AnonyMousKIT: Fake Apple Support AI Calls Strip Activation Lock From Stolen iPhones

SOCRadar's threat research unit disclosed AnonyMousKIT, a credit-metered phishing-as-a-service platform that rents AI voice agents to call owners of lost and stolen Apple devices, pose as Apple Support, and coax out the passcodes and 2FA codes that strip Activation Lock.

Share
Flat white line-art of a smartphone showing a fake Apple Support call, with a single red alert dot, on a saturated navy background.

Stolen-phone fraud used to be a craft. A thief needed the right contact, the right patter, and the patience to work a phone call. AnonyMousKIT turns that craft into a subscription. Researchers at the SOCRadar Threat Research Unit (STRU) disclosed the platform on August 25, describing a credit-metered phishing-as-a-service (PhaaS) operation built for one job: stripping Apple's Activation Lock from lost and stolen iPhones so they can be resold. Its standout feature is not a clever exploit. It is a rented AI voice agent that phones the theft victim, says it is Apple Support, and asks for the one thing a thief cannot brute-force: the device passcode.

Per SOCRadar's report, relayed by The Hacker News, AnonyMousKIT drives lures across five channels billed from a single victim record: email at 1.50 credits, SMS priced per sender ID, WhatsApp, a recorded voice call at 1 credit, and an AI voice agent at 2 credits. Every channel funnels toward the same three requests, in order: the 4- or 6-digit device passcode, then the Apple ID credentials, and finally a live two-factor authentication (2FA) code. That last code is the prize, because it is what lets an attacker complete the account changes that release the hardware.

A Phishing Business, Not a Phishing Kit

The most useful framing in SOCRadar's disclosure is that AnonyMousKIT behaves like a company. "AnonyMousKIT is best understood not as a phishing kit but a small software business with a criminal customer base," the researchers wrote, pointing to credit bundles, published pricing, tiered subscriptions, customer support, status tracking, and infrastructure-replacement protocols. The unlock "tools" advertised on the panel are mostly decoration. SOCRadar found that 5,649 of 6,092 targeted devices, or 92.7 percent, run Apple's A12 silicon or newer, which the current generation of technical bypasses cannot touch. When the hardware cannot be cracked, the owner becomes the target.

The buyers are resellers. SOCRadar identified three storefronts (i-Blocker, Key Unlock, and KG-KING) that launched in the same second on April 10, 2026, sharing the same email relay accounts, and assessed the pattern as one customer running three brands rather than three separate buyers. A scan of 506 domains in the kit family found 30 distinct installations across 42 domains, with 188 domains still live. AnonyMousKIT itself logged 691 send attempts between March and July 2026, against 6,092 across the wider shared-codebase family.

What makes the lure land is context. SOCRadar found that the messages cite the handset's internal Apple model identifier and its live Find My status, both pulled from the stolen device itself, and that victims who click reach an Apple-branded page showing an animated map of where the phone was "found." None of that requires breaking Apple's security. It requires the owner, rattled by a real theft, to trust a caller who already seems to know their specific device. That is the emotional lever, and it is why the defense has to be a flat rule rather than a judgment call in the moment.

Why AI Voice Is the Part That Matters

The vishing channel is what makes this scale. Older stolen-device scams needed a live person on the phone for every attempt. SOCRadar recovered 200 call records tied to the AI voice channel, made between August 31, 2025 and May 30, 2026, with five configured personas that all resolve to the same "Alice from Apple Support" identity across English, Spanish, and Portuguese. The researchers put the total cost of those 200 calls at $19.24, roughly 9.6 cents each. The voice platform named in the report is Vapi, a commercial service; SOCRadar says the personas were recovered from the operator's account there.

My read: the story is not "AI can sound like Apple." It is that AI voice removes the last human bottleneck from stolen-device fraud and prices a scam attempt at about a dime. A recorded call costs one credit; the AI agent costs two. For that premium, the operator gets a caller that never tires, speaks three languages, and runs the same script a thousand times without deviation. This is the same industrialization we have tracked in browser-based phishing, where Mirage2FA turned Microsoft 365 2FA bypass into a service hitting 4,500 firms and iAuthFlow planted attacker passkeys to survive password resets. AnonyMousKIT extends that logic to the phone line. It is an assessment, not a reported fact, but the direction is hard to miss: voice is becoming just another metered channel in the phishing supply chain.

