Particle.news

AnonyMousKIT Uses AI Voice Calls to Steal iPhone Passcodes

Researchers say the criminal platform blends stolen-device data with rented AI voice agents to trick owners into giving passcodes, Apple ID logins, and live 2FA codes so thieves can remove Activation Lock and sell devices.

Overview

  • SOCRadar investigators found a credit‑metered phishing‑as‑a‑service that runs across more than 500 domains and supplies about 168 reseller storefront brands to criminal customers.
  • The service pulls Lost Mode contact details and device identifiers like model and IMEI from stolen phones to craft convincing Apple‑branded lures that push victims to fake capture pages.
  • Researchers recovered 200 call records with 55 transcripts showing five AI personas asking for four‑ or six‑digit device passcodes then prompting users to enter Apple ID credentials and live two‑factor codes, with the calls logged between Aug. 31, 2025 and May 30, 2026.
  • Technical bypasses remain impractical for most modern iPhones because public A12/A13 bootrom code requires physical DFU access and does not remove Activation Lock, which makes scalable social‑engineering the primary threat vector.
  • Defenders are urged to follow Apple’s guidance that it will never ask for passcodes or 2FA codes and to move high‑value Apple IDs to physical hardware security keys to block real‑time interception while researchers and law enforcement continue tracking the ecosystem.