Phishing Has a Price Page Now
SOCRadar recently pulled the hood off AnonyMousKIT, a phishing-as-a-service platform whose entire job is unlocking stolen iPhones, and the most interesting part isn't the AI voice agents. It's the billing. The researchers recovered records of 200 calls the platform's voice AI made to victims between August 2025 and May 2026, 55 full transcripts across five rotating personas, and the entire batch cost the operator $19.24. Ten cents a call. AnonyMousKIT is run like a proper SaaS, with credit metering, a dashboard that tracks orders, balances, successful and blocked attempts, and a reseller tier of 168 storefront brands spread across 506 domains that SOCRadar says has been active since early 2024. Their framing is the right one: this isn't a phishing kit, it's a small software business with a criminal customer base, and like any SaaS it optimizes for unit economics.
The mechanism is where it gets specific, because the kit does its homework. A stolen iPhone leaves the owner's contact details behind through Lost Mode, and AnonyMousKIT builds a profile from the device itself — the correct model, the IMEI, the live Find My status — then fires it across email, SMS, WhatsApp, and phone. One recovered email tells the victim their iPhone 15 Plus was detected near another Apple device in Johannesburg, complete with a View Location button. Another persona, “Alice from Apple Support,” calls the owner and claims someone brought the phone into an Apple store, where it's being held. The agent asks the owner to confirm ownership by dictating the passcode, then steers them to a fake Find My page to harvest the device code, the Apple ID, and the 2FA code. The scale shows up in SOCRadar's numbers: over 6,000 email attempts across the kit family, including government, education, and corporate addresses; thousands of WhatsApp attempts; roughly 90% of the recorded calls aimed at Brazil. And the whole operation, operator roster included, got exposed by one of the oldest bugs in the book — bare relative paths that let the researchers walk the platform's production logs.

The old advice — we'll never call and ask for your passcode — assumed the caller was a human on a phone bill, which is to say, a cost center. Voice AI collapsed that cost to nothing, so the call is no longer the weak link in the chain; the persona is, and the persona rotates. The angle that actually matters to me is the one that follows the stolen device home: a compromised Apple ID hands over iCloud backups and Keychain credentials, which means corporate email, saved passwords, and 2FA material can follow a personal device into the hands of whoever owns the Apple ID. If your phone is stolen and someone starts calling about a recovered device, the move is to hang up and go through official channels — no legitimate support organization asks for a passcode or a 2FA code by phone, and that line in SOCRadar'

Sources
Comments
Post a Comment