Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
A sophisticated phishing-as-a-service platform, dubbed AnonyMousKIT, is being used to target stolen Apple devices and trick owners into providing their passcodes and 2FA codes, enabling Activation Lock removal. Operated by a commercial voice platform, the operation leverages AI-powered voice agents impersonating Apple Support and utilizes a complex network of storefronts and email relays to reach victims globally, with a significant number of targets in South Africa and Brazil. The platform utilizes a checkm8 bootrom exploit to target newer Apple devices, and relies on social engineering to bypass Apple’s security measures. SOCRadar continues to monitor the platform and its associated infrastructure.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
