Security

AnonyMousKIT unlocks stolen iPhones via AI call

3 min read

TL;DR Too Long; Didn’t read

The security company SOCRadar uncovers a criminal platform with AnonyMousKIT that unlocks stolen iPhones via AI phone calls. An AI voice pretends to be an Apple employee on the phone and tricks victims into revealing their device code. Between August 2025 and May 2026, researchers recorded 200 such calls, primarily to Brazil. A single call costs the operators about ten US cents, according to SOCRadar.

A puppet with an Apple logo sticker as a face holds a telephone receiver to its ear and pulls a golden key from a mobile user's pocket, in the background lies an iPhone with a broken padlock symbol. Image generated with GPT Image 2

Key takeaways

  • SOCRadar uncovers the platform AnonyMousKIT, which fakes Apple support calls via AI voice.
  • Between August 2025 and May 2026, researchers counted 200 AI-assisted fraud calls.
  • 179 of the 200 calls targeted victims in Brazil, a call costs about ten cents.
  • AnonyMousKIT is organized with 506 domains and 168 sales pages like a regular software subscription.
  • The AI voice specifically asks for device code, Apple ID, and the unlock code sent via SMS.
  • Apple had not commented on the finding by the time of publication, according to The Hacker News.

The security company SOCRadar has uncovered a criminal platform called AnonyMousKIT that unlocks stolen iPhones using AI voice agents. The software calls owners of lost devices, impersonates Apple Support, and extracts the device code from them over the phone. According to SOCRadar, researchers recorded 200 such calls between August 2025 and May 2026.

AI Voice Impersonates Apple Employee

According to the SOCRadar report, the fraudsters use the voice platform VAPI.ai in combination with the language models GPT-3.5-turbo and GPT-4o, as well as ElevenLabs’ voice synthesis. The AI presents itself as “Alice Dias, Apple Support” and introduces the call with the statement that the call is being recorded for quality and security purposes. It then confirms device ownership, explains that the phone was submitted to an Apple Store for unlocking, and requests the four- or six-digit device code. After that, it announces an SMS link and guides the user through entering a supposed unlock code before automatically hanging up. The researchers analyzed 55 call recordings from five voice profiles in English, Spanish, and Brazilian Portuguese. A conversation lasts an average of 22 seconds; 100 of the 200 recipients hung up immediately, and 48 others did not respond at all to the voice. In the case of CEO fraud via AI voice, criminals also rely on artificially generated voices to feign trust – however, with AnonyMousKIT, the scheme targets private phone owners rather than executives.

Platform Sells Access Like a Software Subscription

SOCRadar counts a total of 506 domains belonging to the AnonyMousKIT family and 168 sales pages that act as resellers. Customers purchase credits and pay different prices depending on the channel: An email costs 1.5 credits, a recorded call one credit, and an AI-assisted call two credits – totaling about ten US cents per AI call. The entire campaign with 200 calls thus cost the operators just under twenty dollars. SOCRadar describes the structure as “a small software company with criminal clientele,” complete with tiered subscriptions and its own processes for exchanging blocked infrastructure. According to SOCRadar, a single developer stands behind the platform, licensing the technology to a seller; this seller, in turn, rents access to several reseller brands. A trio of sales pages launched in late April 2026 within a second shared the same Gmail mailing service and the same pool of staff – an indication that a single actor operates several seemingly independent brands. A configuration error in the shared software also exposed more than 280,000 lines of email and WhatsApp logs, allowing SOCRadar to gain insight into the operation and reach of the platform.

Attacks Primarily Target Brazil and South Africa

In the email campaigns across all 30 analyzed backends, most of the 6092 messages were directed to South Africa, followed by Indonesia and Italy. In contrast, Brazil dominated the AI calls with 179 of the 200 documented conversations, while only one call went to the USA or Canada. In addition to email and phone, AnonyMousKIT also uses WhatsApp messages as a channel – similar to how WhatsApp itself is now experimenting with automated fraud detection to identify such messages. Among the targeted addresses, SOCRadar also found 27 email accounts belonging to South African authorities, as well as other university and corporate addresses. While primarily affecting individuals with stolen devices, a compromised Apple account can also provide access to iCloud backups, passwords stored in the keychain, and business email inboxes. The fraudsters focus on newer iPhone generations: Of the 6092 recorded devices, more than 5600 were running on a chip from the A12 generation or newer. The number of 200 calls and the geographical distribution come solely from the server logs reviewed by SOCRadar and are independently unverified.

It will be crucial whether Apple tightens the activation lock technically before further imitators can copy the disclosed blueprints. The company’s fraud detection system Apple Trust Insights currently only analyzes messages on the device and is unlikely to be effective against a live phone call with a synthetic voice. SOCRadar recommends that victims reset their Apple password immediately in the event of a reported device theft and rely on hardware security keys instead of SMS codes.

Frequently asked questions

What exactly is AnonyMousKIT?

A phishing-as-a-service platform active since February 2024 that provides criminals with tools to unlock stolen iPhones for a fee, supplemented by AI voice agents for fraud calls.

How do I recognize such a fraud call?

Real Apple support never asks for the device code, password, or an unlock code sent via SMS over the phone; if in doubt, one should hang up and contact through the official Apple website.

Is my iPhone affected if it has not been stolen?

No, the fraudsters specifically target individuals whose device is reported as lost or stolen according to Apple's Find My feature.

What is Apple doing about this scheme?

Apple had not commented on the report's publication; the in-house framework Apple Trust Insights currently only detects fraud in text messages, not in phone calls.

How much do the criminals earn with the platform?

SOCRadar does not provide revenue figures but documents tiered pricing per message and call as well as a system of subscriptions and reseller commissions.

Sources (3)
  1. SOCRadar: Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
  2. The Hacker News: Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
  3. BleepingComputer: AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog