Detect Deepfakesby Resemble AI
Deepfake case study · Audio

AnonyMousKIT phishing-as-a-service uses AI voice calls…

The AnonyMousKIT phishing-as-a-service platform utilizes AI voice agents to impersonate Apple Support and harvest credentials from victims of stolen iPhones

Incident date
Jan 2024
Target
Apple Support
Updated Aug 26, 2026 · 1 min read

The AnonyMousKIT phishing-as-a-service platform is automating the theft of Apple ID credentials by impersonating Apple Support to bypass Activation Lock on stolen devices. Researchers at SOCRadar discovered that this service enables low-skill thieves to monetize stolen iPhones by harvesting the passcodes and security codes required to unlock them.

What happened

The platform operates as a sophisticated software business, providing subscribers with a dashboard to input a stolen device's serial number or IMEI to retrieve live Find My status. Once targeted, victims are contacted via email, SMS, WhatsApp, or automated voice calls. The platform features five AI voice-agent personas configured in English, Spanish, and Brazilian Portuguese, with three agents using the name "Alice Dias, Apple Support."

During these calls, the AI agent follows a predefined conversation flow, first confirming device ownership and tricking the victim into dictating their four- or six-digit passcode. The agent then spins a narrative claiming that someone attempted to unlock the phone at an Apple store, necessitating the victim to enter a security link sent via text. By guiding the victim through the input of this code, the platform successfully captures the credentials needed to remove Apple’s Activation Lock. Researchers recovered 200 call logs and 55 transcripts, noting that 179 of these calls targeted victims in Brazil. Despite the use of advanced AI for social engineering, basic coding errors within the platform's 506 domains exposed production logs and operator rosters. The operation is structured in tiers, consisting of a developer, buyers who license the platform, and operators who execute the phishing attacks. As of the investigation's conclusion, the platform remained active, continuing to exploit the gap between stolen hardware and the credentials required for resale.

Sources