Start with Identity
← Blog
News

A phishing kit rents an AI voice agent to call theft victims and ask for their 2FA code

SOCRadar documented AnonyMousKIT, a phishing-as-a-service platform built to strip Apple Activation Lock. An AI persona called Alice from Apple Support phones victims in three languages and asks for the device passcode, Apple ID, and a live two-factor code, at roughly ten cents a call.

By SWI Community TeamAug 26, 2026Updated Aug 29, 2026

SOCRadar's Threat Research Unit disclosed AnonyMousKIT on August 26, 2026, a phishing-as-a-service platform built specifically to strip Apple's Activation Lock from stolen devices. It rents Vapi's commercial voice platform to run an AI persona, "Alice from Apple Support," in English, Spanish, and Portuguese. The agent calls the theft victim, confirms the device passcode, then asks for Apple ID credentials and a live two-factor code, mirroring real support scripts closely enough to pass. Calls cost about 9.6 cents each. SOCRadar documented 200 calls between August 2025 and May 2026, mostly to Brazilian numbers, across 30 installations on 42 domains, 188 of which were still live.

Why it matters

Voice phishing used to be rate-limited by human operators who had to speak the target's language. At ten cents a call, in three languages, on rented infrastructure, that constraint is gone, and this kit is aimed at consumers rather than enterprises, which is where the cost curve bites first. The mechanic is the same one that defeats enterprise MFA: a real-time relay of a one-time code from a human who believes they are talking to support. Codes that can be read aloud can be relayed. Phishing-resistant MFA with a hardware key removes the relay entirely because there is nothing for the victim to recite. The same script works against your help desk, which is how Scattered Spider operates.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.