AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
Summary
AnonyMousKIT is a phishing-as-a-service platform (PhaaS, an illegal service that automates attacks for paying customers) that uses voice AI agents to trick iPhone owners into revealing their passcodes and Apple account credentials. Once attackers obtain these credentials, they can bypass Activation Lock (Apple's security feature that links a stolen iPhone to the owner's account), access the victim's personal data like iCloud backups and passwords, and resell the unlocked device. The operation has been active since early 2024 and uses fake Apple support calls and phishing emails impersonating Apple to deceive victims.
Classification
Affected Vendors
Related Issues
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
CVE-2026-30308: In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman
Original source: https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/
First tracked: August 25, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%