Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
07:47 · August 26, 2026 · Hacker News AI Section

Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across
Summary
Cybersecurity researchers at SOCRadar’s Threat Research Unit have detailed AnonyMousKIT, a phishing-as-a-service operation that helps thieves remove Activation Lock from stolen Apple devices. The platform supplies rented AI voice agents that contact recent theft victims while impersonating Apple Support, requesting the device passcode, Apple ID credentials, and a live two-factor authentication code in sequence. It operates on a credit-based model that prices five delivery channels from a single victim record, with AI voice calls carrying the highest per-use cost.
The service draws device-specific details such as the internal model identifier and current Find My status directly from the stolen hardware to craft convincing lures. Recipients who click through reach a counterfeit Apple page displaying an animated location map, while the voice channel uses commercial LLM-driven synthesis to deliver scripted conversations in English, Spanish, and Portuguese under the consistent persona of “Alice from Apple Support.” Analysis of 200 recorded calls showed most targeted Brazilian numbers, with transcripts revealing a flow that first confirms ownership, reads back the supplied passcode for verification, and then solicits a recovery link sent by text.
SOCRadar recovered the call data from an operator account on the Vapi voice platform and noted that the same shared codebase powering AnonyMousKIT also supports dozens of additional storefronts. The researchers observed that the automated voice vector represents the operation’s main technical advance over earlier manual or recorded-call approaches. They also pointed out that the underlying web infrastructure contains unauthenticated file-path exposures that allowed external access to operational logs.
Apple has long stated that it never requests passcodes, passwords, or 2FA codes during support interactions. To counter the real-time interception these campaigns rely on, the researchers advise moving high-value Apple IDs to physical hardware security keys, which prevent remote capture of the final authentication factor even when an attacker obtains the passcode.
Why it matters
This article highlights a sophisticated, AI-driven social engineering threat targeting mobile devices, which is critical for security professionals managing corporate fleets. Understanding these LLM-driven vishing tactics is essential for updating threat models and employee awareness programs in Dutch enterprises.












