<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes]]></title><description><![CDATA[<p dir="auto">A newly analyzed phishing-as-a-service (PhaaS) platform, dubbed <strong>AnonyMousKIT</strong>, is automating the theft of iPhone passcodes to bypass Apple’s Activation Lock on stolen devices. The service relies on voice AI agents to conduct real-time phone calls, impersonating Apple support representatives to trick victims into revealing their unlock codes.</p>
<p dir="auto">The attack chain appears to begin with traditional phishing or social engineering to collect the victim’s Apple ID credentials. Once the attacker has that information, <strong>AnonyMousKIT</strong> initiates a fraudulent call. The AI-driven voice agent convinces the target that their account has been compromised and that they must verify their identity by repeating a one-time passcode. That passcode, once harvested, is used to remove the device from the owner’s iCloud account, effectively unlocking it for resale or reuse.</p>
<p dir="auto">Key technical characteristics of the platform:</p>
<ul>
<li>Uses voice AI to mimic human interaction, reducing the need for live operators.</li>
<li>Targets Apple Activation Lock, a security feature designed to prevent stolen iPhones from being reactivated.</li>
<li>Relies on passcode phishing to complete the unlock process, rather than exploiting a hardware or software flaw.</li>
<li>Operates as a service, meaning less-skilled criminals can purchase access to the tooling without building it themselves.</li>
</ul>
<p dir="auto">While the article does not mention a specific CVE or Apple advisory ID associated with this campaign, the method highlights a growing trend: attackers bypassing technical security controls through social engineering rather than code-level exploits. For defenders, the key takeaway is that users should be reminded that Apple will never request a passcode or verification code over an unsolicited phone call.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Has your organization seen an increase in AI-driven voice phishing attempts, and how are you training users to verify unsolicited phone calls?</p>
]]></description><link>https://xploitlk.com/topic/99/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:29:35 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/99.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 25 Aug 2026 20:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>