Detect Deepfakesby Resemble AI
Deepfake case study · Audio

Fake Apple Support AI Calls Target Stolen-Device Owners…

A phishing-as-a-service platform called AnonyMousKIT uses AI voice agents to impersonate Apple Support and trick theft victims into revealing device…

Incident date
Aug 2025
Target
Apple device owners
Updated Aug 26, 2026 · 2 min read

What happened

Cybersecurity researchers at SOCRadar have uncovered a phishing-as-a-service (PhaaS) platform known as AnonyMousKIT, which leverages AI voice agents to target owners of recently lost or stolen Apple devices. The platform operates as a credit-metered software business, providing criminal users with tools to strip Apple's Activation Lock from stolen hardware. By using rented AI voice agents, attackers pose as Apple Support representatives to contact victims, requesting their 4- or 6-digit device passcodes, Apple ID credentials, and live two-factor authentication (2FA) codes.

The platform utilizes a variety of lures, including emails, SMS, WhatsApp, and recorded or AI-driven voice calls. The AI voice agent, which the researchers identified as the platform's primary innovation, was documented using five configured personas under the identity of Alice from Apple Support across English, Spanish, and Portuguese. Between August 31, 2025, and May 30, 2026, the researchers tracked 200 AI voice calls, with the vast majority directed toward numbers in Brazil. These lures often cite specific details pulled from the stolen device, such as its internal model identifier and its live Find My status, to increase credibility. Once a victim engages, they are directed to an Apple-branded capture page that displays an animated map of the handset's reported location.

While the platform offers various unlock tools, researchers noted that these are largely bait, as the majority of targeted devices use modern silicon that is not vulnerable to the older bootrom exploits provided by the kit. The ultimate objective of these social engineering efforts is the interception of 2FA codes to compromise the victim's Apple ID. Apple explicitly states that the company never requests passwords, device passcodes, or 2FA codes to provide support. To mitigate these risks, experts recommend that users protect high-value Apple IDs with physical hardware security keys, which effectively prevent the real-time interception of authentication codes.

Sources