Cybersecurity researchers have uncovered a phishing-as-a-service platform that uses rented AI voice agents to impersonate Apple Support and trick theft victims into surrendering device passcodes. SOCRadar Threat Research Unit disclosed Monday that the platform, which it tracks as AnonyMousKIT, operates on a credit-metered basis and targets owners of recently lost or stolen Apple devices across five channels: email at 1.50 credits, SMS priced per sender ID, WhatsApp, recorded voice calls at 1 credit, and AI voice agents at 2 credits. The phishing campaign aims to bypass Apple's Activation Lock, a security feature introduced in iOS 7 that ties hardware to a specific Apple ID and renders stolen handsets unusable until the owner's account is removed.

The platform operates like a legitimate software business with a criminal customer base, featuring credit bundles, published pricing, tiered subscriptions, customer support, status tracking, and infrastructure replacement protocols. Researchers recovered 200 call records, 55 transcripts, and five configured personas from the operator's account with the commercial voice platform Vapi. All five personas carry the same translated identity—Alice from Apple Support—across English, Spanish, and Portuguese. The calls ran between August 31, 2025 and May 30, 2026, with 179 of the 200 placed to numbers in Brazil. Each call cost the operators about 9.6 cents, putting the total cost of the 200 calls at $19.24. Of those 200 attempts, 100 victims hung up, 48 ended in silence timeouts, 24 went unanswered, and 28 resulted in platform errors or busy signals.

SOCRadar's researchers found the logs through two bare relative file paths in the shared codebase that resolve to the web root and permit unauthenticated HTTP access, meaning every deployment of that codebase inherits the vulnerability. A scan of 506 kit-family domains identified 30 distinct installations reachable on 42 domains, with 188 of the 506 live. The AnonyMousKIT installation logged 691 send attempts between March and July 2026, compared with 6,092 across the 30 backends. The top two email subject lines were "Your device has been found," which appeared in 308 of 691 sends, and "Alert," which accounted for 157. A total of 627 of the logged sends relayed through a single free Gmail account, noreplyapple00000@gmail.com, and 678 of the 691 lures carried a location token naming a city such as Johannesburg, Abuja, Buenos Aires, Maputo, and Mumbai. South Africa accounts for 1,735 of the 6,092 family-wide sends, and 64 of AnonyMousKIT's own 691 sends reached non-consumer domains, including 27 to South African government addresses—recipients the report says were selected because their devices were stolen, not because of their roles.

The report describes the automated, LLM-driven voice vector as the platform's primary innovation. SOCRadar characterized AnonyMousKIT as "best understood not as a phishing kit but a small software business with a criminal customer base." Lures cite the handset's internal Apple model identifier and its live Find My status, both pulled from the stolen device itself, and victims who follow the link reach an Apple-branded capture page that renders an animated map of the handset's reported location. The phishing pages and calls request the 4- or 6-digit device passcode, then Apple ID credentials, and finally a live two-factor authentication code. Apple's own guidance states that the company never asks for a password, device passcode, or 2FA code to provide support. The report also notes that the four unlock tools offered on the panel serve as bait, because 5,649 of the 6,092 targeted devices—92.7%—run A12 silicon or newer, while the checkm8 bootrom exploit reaches only A5 through A11 chips.

The platform remained operational on the last day of SOCRadar's analysis, and the company said it continues to track AnonyMousKIT, its sibling storefronts, and the wider shared-codebase family. The researchers recommended moving high-value Apple IDs to physical hardware security keys, which they said completely mitigates the real-time 2FA interception that is the funnel's ultimate objective. Apple directs users to forward Apple-branded phishing email and text messages to reportphishing@apple.com, and in support documentation published on June 15, 2026, the company stated that it will never ask users to log in to any website, tap Accept in the two-factor authentication dialog, provide a password or device passcode, or enter a two-factor authentication code into any website. The development comes as German and U.S. law enforcement dismantled Kratos in July, pulling more than 200 servers offline, and Indonesian authorities arrested the man they say developed and ran it. The commercialization of AI voice technology has lowered the barrier to entry for social engineering attacks while simultaneously increasing their scalability and realism. As voice synthesis continues to improve, organizations and individuals will need to adopt authentication methods that assume human voices can be perfectly faked in real time.