Skip to content
feed: live
>_0dayNews
mobile

AnonyMousKIT: AI Voice Agents Phish iPhone Unlock Codes

A new PhaaS platform, AnonyMousKIT, deploys AI voice agents to call iPhone owners and extract the codes needed to disable Activation Lock on stolen devices.

fuseMarisol "Fuse" Delgado·Published ·2 min read

A newly documented phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the most labor-intensive step of iPhone theft: getting the victim to hand over the credentials that disable Activation Lock. Instead of relying on human callers, the service deploys voice AI agents to do the social engineering at scale, according to BleepingComputer.

What Activation Lock is, and why thieves need to break it

Activation Lock ties an iPhone to its owner’s Apple ID the moment Find My is enabled — which it is by default. A stolen device that isn’t unlocked from the previous owner’s account is effectively unsellable: it prompts for Apple ID credentials on every setup attempt and can’t be provisioned for a new user. That makes the lock a real economic barrier for phone theft rings.

The problem for thieves has always been extraction — getting the victim’s Apple ID password, device passcode, or recovery codes requires either brute force (not viable given Apple’s lockout policies) or social engineering the owner directly. AnonyMousKIT sells a turnkey solution to that second problem: automated voice calls that impersonate Apple, walk the victim through a scripted flow, and collect whatever credential is needed to complete the unlock.

PhaaS means lower skill floor, higher volume

The PhaaS model is why this matters beyond the specific tool. AnonyMousKIT isn’t a sophisticated nation-state capability — it’s a rental platform. Subscribers get access to the AI voice infrastructure and the phishing flows without needing to build or run any of it themselves. The same industrialization that made email phishing accessible to low-skill operators is now reaching vishing (voice phishing).

This follows a pattern that’s been building in the mobile threat landscape: the ToxicPanda campaign used store permission tricks; banking trojans have layered overlay attacks. AnonyMousKIT points at a different attack surface — not the device’s software, but the owner’s voice channel.

What to do

For iPhone users:

  • Apple will never call you to verify your passcode, Apple ID password, or recovery key. Hang up on any call claiming to be Apple that asks for these. Full stop.
  • Enable Stolen Device Protection (Settings → Face ID & Passcode → Stolen Device Protection). When enabled away from familiar locations, it requires biometric authentication and imposes a one-hour security delay before sensitive account changes — buying time if a thief does obtain your passcode through social engineering.
  • If your device is stolen: change your Apple ID password from a trusted device immediately, before a caller can convince you not to.

For security teams and IT:

Vishing at scale via AI is now a commodity service. AnonyMousKIT’s approach to Activation Lock is a proof of concept for any credential-recovery flow that depends on a phone call to authenticate. MDM-managed device fleets should confirm Find My and Activation Lock are enforced via MDM policy so that device unlocking cannot be initiated without IT-side approval regardless of what a user provides to a caller.

Apple’s recent iOS patch cycle has been aggressive — 27 and 108 vulnerabilities addressed in consecutive rounds — but software patches don’t help when the attack vector is a phone call. The defensive layer here is user awareness and Stolen Device Protection, not a software update.

Found this useful? Share it.