VMTech
Discuss a project

AI Voice Calls Impersonate Apple Support to Defeat Activation Lock

AI Voice Calls Impersonate Apple Support to Defeat Activation Lock

SOCRadar Threat Research Unit has detailed a phishing-as-a-service platform called AnonyMousKIT that targets owners of recently lost or stolen Apple devices. The service uses rented AI voice agents posing as Apple Support and attempts to obtain a device's four- or six-digit passcode, Apple ID credentials and a live two-factor authentication code.

The operation offers five delivery channels from a single victim record: email, SMS, WhatsApp, recorded calls and AI voice calls. SOCRadar recovered 200 call records, 55 transcripts and five configured personas from an operator account on the commercial voice platform Vapi. The researchers calculated the calls cost $19.24 in total, or about 9.6 cents each.

Calls exploit the urgency around stolen devices

All five voice personas used the translated identity “Alice from Apple Support” in English, Spanish and Portuguese. Calls recorded between August 31, 2025 and May 30, 2026 were heavily concentrated in Brazil, which received 179 of the 200 calls.

A recovered transcript shows the agent first asking a victim to confirm device ownership, then requesting the device passcode and reading the digits back for confirmation. The caller says someone has visited an Apple Store to remove Activation Lock and asks whether a recovery link has arrived by text message.

Activation Lock, introduced with iOS 7, binds hardware to an Apple ID and leaves a stolen device unusable until the owner removes it from the account. The kit's lures cite the internal Apple model identifier and live Find My status obtained from the stolen handset. Its Apple-branded capture pages display an animated map that purports to show the device's location.

A commercialised phishing operation

SOCRadar describes AnonyMousKIT as a criminal software business rather than a simple phishing kit. It uses credits and published prices: email costs 1.50 credits, recorded calls cost one credit and an AI voice agent costs two credits. The platform also includes subscriptions, customer support, status tracking and infrastructure replacement procedures.

The recovered call outcomes do not establish how many victims supplied credentials. They list 100 hang-ups, 48 silence timeouts, 24 no-answers and 28 platform errors or busy signals. No capture count for passcodes, Apple IDs or two-factor codes was reported across the five delivery channels.

Researchers found that two relative file paths in the shared codebase exposed logs through unauthenticated HTTP access. A scan of 506 kit-family domains identified 30 installations reachable on 42 domains, while 188 of the 506 domains were live. Across those 30 back ends, the researchers logged 6,092 send attempts; the AnonyMousKIT installation accounted for 691 between March and July 2026.

What Apple device users and organisations should do

Apple states that it will never ask users to provide a password, device passcode or two-factor authentication code for support. It also says it will not ask users to log in to a website or tap Accept in a two-factor authentication prompt. Apple directs recipients of Apple-branded phishing emails and texts to forward them to reportphishing@apple.com.

SOCRadar recommends physical hardware security keys for high-value Apple IDs, stating that they mitigate the real-time two-factor interception sought by this funnel. For organisations, the practical implication is to include stolen-device vishing in incident procedures: employees should treat unsolicited recovery calls as hostile and provide no passcode, account credential or authentication code.

#cybersecurity#phishing#applesecurity#vishing
Open analytics
On the site 0 views
min read 4 26.08.2026
Instagram

AI Voice Calls Impersonate Apple Support to Defeat Activation Lock

Open the post on Instagram ↗