3 Sources
[1]
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen
[2]
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit
[3]
New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls
* SOCRadar uncovers AnonyMousKIT, a phishing kit abusing Apple's Lost Mode contact info * Crooks spoof Find My pages, trick victims into giving credentials to unlock stolen iPhones * Active since 2024, it operates like a criminal software business with 500+ domains and AI‑driven vishing Security
Share
Copy Link
A phishing-as-a-service platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices. Active since early 2024, it operates across 506 domains with 168 storefront brands as resellers, using AI-powered voice calls that impersonate Apple Support to trick victims into revealing device passcodes and Apple ID credentials.
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT has been operating since early 2024, automating the retrieval of codes used to bypass Apple's Activation Lock and unlock stolen devices
1
. Researchers at threat intelligence platform SOCRadar discovered the illegal service while investigating bare relative paths that exposed operational details about the platform's infrastructure and operators1
. The platform represents a structured ecosystem that sells stolen iPhones, harvests Apple ID credentials, accesses iCloud backups, and retrieves Keychain credentials1
. SOCRadar found that AnonyMousKIT is connected to 506 domains and fuels a sprawling business with 168 storefront brands acting as resellers1
. The platform operates like a small software business with a criminal customer base, featuring credit bundles, published pricing, tiered subscriptions, customer support, status tracking, and infrastructure replacement protocols2
.The platform's primary innovation lies in its use of AI voice agents to conduct fake Apple Support AI calls targeting owners of stolen devices
2
. SOCRadar recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by AI voice agents operating under five personas1
. The calls cost the operator approximately $0.10 per attempt, making this cybercriminal tactic both scalable and cost-effective1
. All five personas carry the same translated identity, "Alice from Apple Support," across English, Spanish, and Portuguese2
. During these AI-powered voice calls, the agent informs victims that someone trying to unlock the phone brought it to an Apple store where the device was retained, then asks the victim to confirm ownership by dictating the passcode1
. The platform is credit-metered and drives lures across five channels from a single victim record: email at 1.50 credits, SMS priced per sender ID, WhatsApp, a recorded voice call at 1 credit, and an AI voice agent at 2 credits2
.
Source: Hacker News
AnonyMousKIT retrieves information from stolen devices, such as the owner's contact information supplied through the Lost Mode feature, and uses it to contact the owner through email, SMS, WhatsApp, or phone calls
1
. The phishing messages impersonate Apple and claim that the missing device has been located, providing the correct model and IMEI details to make the communication appear legitimate1
. The email takes the victim to fake Find My pages or Apple pages where they are prompted to enter their device passcode, Apple ID credentials, and the two-factor authentication code1
. Lures cite the handset's internal Apple model identifier and its live Find My status, both pulled from the stolen device itself2
. Victims who follow the link reach an Apple-branded capture page that renders an animated map of the handset's reported location2
. Once threat actors obtain those codes, they can access the victim's personal data, factory reset the device, and remove it from the Find My app before selling it1
.
Source: BleepingComputer
Related Stories
The campaigns facilitated by AnonyMousKIT had a global footprint but were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil
1
. Notably, 90% of the 200 documented calls were made to Brazil, with 179 of 200 going to numbers in that country1
2
. South Africa accounts for 1,735 of the 6,092 family-wide sends across all tracked installations2
. The researchers found that a small percentage of emails from the platform were sent to government and corporate organizations1
. Just under 30 attempts were made toward South African government domains, and three to a local university3
. The top two subject lines used in email lures were "Your device has been found" with 308 of 691 sends, and "Alert" with 157 sends2
.A compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices, SOCRadar warns
1
. This cybersecurity threat matters because Apple's Activation Lock feature, which activates automatically when the Find My tracking service is turned on, links the iPhone device to the owner's Apple Account1
. Even if a stolen device is factory-reset, it remains linked to the original owner's account and requires a valid authorization code during first setup before it can be used1
. Because of this protection feature, many stolen iPhones are sold for parts, but their value increases significantly if they can be unlocked for resale of unlocked devices, especially when sensitive data belonging to the owner can also be recovered1
. The platform's ability to unlock stolen devices at scale transforms what would otherwise be low-value parts into high-value functioning smartphones. A scan of 506 kit-family domains identified 30 distinct installations reachable on 42 domains, with 188 of the 506 live2
. The logs reached SOCRadar via two bare relative file paths in the shared codebase that resolve to the web root and allow unauthenticated HTTP access, meaning every deployment of that codebase inherits the flaw2
. At the time the report was published, the campaign was still ongoing, and researchers continue tracking this evolving vishing operation3
.Summarized by
Navi
[1]
1
Technology

2
Technology

3
Science and Research
