3 Sources
[1]
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials. Researchers at threat intelligence platform SOCRadar took advantage of the platform operator's use of bare relative paths to gather information on how the service works, its operators, and infrastructure. SOCRadar found that AnonyMousKIT is connected to 506 domains and is fueling a sprawling business with 168 storefront brands acting as resellers. The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas. SOCRadar notes that the calls cost the operator about $0.10 per attempt, adding that 90% of the calls were made to Brazil. Retrieving unlocking codes Apple's Activation Lock feature activates automatically when the Find My tracking service is turned on, and links the iPhone device to the owner's Apple Account. Even if a stolen device is factory-reset, it remains linked to the original owner's account and requires a valid authorization code during first setup before it can be used. Because of this protection feature, many stolen iPhones are sold for parts. However, their value increases significantly if they can be unlocked, especially when sensitive data belonging to the owner can also be recovered. AnonyMousKIT retrieves information from stolen devices, such as the owner's contact information supplied through the Lost Mode feature, and uses it to contact the owner through email, SMS, WhatsApp, or a phone call. The phishing messages impersonate Apple and claim that the missing device has been located, providing the correct model and IMEI details to make the email appear legitimate. The email takes the victim to a fake Find My or Apple page where they are prompted to enter their device passcode, Apple Account credentials, and the two-factor authentication code. In some cases examined by SOCRadar, an AI agent with an "Alice from Apple Support" persona informs victims that someone trying to unlock the phone brought it to an Apple store, where the device was retained. The AI agent then asks the victim to confirm ownership by dictating the passcode, then directs them to the phishing page. Once the threat actors obtain those codes, they can access the victim's personal data, factory reset the device, and remove it from the Find My app before selling it. A compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices, SOCRadar warns. The researchers found that a small percentage of the emails from the platform were sent to government and corporate organizations. SOCRadar reports that the campaigns facilitated by the AnonuMousKIT had a global footprint, but were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil.
[2]
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across five channels from a single victim record, comprising email at 1.50 credits, SMS priced per sender ID, WhatsApp, a recorded voice call at 1 credit, and an AI voice agent at 2 credits. The targets are owners of Apple devices that were recently lost or stolen, and the pages and calls ask each of them for the 4- or 6-digit device passcode, then the Apple ID credentials, and finally a live two-factor authentication (2FA) code. Apple's own guidance states that the company never asks for a password, device passcode, or 2FA code to provide support. "AnonyMousKIT is best understood not as a phishing kit but a small software business with a criminal customer base. It features credit bundles, published pricing, tiered subscriptions, customer support, status tracking, and infrastructure replacement protocols," SOCRadar said in a Monday report. Activation Lock, introduced in iOS 7, ties the hardware to a specific Apple ID and renders a stolen handset unusable until the owner's account is removed. Lures cite the handset's internal Apple model identifier and its live Find My status, both pulled from the stolen device itself. Victims who follow the link reach an Apple-branded capture page that renders an animated map of the handset's reported location. The AI voice channel is the best-documented vector after email, with 200 call records, 55 transcripts, and five configured personas recovered from the operator's account with the commercial voice platform Vapi. The researchers' report does not say whether the account was reported to Vapi, and neither company has said publicly whether it is still active. All five personas carry the same translated identity, Alice from Apple Support, across English, Spanish, and Portuguese. The calls ran between August 31, 2025 and May 30, 2026, and 179 of the 200 went to numbers in Brazil. In the recovered transcript, the agent asks the victim to confirm ownership, then requests the four- or six-digit passcode and reads the digits back for confirmation. It then explains that someone visited an Apple Store to remove the Activation Lock and asks whether a recovery link has arrived via text. The researchers put the total cost of the 200 calls at $19.24, or about 9.6 cents each. The outcome table in the report assigns all 200 calls to one of four results, comprising 100 victims who hung up, 48 silence timeouts, 24 no-answers, and 28 platform errors or busy signals. No count of captured passcodes, Apple IDs, or 2FA codes appears in the report for any of the five channels. The logs reached SOCRadar via two bare relative file paths in the shared codebase that resolve to the web root and allow unauthenticated HTTP access. Every deployment of that codebase inherits the flaw. A scan of 506 kit-family domains identified 30 distinct installations reachable on 42 domains, with 188 of the 506 live. The AnonyMousKIT installation logged 691 send attempts between March and July 2026, compared with 6,092 across the 30 backends. Three storefronts, i-Blocker, Key Unlock, and KG-KING, launched in the same second on April 10, 2026, sharing the same Gmail relay accounts. SOCRadar assessed that pattern as one buyer running three brands rather than three separate customers. The researchers recorded the following characteristics of the email lures - * The top two subject lines were "Your device has been found" (308 of 691) and "Alert" (157) * Display names spoofed Apple, Find My, Apple Support, and Apple Assistance * 627 of the logged sends relayed through a single free Gmail account, noreplyapple00000[@]gmail[.]com, against 20 and 2 for the two other relay accounts * 678 of the 691 lures carried a location token naming a city, including Johannesburg, Abuja, Buenos Aires, Maputo, and Mumbai * Victim-facing capture pages were served from tokenized /help?TOKEN URLs South Africa accounts for 1,735 of the 6,092 family-wide sends, and 64 of AnonyMousKIT's own 691 sends reached non-consumer domains, including 27 to South African government addresses. SOCRadar said those recipients were selected because their devices were stolen, not because of