Researchers at SOCRadar’s Threat Research Unit say they have mapped the infrastructure behind AnonyMousKIT, a phishing-as-a-service platform built specifically to unlock stolen iPhones by defeating Apple’s Activation Lock through social engineering rather than a technical exploit. In a report published this week, SOCRadar said the platform has been active since February 2024, links 506 domains and 168 storefront resale brands to a single shared codebase, and automates credential-harvesting campaigns across email, SMS, WhatsApp, and AI-driven voice calls.

The voice channel is the notable escalation. SOCRadar recovered records of more than 200 AI-generated calls, 90 percent placed to victims in Brazil, using a persona called Alice from Apple Support delivered in English, Spanish, and Portuguese. The total cost of running those 200 calls, based on the researchers’ analysis of the operator’s own billing data, was 19 dollars and 24 cents.

The original insight is the economics, not the social engineering itself, which is not new; CyberTech has covered how cheap fraud tooling has become in other contexts, and AnonyMousKIT extends that trend to voice. A criminal operator with modest resources can now rent commercial AI voice infrastructure and run a multilingual, persona-consistent phone campaign against hundreds of victims for the cost of a meal, a threshold that used to require a call-center operation or a far better-resourced group, similar to the AI-themed impersonation tactics CyberTech has tracked elsewhere. For security teams, the defender-relevant lesson is not about iPhone theft specifically: phone-based social engineering, historically limited by an attacker’s own time and language skills, has had its cost floor removed, and organizations relying on voice callbacks or phone verification as an identity check should assume a similarly cheap AI voice pipeline is available to whoever targets them next.