AnonyMousKIT Phishing-as-a-Service Deploys AI Voice Agents Posing As “Apple Support”: SOCRadar Uncovers 506-Domain Reseller Supply Chain Active Since Early 2024. 200 Call Logs Recovered. 179 Of 200 Calls To Brazil. Voice Agent “Alice Dias Apple Support” Asks Victims To Dictate Passcode. Platform Targets Owners Of Stolen iPhones During Active Device Search
According to Help Net Security/SOCRadar, a phishing-as-a-service platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones targeting the phones’ legitimate owners with AI-generated voice calls that impersonate Apple Support. SOCRadar researchers discovered the operation by exploiting a critical flaw: the platform’s use of bare relative paths exposed production logs and operator rosters.
The investigation revealed a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Researchers recovered 200 call logs and 55 transcripts from AI voice agents; 179 of the 200 calls went to Brazil, with total call costs of just $19.24. The platform runs five voice-agent personas in English, Spanish and Brazilian Portuguese, three using the name “Alice Dias, Apple Support.”
The attack chain is precise: a subscriber enters a stolen device’s serial number or IMEI, the platform pulls its model and live Find My status, and contacts the owner by email, SMS, WhatsApp, recorded call or live voice agent. The voice agent opens by confirming device ownership and asks the victim to “dictate” their four- or six-digit passcode, framing the request around someone trying to unlock the phone at an Apple Store. The stolen passcode is then used to remove Activation Lock and resell the device.
SOCRadar describes the platform as “a small software business with a criminal customer base” operating on a three-tier model: developer, resellers and operators. AnonyMousKIT was still active at the time of publication.
Your stolen phone calls you. The voice says Apple Support. It wants your passcode. That is the attack. Check out our previous coverage of cybersecurity on The Trusted Times.

