CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

August 26, 2026

Cybersecurity researchers have uncovered a phishing-as-a-service (PhaaS) platform called AnonyMousKIT that uses AI voice agents to trick owners of stolen Apple devices into revealing passcodes and two-factor authentication (2FA) codes. The platform, detailed by SOCRadar Threat Research Unit (STRU), is designed to strip Apple’s Activation Lock from stolen devices, making them resellable.

AnonyMousKIT operates as a credit-metered service, offering lures across five channels: email, SMS, WhatsApp, recorded voice calls, and AI voice agents. The AI voice channel, powered by the commercial platform Vapi, impersonates Apple Support with personas named ‘Alice from Apple Support’ in English, Spanish, and Portuguese. The calls, which ran between August 2025 and May 2026, targeted victims primarily in Brazil, with 179 of 200 calls going to Brazilian numbers. The total cost for these calls was just $19.24, highlighting the low barrier to entry for such attacks.

The phishing pages mimic Apple’s branding and display an animated map of the device’s location, adding a layer of deception. Victims are asked for their device passcode, Apple ID credentials, and a live 2FA code. Apple has reiterated that it never asks for this information, and users are advised to forward phishing attempts to reportphishing@apple.com.

SOCRadar identified 30 active installations of the kit across 42 domains, with 188 of 506 related domains live. The platform also offers unlock tools, but researchers note that 92.7% of targeted devices run A12 silicon or newer, making the checkm8 bootrom exploit obsolete. A public bootrom exploit for A12 and A13 was released in June 2026, but it requires physical possession and does not compromise the Secure Enclave.

The report recommends using physical hardware security keys for high-value Apple IDs to mitigate real-time 2FA interception. This development follows the dismantling of the Kratos platform by German and U.S. law enforcement in July, indicating a growing focus on such criminal ecosystems.

CVEs: CVE-2026-58231

Attack groups: AnonyMousKIT, Kratos

Companies: Apple, SOCRadar, Infoblox, Mirage Security, Vapi

Products: AnonyMousKIT, Vapi