A phishing-as-a-service platform called AnonyMousKIT uses voice AI agents to extract passcodes from stolen Apple devices and bypass Activation Lock security features.
Security researchers have identified AnonyMousKIT, a newly discovered phishing-as-a-service (PhaaS) platform that automates theft of unlock codes for compromised iPhones.
The service leverages voice-based AI agents to conduct phishing attacks targeting device owners. Once attackers obtain a stolen iPhone, AnonyMousKIT facilitates the retrieval of passcodes needed to unlock the device and disable Apple's Activation Lock—a security mechanism that prevents unauthorized access to iPhones linked to an Apple ID.
Activation Lock has become a primary anti-theft feature for Apple devices. Without disabling it, stolen iPhones remain essentially locked to their original owners, limiting their resale value and utility for criminals. By automating the passcode extraction process, AnonyMousKIT streamlines what would otherwise be a manual, time-consuming social engineering operation.
The platform represents a growing trend of criminals-as-a-service business models in the cybercriminal ecosystem. Rather than conducting attacks directly, platform operators monetize their infrastructure by offering phishing automation tools to other bad actors, lowering barriers to entry for device theft operations.
Voice AI adoption for malicious purposes has accelerated in recent years. Deepfakes and synthetic voice technology enable attackers to conduct convincing social engineering attacks at scale, impersonating trusted contacts or service representatives to extract sensitive information.
Apple has implemented multiple security layers to combat device theft, including Activation Lock, Find My, and biometric authentication requirements. However, as long as passcodes remain valuable targets, criminals will continue developing new methods to obtain them.
The discovery underscores broader security challenges surrounding AI-enabled attacks and the vulnerability of authentication systems to sophisticated social engineering. Device owners are advised to use strong, unique passcodes and enable two-factor authentication on their Apple accounts.
Following recent hacks of AI models, companies are debating whether to move cybersecurity testing online. Proponents argue that internet-connected tests provide more accurate threat assessments.
France's tax administration fell victim to a significant security breach, exposing vulnerabilities in one of the country's most critical government systems. Details remain limited as authorities investigate the incident.
A large distributed denial-of-service attack has disrupted Norway's shared government digital infrastructure since Monday, affecting public sector services accessible to citizens.
Security researchers have released a new bootloader that exploits a privilege escalation vulnerability in the original Meta Quest headset, granting users full control and independence from Meta's servers and applications.