Data BreachBleeping Computer
8.5 — CRITICAL
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes, compromising Apple devices and exposing personal data, while also targeting corporate and government organizations with compromised Apple IDs.
⚙️Technical Details
Affected Systems
Apple devices
Attack Vectors
Phishing emails impersonating AppleVoice calls using AI agents with personas such as 'Alice from Apple Support'Exploiting iCloud backups, Keychain passwords, and corporate information
💥Impact Assessment
Severity: High
Who Is at Risk
Individuals with compromised Apple devicesCorporate organizations with compromised Apple IDsSeverity: High
🛡️Recommended Actions
1Implement two-factor authentication for Apple accounts
2Regularly update and patch Apple devices
3Monitor iCloud backups and Keychain passwords for suspicious activity
📦Affected Products
Apple devicesiCloud services
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
