AI-Powered Phishing Platform Automates Theft of Apple Device Credentials
Researchers uncover AnonyMousKIT, a professionalized service using AI voice agents to bypass Apple's Activation Lock.
Cybersecurity researchers at SOCRadar have discovered AnonyMousKIT, a sophisticated Phishing-as-a-Service (PhaaS) platform designed to strip Activation Locks from stolen Apple devices. The platform enables criminals to automate the theft of passcodes and Apple ID credentials through a combination of AI-driven social engineering and multi-channel lures.
AnonyMousKIT operates as a credit-metered business, providing thieves with a scalable infrastructure to target victims via email, SMS, WhatsApp, and AI voice agents. These voice agents, powered by the commercial Vapi platform, utilize personas such as "Alice from Apple Support" to conduct high-trust social engineering in English, Spanish, and Portuguese. To increase the credibility of the scam, the platform generates highly targeted lures that incorporate the stolen device's internal Apple model identifier and its live "Find My" status. A scan of 506 kit-family domains identified 30 distinct installations of the platform.
The Shift to Social Engineering
Apple's Activation Lock, introduced in iOS 7, serves as a critical security barrier that prevents stolen devices from being repurposed without the original owner's credentials. As technical bypasses for modern A12+ silicon have become largely obsolete, criminal organizations have shifted their focus toward social engineering. AnonyMousKIT represents the professionalization of this shift, transforming what was once a manual process into a scalable, commercialized service for device thieves.
Implications for Device Security
The integration of LLM-driven AI voice agents allows attackers to automate high-trust interactions at a very low cost, significantly increasing the success rate of stripping Activation Locks. This evolution makes phone theft more profitable and demonstrates how commercial AI voice platforms can be weaponized to bypass multi-factor authentication (MFA) through real-time interception of 2FA codes. SOCRadar noted that AnonyMousKIT is best understood not as a simple phishing kit, but as a small software business catering to a criminal customer base.
Future Outlook
As AI-driven social engineering becomes more accessible, the risk to device owners increases. By combining technical tooling and social engineering, thieves now have a way to unlock devices at scale. Security experts are now monitoring whether similar PhaaS models emerge for other ecosystem locks and whether commercial AI providers implement stricter safeguards to prevent the deployment of fraudulent support personas.