Phishing Has a Price Page Now

SOCRadar recently pulled the hood off AnonyMousKIT, a phishing-as-a-service platform whose entire job is unlocking stolen iPhones, and the most interesting part isn't the AI voice agents. It's the billing. The researchers recovered records of 200 calls the platform's voice AI made to victims between August 2025 and May 2026, 55 full transcripts across five rotating personas, and the entire batch cost the operator $19.24. Ten cents a call. AnonyMousKIT is run like a proper SaaS, with credit metering, a dashboard that tracks orders, balances, successful and blocked attempts, and a reseller tier of 168 storefront brands spread across 506 domains that SOCRadar says has been active since early 2024. Their framing is the right one: this isn't a phishing kit, it's a small software business with a criminal customer base, and like any SaaS it optimizes for unit economics.

The mechanism is where it gets specific, because the kit does its homework. A stolen iPhone leaves the owner's contact details behind through Lost Mode, and AnonyMousKIT builds a profile from the device itself — the correct model, the IMEI, the live Find My status — then fires it across email, SMS, WhatsApp, and phone. One recovered email tells the victim their iPhone 15 Plus was detected near another Apple device in Johannesburg, complete with a View Location button. Another persona, “Alice from Apple Support,” calls the owner and claims someone brought the phone into an Apple store, where it's being held. The agent asks the owner to confirm ownership by dictating the passcode, then steers them to a fake Find My page to harvest the device code, the Apple ID, and the 2FA code. The scale shows up in SOCRadar's numbers: over 6,000 email attempts across the kit family, including government, education, and corporate addresses; thousands of WhatsApp attempts; roughly 90% of the recorded calls aimed at Brazil. And the whole operation, operator roster included, got exposed by one of the oldest bugs in the book — bare relative paths that let the researchers walk the platform's production logs.

Source article image
Source image 1

The old advice — we'll never call and ask for your passcode — assumed the caller was a human on a phone bill, which is to say, a cost center. Voice AI collapsed that cost to nothing, so the call is no longer the weak link in the chain; the persona is, and the persona rotates. The angle that actually matters to me is the one that follows the stolen device home: a compromised Apple ID hands over iCloud backups and Keychain credentials, which means corporate email, saved passwords, and 2FA material can follow a personal device into the hands of whoever owns the Apple ID. If your phone is stolen and someone starts calling about a recovered device, the move is to hang up and go through official channels — no legitimate support organization asks for a passcode or a 2FA code by phone, and that line in SOCRadar'

Source article image
Source image 2
s report should be the last sentence of your incident, not a footnote. The practical question for IT shops: a stolen employee phone now sitting in Lost Mode is an incident with a real blast radius. How many of you actually treat it that way, and at what point does a missing iPhone stop being an inconvenience ticket and become a data exfiltration event?

Sources

Comments

Popular posts from this blog

AI Is Starting to Feel Less Like a Gadget and More Like Infrastructure

When Two AI Bots Finally Learned to Talk in Discord

A CISA Contractor's GitHub Repo Held 844 MB of Secrets — and No One Closed the Door