Interestana
Home/News/AI Voice Scams Target Stolen iPhones for Passcodes
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

AI Voice Scams Target Stolen iPhones for Passcodes

AI Voice Scams Target Stolen iPhones for Passcodes

Cybersecurity researchers have uncovered a sophisticated phishing-as-a-service (PhaaS) platform designed to bypass Apple's Activation Lock on stolen devices. This platform, tracked by the SOCRadar Threat Research Unit (STRU) as AnonyMousKIT, employs rented artificial intelligence voice agents to contact victims of device theft. These AI agents impersonate Apple Support representatives, aiming to extract sensitive information such as device passcodes and two-factor authentication (2FA) codes from unsuspecting users. The AnonyMousKIT platform operates on a credit-metered system, allowing threat actors to rent its capabilities and initiate large-scale phishing campaigns. The primary objective of these scams is to gain access to the stolen Apple devices by circumventing the Activation Lock, a security feature that prevents unauthorized use of an iPhone, iPad, or Mac if it's lost or stolen. By obtaining the device passcode and 2FA codes, attackers can effectively disable Activation Lock and either use the device themselves or sell it on the black market. The use of AI voice agents represents a significant escalation in the sophistication of these phishing attacks, making them more convincing and harder to detect than traditional text-based scams. These AI agents can mimic human speech patterns, intonation, and conversational flow, creating a more personalized and trustworthy interaction for the victim. This allows attackers to build rapport and exploit the victim's trust more effectively. The SOCRadar report highlights that the platform is actively being used, indicating a growing threat to Apple device owners. The credit-metered nature of the service lowers the barrier to entry for cybercriminals, as they do not need to develop their own infrastructure or AI capabilities. They can simply pay for access to the AnonyMousKIT platform and deploy their phishing attacks. This model democratizes access to advanced attack tools, potentially leading to a surge in such incidents. The activation lock feature is a critical security measure implemented by Apple to deter theft. When a device is lost or stolen, the owner can remotely lock it, making it unusable without their Apple ID and password. This significantly reduces the resale value of stolen devices. However, the AnonyMousKIT platform directly targets the user's credentials, aiming to neutralize this protection. The research underscores the evolving landscape of cyber threats, where AI is increasingly being weaponized for malicious purposes. The ability of AI to generate realistic human voices and engage in dynamic conversations poses a new challenge for cybersecurity defenses and user education. Victims are often unaware they are interacting with an AI, making them more susceptible to social engineering tactics. The platform's ability to drive lures across various communication channels further amplifies its reach and effectiveness. This coordinated approach, combining AI-powered voice calls with potentially other phishing methods, creates a multi-pronged attack strategy. The implications of such platforms extend beyond individual device security, potentially impacting the broader ecosystem of digital trust and online safety. As AI technology advances, it is crucial for both technology companies and cybersecurity researchers to stay ahead of these emerging threats and develop robust countermeasures.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next