AI-Powered Phishing Targets Apple Users via Fake Support Calls
A new phishing-as-a-service platform uses AI voice agents to impersonate Apple Support. The scheme targets stolen device owners to bypass Activation Lock.
TL;DR
- AnonyMousKIT is a PhaaS platform using AI voice bots to mimic Apple Support.
- Attackers target stolen iPhone owners, asking for passcodes and 2FA codes.
- The service is credit-metered and automates social engineering at scale.
- Activation Lock bypass allows thieves to resell stolen devices.
- Organizations should educate users on verifying support calls through official channels.
Cybersecurity researchers have uncovered a novel phishing campaign leveraging artificial intelligence to impersonate Apple Support. The operation, orchestrated through a platform called AnonyMousKIT, specifically targets owners of stolen Apple devices by using AI-generated voice calls to extract sensitive information such as passcodes and two-factor authentication (2FA) codes.
This technique enables attackers to remove Apple's Activation Lock—a security feature designed to prevent unauthorized access to lost or stolen devices. By tricking victims into providing credentials under the guise of official support, criminals can unlock and resell these devices with minimal friction.
How AnonyMousKIT Operates
- AnonyMousKIT functions as a phishing-as-a-service (PhaaS) platform, allowing cybercriminals to rent AI voice agents.
- These agents initiate automated calls to device owners, mimicking Apple Support representatives convincingly.
- Victims are prompted to share their device passcodes or 2FA codes, which are then used to disable Activation Lock.
- The platform operates on a credit-based system, making it accessible for low-investment, high-reward fraud schemes.
Implications for Enterprise and End Users
- Organizations relying on Apple devices must recognize emerging voice-based social engineering threats.
- Traditional email-focused phishing defenses may not protect against real-time voice interactions.
- Users should verify all unsolicited support calls through official Apple channels before sharing any credentials.
- Security awareness training should now include guidance on identifying AI-simulated support scams.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.