AnonyMousKIT PhaaS operates a structured criminal ecosystem that weaponises voice AI agents to harvest iPhone passcodes and Apple credentials at scale. The platform, active since early 2024, automates the entire theft pipeline: it extracts victim contact details from stolen devices, deploys AI personas (including "Alice from Apple Support") to conduct phishing calls costing $0.10 per attempt, and directs victims to fake Apple pages where they surrender passcodes and two-factor authentication codes. SOCRadar's analysis of 200 recorded calls across 55 distinct transcripts reveals a sophisticated operation spanning 506 domains with 168 reseller storefronts, concentrated heavily in Brazil but with a global footprint touching government and corporate organisations. The economics are brutal: once credentials are obtained, attackers gain access to iCloud backups, Keychain passwords, work email, and corporate data stored on personal or employer-issued devices.
For CX teams, this represents a critical inflection point in how customer authentication and voice interactions are weaponised. The sophistication of AnonyMousKIT's voice AI—capable of maintaining multiple personas and extracting sensitive information through social engineering—mirrors the same conversational AI capabilities that legitimate CX platforms are deploying at scale. As organisations accelerate adoption of voice AI agents within their own contact centres and customer journeys, the question becomes unavoidable: how do you distinguish between a legitimate voice interaction and a convincing phishing attempt when both operate on identical technical foundations? The fact that 90% of AnonyMousKIT's calls targeted Brazil, yet the operation maintains global reach, suggests that regional CX teams cannot assume their customer base is insulated from these threats.
The deeper implication concerns credential compromise post-authentication. SOCRadar notes that once attackers possess valid credentials, only 37% of subsequent actions are blocked—a gap that exposes the fragility of security architectures that assume the perimeter is the primary threat. For CX professionals managing customer data, support tickets, and integrations with identity systems, this means that voice-based verification workflows, password resets, and account recovery flows are now active attack surfaces. Teams relying on voice authentication or voice-driven customer verification should audit whether their current controls can distinguish between legitimate customers and AI-driven social engineering at the point of interaction, not merely at the point of credential validation.
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]