Security1 distinct publisher3 min readPublished
SOCRadar's teardown of the AnonyMousKIT service found 200 AI-voiced calls at about $0.10 each, most of them to Brazil. The skill in phone social engineering is now a script file.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The passcode is the part email cannot reliably get. Activation Lock binds a handset to the owner's Apple Account the moment Find My is enabled, survives a factory reset, and demands a valid authorization code at first setup [7]. That is why a stolen iPhone destined for parts is worth less than one that can be unlocked, and worth more still if the owner's data travels with it [8]. A convincing fake Find My page will collect an Apple Account password and a 2FA code [11]. The device passcode is the credential a wary owner is least likely to type into a browser, and the call exists to have it said out loud instead [12].
Run the numbers on the recovered log and the scale is modest. Two hundred calls at roughly ten cents [5][6] is about twenty dollars of telephony for the entire sample [1], with some 180 of those calls placed to Brazilian numbers [2]. Across the window from August 2025 to May 2026 that averages around twenty calls a month [3]. This is a capability finding rather than a volume one, and SOCRadar obtained it by pulling on the operator's use of bare relative paths [3], so what was recovered is what leaked, not necessarily what was dialled.
The harder problem is what the caller already holds. The pretext quotes the device's genuine model and IMEI [10], and the owner's phone number and email came from the Lost Mode contact details the owner published themselves in the hope of getting the phone back [9]. A verification script that treats device identifiers plus a matching contact number as evidence of identity has the polarity reversed here. The attacker can answer the challenge questions. The person being asked to prove something is the victim, and the proof requested is a secret.
Corporate exposure follows from where the Apple Account sits, not from who was targeted. SOCRadar found a small share of the platform's phishing emails going to government and corporate recipients [15], and warns that an account taken this way can reach iCloud backups, Keychain passwords, and work email held on personal or employer-issued hardware [14]. The concentration of activity in South Africa, Indonesia, Italy, India, Kenya and Brazil [16] tells you where the resale market is, not where the credential eventually lands.
As an enforcement problem, the shape of the estate matters more than the voice agent. SOCRadar counted 506 domains and 168 reseller storefront brands [4], which is about three domains per brand [4]. Take down a storefront and you have taken down two or three names attached to a service that has been running since early 2024 and that also sells the stolen handsets, harvests Apple IDs, and reads iCloud and Keychain data [1][2]. Five personas and 55 distinct transcripts [5] are the cheapest assets in that inventory to replace.
Ranked by verification strength, evidence, and original report placement.
The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.
A phishing-as-a-service platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable Activation Lock.
The service has been active since early 2024 and powers an ecosystem that sells stolen iPhones, harvests Apple IDs, and accesses iCloud backups and Keychain credentials.
Researchers at threat intelligence platform SOCRadar exploited the platform operator's use of bare relative paths to gather information on how the service works, its operators, and its infrastructure.
SOCRadar found AnonyMousKIT connected to 506 domains and 168 storefront brands acting as resellers.
SOCRadar states the calls cost the operator about $0.10 per attempt, and that 90% of the calls were made to Brazil.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor teardown with concrete artifacts
The claims are unusually specific for a criminal-service story — recovered call records, transcript and persona counts, domain and brand tallies, and a quoted script — and the collection method (bare relative paths exposing operator files) is stated. But everything rests on one threat-intelligence vendor's self-published research relayed by one outlet, with no independent researcher, Apple statement, law-enforcement action or indicator list in the cluster to check the counts against.
Operational since 2024 at industrial breadth, modest voice-call volume
This measures real-world operational use of the service rather than defender uptake. Breadth is substantial: activity since early 2024, 506 domains, 168 reseller storefronts and campaigns concentrated across six countries. The AI-voice component, however, is documented at only 200 calls over roughly ten months — about 20 per month — and the article does not say whether that log is complete, so the voice-agent layer reads as an established but small-scale capability inside a larger phishing operation.
Framing outruns the documented call volume
The substantive claims are attributed and internally consistent, so the gap is small rather than severe. But the story is framed around voice AI industrializing phone social engineering while the actual voice evidence is 200 calls and about $20 of call spend over ten months, with no reported success rate, no unlock count and no confirmed corporate victim. The infrastructure numbers that carry the sense of scale describe the phishing business generally, not the AI agent the headline foregrounds.
Vendor research relay with a sponsored promotion attached
The findings originate with SOCRadar, a commercial threat-intelligence platform whose product benefits from publicized original research, and the reporting reproduces its counts and warnings without external checking. The article itself ends with a promotional block for a third-party security report and its simulation figures, layering a second commercial interest on top of the disclosure. None of this makes the technical account wrong, but the numbers flow through parties with a marketing stake in their impressiveness.
Coherent single-source account, uncorroborated
Confidence is moderate: the mechanism is plausible, specific and consistent with how Activation Lock works, and the reporting outlet is an established security publication. It is held down by having exactly one publisher and one originating vendor, an unquantified enterprise-impact claim, no Apple or law-enforcement response, and no way to test whether the recovered call log reflects the operation's full activity.
security
FTP greeting banners are now a C2 channel, and they are carrying two new RATs2 distinct publishers
build
Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout1 distinct publisher
build
Unauthenticated root on macOS Screen Sharing: CVE-2026-65400 is already dropping miners1 distinct publisher
invest
Your Landed Cost Is Being Litigated By Companies With $306,000 Problems1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026