thieves to unlock stolen iPhones and access sensitive data. It impersonates Apple through phishing emails and calls, directing victims to fake Apple pages to harvest passcodes and two-factor authentication codes. The platform has been active since early 2024 and operates a large ecosystem with hundreds of reseller storefronts. Most attacks target Brazil, but campaigns have a global footprint including South Africa, Indonesia, Italy, India, and Kenya. Compromised Apple IDs can expose iCloud backups, Keychain passwords, and corporate data. The service lowers the value of stolen devices by enabling full unlocking and data access.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
AnonyMousKIT is a phishing-as-a-service (PhaaS) platform that leverages voice AI agents to conduct social engineering attacks aimed at retrieving passcodes and Apple ID credentials from victims. It exploits Apple's Activation Lock feature by impersonating Apple support and sending phishing messages that appear legitimate, including accurate device details. Victims are contacted via email, SMS, WhatsApp, or phone calls, where AI personas engage them to disclose passcodes and two-factor authentication codes. The platform has been active since early 2024, with a sprawling infrastructure of over 500 domains and 168 reseller storefronts. Researchers documented 200 calls with AI agents between August 2025 and May 2026, mostly targeting Brazil. Successful credential theft allows attackers to unlock stolen iPhones, disable Activation Lock, access iCloud backups, and harvest sensitive personal and corporate information. The campaign has a global reach but is concentrated in specific countries. The platform operates at low cost per call and uses automation to scale attacks.
Potential Impact
The threat enables attackers to bypass Apple's Activation Lock by phishing victims for passcodes and Apple ID credentials, allowing stolen iPhones to be unlocked and resold at higher value. Compromised Apple IDs expose iCloud backups, Keychain passwords, and potentially corporate data stored on Apple devices. The phishing campaigns have a global footprint with concentration in Brazil and other countries. The platform's automation and use of voice AI agents increase the scale and efficiency of attacks. This results in significant privacy and financial risks for victims, including loss of device control and exposure of sensitive personal and corporate information.
Defensive Guidance
No official patch or fix applies as this is a phishing campaign rather than a software vulnerability. Users should be aware of phishing attempts impersonating Apple support and avoid providing passcodes, Apple ID credentials, or two-factor authentication codes in response to unsolicited communications. Organizations should educate users about this specific phishing technique involving voice AI agents and verify any device-related alerts directly through official Apple channels. Monitoring for suspicious activity on Apple accounts and enabling strong authentication methods can help reduce risk. Since this is a service operated outside of Apple, remediation depends on user vigilance and incident response to compromised accounts.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a8dfcfbacd9273b49b01bc7
Added to database: 08/25/2026, 20:37:15 UTC
Last enriched: 09/10/2026, 12:53:51 UTC
Last updated: 10/02/2026, 14:25:59 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.