The security company SOCRadar has uncovered a criminal platform called AnonyMousKIT that unlocks stolen iPhones using AI voice agents. The software calls owners of lost devices, impersonates Apple Support, and extracts the device code from them over the phone. According to SOCRadar, researchers recorded 200 such calls between August 2025 and May 2026.
AI Voice Impersonates Apple Employee
According to the SOCRadar report, the fraudsters use the voice platform VAPI.ai in combination with the language models GPT-3.5-turbo and GPT-4o, as well as ElevenLabs’ voice synthesis. The AI presents itself as “Alice Dias, Apple Support” and introduces the call with the statement that the call is being recorded for quality and security purposes. It then confirms device ownership, explains that the phone was submitted to an Apple Store for unlocking, and requests the four- or six-digit device code. After that, it announces an SMS link and guides the user through entering a supposed unlock code before automatically hanging up. The researchers analyzed 55 call recordings from five voice profiles in English, Spanish, and Brazilian Portuguese. A conversation lasts an average of 22 seconds; 100 of the 200 recipients hung up immediately, and 48 others did not respond at all to the voice. In the case of CEO fraud via AI voice, criminals also rely on artificially generated voices to feign trust – however, with AnonyMousKIT, the scheme targets private phone owners rather than executives.
Platform Sells Access Like a Software Subscription
SOCRadar counts a total of 506 domains belonging to the AnonyMousKIT family and 168 sales pages that act as resellers. Customers purchase credits and pay different prices depending on the channel: An email costs 1.5 credits, a recorded call one credit, and an AI-assisted call two credits – totaling about ten US cents per AI call. The entire campaign with 200 calls thus cost the operators just under twenty dollars. SOCRadar describes the structure as “a small software company with criminal clientele,” complete with tiered subscriptions and its own processes for exchanging blocked infrastructure. According to SOCRadar, a single developer stands behind the platform, licensing the technology to a seller; this seller, in turn, rents access to several reseller brands. A trio of sales pages launched in late April 2026 within a second shared the same Gmail mailing service and the same pool of staff – an indication that a single actor operates several seemingly independent brands. A configuration error in the shared software also exposed more than 280,000 lines of email and WhatsApp logs, allowing SOCRadar to gain insight into the operation and reach of the platform.
Attacks Primarily Target Brazil and South Africa
In the email campaigns across all 30 analyzed backends, most of the 6092 messages were directed to South Africa, followed by Indonesia and Italy. In contrast, Brazil dominated the AI calls with 179 of the 200 documented conversations, while only one call went to the USA or Canada. In addition to email and phone, AnonyMousKIT also uses WhatsApp messages as a channel – similar to how WhatsApp itself is now experimenting with automated fraud detection to identify such messages. Among the targeted addresses, SOCRadar also found 27 email accounts belonging to South African authorities, as well as other university and corporate addresses. While primarily affecting individuals with stolen devices, a compromised Apple account can also provide access to iCloud backups, passwords stored in the keychain, and business email inboxes. The fraudsters focus on newer iPhone generations: Of the 6092 recorded devices, more than 5600 were running on a chip from the A12 generation or newer. The number of 200 calls and the geographical distribution come solely from the server logs reviewed by SOCRadar and are independently unverified.
It will be crucial whether Apple tightens the activation lock technically before further imitators can copy the disclosed blueprints. The company’s fraud detection system Apple Trust Insights currently only analyzes messages on the device and is unlikely to be effective against a live phone call with a synthetic voice. SOCRadar recommends that victims reset their Apple password immediately in the event of a reported device theft and rely on hardware security keys instead of SMS codes.


