← Blog · · df00tech

AnonyMousKIT: Phishing-as-a-Service Kit Uses Voice AI to Bypass iPhone Activation Lock

security-news campaign

What happened

According to BleepingComputer, researchers have uncovered a phishing-as-a-service (PhaaS) platform dubbed AnonyMousKIT. The kit is reported to automate the process of tricking victims into revealing the codes needed to unlock stolen Apple devices and disable Activation Lock, reportedly using voice AI agents as part of the social-engineering flow. Details on scale, actor attribution, and specific technical mechanics are still limited at this stage.

Why it matters for defenders

Activation Lock bypass services are a persistent driver of iPhone theft, since a device that can be unlocked and re-enrolled retains most of its resale value. Automating the social-engineering step with voice AI lowers the skill and labor bar for operators, which could increase the volume and scale of these campaigns. While this is primarily a consumer-fraud and device-theft concern rather than an enterprise network intrusion, it is relevant to organizations with BYOD policies, mobile device management (MDM) fleets, and any teams tracking phishing-as-a-service tooling trends, since PhaaS kits often evolve or get repurposed for credential phishing against other targets.

What defenders should watch for

  • Awareness training that specifically covers voice-based (vishing) social engineering, including AI-generated or AI-assisted voice calls impersonating Apple support or carriers.
  • Monitoring for phishing infrastructure and lookalike domains impersonating Apple account-recovery or device-unlock services, if threat intel feeds are available.
  • For MDM/fleet-managed devices, review processes for reporting lost/stolen devices and ensure Activation Lock and Find My are enforced by policy.
  • Encourage users never to share Apple ID credentials, verification codes, or device passcodes over the phone, even when the caller appears to be legitimate support.

Developing story

This item is based on a single news report and details may evolve as more research is published; no CVE or specific technical indicators have been disclosed at this time. For the original reporting, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.