← Home
CYBERSECURITY

AnonyMousKIT PhaaS Uses Voice AI to Steal iPhone Passcodes

August 29, 2026 Marcus Reeves

How Voice AI Enhances Traditional Phishing Tactics

A newly discovered phishing-as-a-service platform named AnonyMousKIT has been automating the theft of i Phone unlock codes since early 2024. The service uses artificial intelligence-powered voice agents to trick victims into revealing passcodes that disable Apple's Activation Lock. This allows criminals to resell stolen devices without restrictions. The operation was uncovered by cybersecurity researchers in mid-2026 and highlights a growing trend in AI-driven fraud targeting mobile security features.

The platform operates by sending fake alerts that mimic official Apple notifications, prompting users to enter their passcodes during a voice call. Once the code is spoken, AI agents capture and transmit it to attackers who then remotely unlock the device. AnonyMousKIT markets itself as a turnkey solution for cybercriminals, offering step-by-step guides and support for conducting these scams. Its emergence shows how accessible advanced phishing tools have become, lowering the barrier for individuals with minimal technical skills to commit sophisticated fraud.

What Makes This Service Particularly Dangerous for Apple Users

Unlike older phishing methods that rely on deceptive websites or SMS messages, AnonyMousKIT leverages real-time voice interaction to increase credibility. The AI agents are programmed to respond dynamically, adapting to user hesitation or questions with natural-sounding replies. This makes the scam harder to detect, especially for elderly or less tech-savvy individuals who may trust a human-sounding voice. Researchers noted that the service includes multilingual capabilities, expanding its reach across different regions. The use of AI also allows the platform to scale operations efficiently, handling hundreds of calls simultaneously with minimal human oversight.

AnonyMousKIT specifically targets the Activation Lock, a security feature designed to prevent stolen i Phones from being reactivated without the owner’s Apple ID and password. By stealing the device passcode, attackers can bypass this protection and wipe or resell the phone as if it were new. This undermines one of Apple’s core anti-theft defenses and increases the incentive for device theft. Law enforcement agencies have reported a rise in i Phone thefts linked to such services, particularly in urban areas where resale markets are active. The automation of these attacks means that even low-level criminals can now execute high-impact fraud with little effort.

How does AnonyMousKIT avoid detection by security systems? The service uses encrypted communication channels and frequently changes its infrastructure to evade blocking. Voice calls are routed through proxy networks, making it difficult to trace the origin of the attacks.

Frequently Asked Questions

Can Apple devices be protected against this type of phishing? Users should never share their passcode via phone, even if the caller claims to be from Apple. Enabling two-factor authentication and being skeptical of unsolicited calls requesting sensitive information are key preventive steps.

Is AnonyMousKIT still operational as of mid-2026? Yes, investigations confirm the platform has remained active since its discovery, with ongoing updates to its AI scripts and user interface to improve effectiveness and evade countermeasures.

Read full article on Tech Site News →