AI voice agents are now being used to strip Apple Activation Lock from stolen iPhones.
Threat actors are combining AI automation, web exploits, and mobile payment relay attacks to bypass traditional security layers. Here are the top four active mobile threats you need to know about right now:
AI-Powered "Apple Support" Vishing:
Cybercriminals are leveraging a Phishing-as-a-Service (PhaaS) platform named AnonyMousKIT. Automated AI voice agents impersonate Apple Support, convincingly tricking victims into surrendering 2FA codes and device passcodes to remove Activation Lock and wipe stolen devices.
Malicious Web Exploits Target Unpatched iOS:
Security researchers uncovered malicious Composer packages injecting spyware through web-streaming platforms. Visiting these compromised sites triggers a WebKit-to-kernel exploit chain , installing spyware that harvested crypto wallet seed phrases and app data.
"WindRelay" NFC Mobile Payment Hijacking:
A dangerous Android malware combination (SpyNote RAT + WindRelay) turns infected devices into live NFC relays. Distributed via smishing or fake apps, it silently captures contactless payment data to execute real-time fraudulent transactions.
WhatsApp Passkey & AI Support Exploits:
Attackers are targeting Meta’s automated AI support channels to trigger unauthorized password resets. In response, Meta has rolled out multi-passkey support on WhatsApp for iOS and Android to prevent credential harvesting.
3 Key Actions to Protect Your Devices:
Update your OS immediately:
Patching iOS and Android stops zero-click WebKit and kernel-level exploits.
Never share passcodes over the phone:
Apple, Google, and financial institutions will never call asking for your 2FA code or device passcode.
Stick to official app stores:
Avoid sideloading or downloading apps via links in SMS or social media to prevent RAT infections.
How is your organization adapting its security awareness training to account for hyper-realistic AI voice phishing?
#CyberSecurity #MobileSecurity #ThreatIntelligence #Phishing #ArtificialIntelligence #InfoSec
What's Your Reaction?