BlackTree Security · Infrastructure · Automation · AI

The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.

A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT turns that technical obstacle into a social-engineering workflow, using email, SMS, WhatsApp, recorded calls and commercial AI voice agents to persuade the owner to surrender the passcode, Apple Account credentials and live two-factor code.

SOCRadar’s investigation found a credit-metered phishing-as-a-service ecosystem connected to 506 domains and 168 storefront brands. The platform did not invent a new way to break Apple’s cryptography. It industrialised the task of asking the right person for the secrets that make the protection disappear.

The theft becomes a seven-stage service

Activation Lock ties a device to its owner’s Apple Account when Find My is enabled. Resetting the phone does not remove that relationship. An attacker who cannot obtain the owner’s credentials may be limited to selling the hardware for parts.

AnonyMousKIT sells the missing second stage. An operator enters details about the stolen device and target once. The platform then drives a campaign across several channels:

  1. Profile the device and its Find My status.
  2. Create a victim record with the owner’s details, model and tracking link.
  3. Send lures through email, SMS, WhatsApp, recorded audio or AI voice.
  4. Display a localised recovery page with anti-bot checks and a convincing location narrative.
  5. Collect the device passcode, Apple Account password and live six-digit authentication code.
  6. Send the captured information to the operator panel and Telegram webhooks.
  7. Use the credentials to remove Activation Lock and resell the device.

The platform’s strength is not one technically novel phishing page. It is the orchestration. The victim can be contacted repeatedly through the channel most likely to work, while the lure includes details that only someone holding the device might be expected to know.

AI made voice phishing cheap enough to repeat

SOCRadar recovered records for 200 AI voice calls, 55 transcripts and five configured personas. The dominant persona presented itself as “Alice from Apple Support” and used Portuguese-language scripts for a campaign focused heavily on Brazil.

The calls inserted the victim’s name and device model, described a fabricated store recovery case, asked whether a security text had arrived and guided the target toward the phishing link. Of the 200 recovered calls, 179 went to Brazilian numbers. The total recorded cost was $19.24, approximately 9.6 cents per attempt.

That cost changes attacker economics. A human operator no longer needs to conduct every conversation. The service can place repeated, personalised calls, preserve a consistent script and hand successful credentials back to the criminal workflow.

The evidence should still be described carefully. The recovered records show that the calls occurred and that at least one transcript reached credential capture. They do not prove that all 200 calls succeeded, and the platform’s own logs record hang-ups, silence, unanswered calls and service errors.

The “brands” were storefronts for one codebase

Researchers did not find 168 independent phishing products. Shared panel code, infrastructure and implementation mistakes linked a large reseller family. Scanning the 506-domain set identified 30 distinct backend installations across 42 domains, with other domains offline, sinkholed or used elsewhere in the operation.

The ecosystem separated roles that are often collapsed into one threat actor:

  • A developer maintained and installed the shared phishing platform.
  • A seller promoted subscriptions and handled status, pricing and collections.
  • Storefront owners licensed backend deployments under different names.
  • Subscribers used those storefronts to target owners of stolen devices.

This structure matters for disruption. Removing one lure domain or Telegram channel does not remove the codebase, developer, reseller relationships or customer pool that can generate the next domain.

A basic coding error exposed the operation

The same platform that used AI voice agents and multi-channel automation also relied on bare relative file paths. Those paths exposed production logs without authentication across multiple deployments.

SOCRadar reports that AnonyMousKIT’s email log alone contained more than 120,000 lines, with more than 166,000 lines in its WhatsApp activity log. The wider backend family exposed operator identifiers, campaign activity, delivery details and other records that allowed researchers to map the criminal supply chain from the inside.

The contrast is useful. AI can lower the cost of persuasion, but it does not make the surrounding criminal software professional or secure. Attackers inherit the same configuration, logging and access-control failures as legitimate software teams.

What defenders and device owners should do

  • Treat any message or call claiming that a lost device has been found as untrusted until independently verified through Apple’s official Find My interface.
  • Never provide a device passcode, Apple Account password or two-factor code by phone, chat or a link in a recovery message.
  • Keep Activation Lock enabled. Do not remove a device from the account merely because a caller claims it is required for return or inspection.
  • Organisations should treat an employee’s stolen phone as a possible identity and cloud-access incident, especially where iCloud backups, Keychain material or corporate mail may be reachable.
  • Security teams can use SOCRadar’s published indicators and watch for direct contact with known lure domains, panel infrastructure and suspicious Apple-themed sender accounts.
  • Incident responders should preserve the original messages, caller numbers, links and timestamps before blocking them.

AnonyMousKIT shows how physical theft, cloud identity and AI-assisted social engineering now form one market. The phone is the asset, but the owner is the control the attacker must defeat.

Sources and further reading

Leave a Reply

Your email address will not be published. Required fields are marked *