Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Scheduled Pinned Locked Moved Cybersecurity News
apple
1 Posts 1 Posters 3 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    A newly analyzed phishing-as-a-service (PhaaS) platform, dubbed AnonyMousKIT, is automating the theft of iPhone passcodes to bypass Apple’s Activation Lock on stolen devices. The service relies on voice AI agents to conduct real-time phone calls, impersonating Apple support representatives to trick victims into revealing their unlock codes.

    The attack chain appears to begin with traditional phishing or social engineering to collect the victim’s Apple ID credentials. Once the attacker has that information, AnonyMousKIT initiates a fraudulent call. The AI-driven voice agent convinces the target that their account has been compromised and that they must verify their identity by repeating a one-time passcode. That passcode, once harvested, is used to remove the device from the owner’s iCloud account, effectively unlocking it for resale or reuse.

    Key technical characteristics of the platform:

    • Uses voice AI to mimic human interaction, reducing the need for live operators.
    • Targets Apple Activation Lock, a security feature designed to prevent stolen iPhones from being reactivated.
    • Relies on passcode phishing to complete the unlock process, rather than exploiting a hardware or software flaw.
    • Operates as a service, meaning less-skilled criminals can purchase access to the tooling without building it themselves.

    While the article does not mention a specific CVE or Apple advisory ID associated with this campaign, the method highlights a growing trend: attackers bypassing technical security controls through social engineering rather than code-level exploits. For defenders, the key takeaway is that users should be reminded that Apple will never request a passcode or verification code over an unsolicited phone call.

    Source: BleepingComputer

    Has your organization seen an increase in AI-driven voice phishing attempts, and how are you training users to verify unsolicited phone calls?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World