What the Research Confirms, and What It Doesn’t

The disclosure is unusually detailed on infrastructure and unusually quiet on outcomes. SOCRadar reached the operator's logs through two exposed file paths in the shared codebase and reconstructed the records from there. But the report assigns all 200 calls to four results: 100 victims hung up, 48 were silence timeouts, 24 were no-answers, and 28 were platform errors or busy signals. It records no count of captured passcodes, Apple IDs, or 2FA codes for any channel. The volume and the machinery are documented; the success rate is not.

Several points remain unconfirmed and should be read as open questions rather than facts. SOCRadar names Vapi as the voice platform, but the report does not say whether the account was reported, and neither company has said publicly whether it is still running. The number of people who actually lost a device or an Apple ID to the operation is not established. The named storefronts are resellers, not the operator, whose identity is not disclosed. On the vendor side, The Hacker News reported that Apple did not respond to its request for comment by publication. And the calling was geographically lopsided: 179 of the 200 calls went to numbers in Brazil.

What Device Owners and MDM Teams Should Verify

The defense here is refreshingly concrete, because the attack depends on a person handing over a code. Apple's guidance, updated on June 15, 2026, is explicit that the company never asks you to provide your password, device passcode, or 2FA code, or to enter one on a website. Any call, text, or email that does is an attacker. The checklist below splits the response into what an individual should do and what an enterprise mobility team managing fleets of Apple hardware should confirm.

  STOLEN-DEVICE PHISHING: DEFENDER CHECKLIST
The attack needs the owner to read a code aloud. Every step here makes sure no one ever does.
THE ONE RULE
Apple never calls, texts, or emails to ask for your device passcode, Apple ID password, or 2FA code. Anyone who does is an attacker. Hang up, and do not tap Approve.
IF YOUR IPHONE IS LOST OR STOLEN (CONSUMER)
Mark it as lost in Find My, report the theft to Apple and local police, and change your Apple ID password from a device you trust. Ignore any “we found your device” call or link that follows.
FOR ENTERPRISE / MDM TEAMS
Confirm supervised and managed Apple devices keep Activation Lock enforced, verify Lost Mode workflows, and brief high-risk staff that a caller citing their exact device model or Find My status is a known lure, not proof of legitimacy.
CLOSE THE 2FA FUNNEL
Move high-value Apple IDs to FIDO2 hardware security keys. SOCRadar says this mitigates the real-time 2FA interception the whole scam depends on, because a key cannot be read aloud or typed into a fake page.
Source: SOCRadar Threat Research Unit; Apple Support guidance (June 15, 2026). Defender reference only.

Defender checklist for stolen-device phishing: the one rule, plus consumer, enterprise-MDM, and 2FA-hardening steps. Sources: SOCRadar STRU and Apple Support.

The Bottom Line for Defenders

Answer first: the single control that breaks this funnel is moving high-value Apple IDs onto phishing-resistant hardware security keys. SOCRadar says that step mitigates the real-time 2FA interception the funnel depends on, because a FIDO2 key cannot be read aloud to a caller or typed into a lookalike page. That is the same phishing-resistant authentication that blunts account-takeover attacks more broadly, where a stolen credential plus a phishable second factor is all an attacker needs. For everyone else, the rule is shorter than the scam: Apple will not call to ask for your passcode or your 2FA code, so when someone does, hang up and forward the message to reportphishing@apple.com.

The disclosure lands in a season of pressure on phishing-as-a-service operators. In July, German and U.S. law enforcement dismantled the Kratos phishing kit and pulled more than 200 servers offline. AnonyMousKIT, by contrast, was still running on the last day of SOCRadar's analysis, and the firm says it continues to track the platform and its sibling storefronts.

Primary Documents