their roles. The report said the four unlock tools offered on the panel serve as bait, because 5,649 of the 6,092 targeted devices, or 92.7%, run A12 silicon or newer. The checkm8 bootrom exploit reaches only A5 through A11 chips. It also states that technical bypasses are obsolete now that Apple has moved past the checkm8 generation. A public bootrom exploit for A12 and A13 was released on June 18, 2026, two months before the report, and its proof of concept remains live. Its authors describe it as a tethered bootrom exploit requiring physical possession and device firmware update (DFU) mode, and the research does not show a Secure Enclave compromise. Its control tool demotes the device to production mode or boots a raw iBoot image, and neither action recovers a device passcode or removes Activation Lock. SOCRadar described the automated, LLM-driven voice vector as the platform's primary innovation. In March, Mirage Security analyzed a subscription vishing service with commercial text-to-speech embedded as a core feature, and The Hacker News reported in May on an earlier AI vishing kit. Infoblox Threat Intel documented the same unlock-kit ecosystem in May using DNS telemetry, publishing a list of 4,244 malicious domains detected between March 2022 and May 2026. "By combining technical tooling and social engineering, thieves now have a way to unlock devices at scale and make phone theft profitable," Infoblox Threat Intel researchers Maël Le Touz and Elena Puga said. Identical second-level labels across different top-level domains are a pattern match rather than an attribution to a single operator. "Apple will never ask you to log in to any website, or to tap Accept in the two-factor authentication dialog, or to provide your password, device passcode, or two-factor authentication code or to enter it into any website," Apple said in support documentation published on June 15, 2026. Apple directs users to forward Apple-branded phishing email and text messages to [email protected]. The researchers recommended moving high-value Apple IDs to physical hardware security keys, which it said completely mitigates the real-time 2FA interception that is the funnel's ultimate objective. The Hacker News contacted Apple for comment on the research; the company had not responded by the time of publication. The development comes as German and U.S. law enforcement dismantled Kratos in July, pulling more than 200 servers offline, and Indonesian authorities arrested the man they say developed and ran it. "The platform was still running on the last day of our analysis. SOCRadar continues to track it, its sibling storefronts, and the wider shared-codebase family, and will report material changes," the company said.
[3]
New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls
* SOCRadar uncovers AnonyMousKIT, a phishing kit abusing Apple's Lost Mode contact info * Crooks spoof Find My pages, trick victims into giving credentials to unlock stolen iPhones * Active since 2024, it operates like a criminal software business with 500+ domains and AI‑driven vishing Security researchers have discovered AnonyMousKIT, a new phishing kit designed to bypass the last line of defense for stolen iPhones, which has been in use for more than two years. Apple devices come with several anti-theft mechanisms working together to make iPhones a lot less attractive to thieves, including Find My, Activation Lock, and Lost Mode. If a user's device is lost or stolen, they can use their tablet, laptop, or a similar device to enable Find My iPhone, which can then locate the device through an app or a website. They can also see its location on a map, make it play a sound, remotely wipe it, or receive a notification when it's found. Enabling the Find My feature also turns on Activation Lock, which locks the phone and prevents it from being set up by someone else. Even if the thief factory resets it, the phone remains connected to the real owner's Apple account, and they simply can't set it up. To do that, they would need the iPhone device passcode to exit Lost Mode, and the Apple account password, if Activation Lock/setup authentication is required. But there is another feature Apple added, just in case the device isn't actually stolen, but rather lost. For these occasions, there is an option to display the owner's contact information on the screen so that a good samaritan who finds it can return it to its rightful owner. As is the case with many other well-intended features, this one is now also being abused as part of the AnonyMousKIT phishing kit. This is why we can't have nice things According to security researchers SOCRadar, crooks are using AnonyMousKIT to create fake Find My or Apple pages. Then, they use the contact information displayed on the stolen iPhone to reach out to the victim. Through the kit, they can send emails, SMS messages, WhatsApp texts, or even AI-powered phone calls. Reaching out to the victim, the attackers introduce themselves as Apple customer support agents, and tell the victim their smartphone had been retrieved. They also provide the victim with the correct model and IMEI details to confirm the authenticity of their claims. Then they require the victim to confirm their identity by visiting the spoofed Find My page and providing the credentials needed to unlock the phone. The credentials end up with the attackers, who can then unlock the phone, wipe it, and sell it on the black market for a much higher price. "Software business" SOCRadar says the earliest records of the AnonyMousKIT date back to early 2024. Since then it has grown into a major operation, counting more than 500 domains, and having more than 150 storefront brands working as resellers and affiliates. As part of their investigation, the researchers found records of roughly 200 calls, which the crooks made to victims between August 2025 and May 2026. The calls were done using five different AI agent personas and 55 different interaction transcripts. Every call had cost the attackers $0.10, and most of them - 90% - were made to Brazilian victims. A small percentage of email correspondence was made towards government and corporate addresses, as well. Just under 30 attempts were made towards South African government domains, and three to a local university. While the campaign is global in its reach, it's mostly focused on South Africa, Indonesia, India, Kenya, Brazil, and Italy. SOCRadar describes AnonyMousKIT "not as a phishing kit but as a small software business with a criminal customer base." "Its primary innovation is an automated, LLM-driven voice vector. At ~$0.10 per call, the platform initiates dynamic vishing across three languages using structured pretexts synced with email and SMS lure data, removing the need for fluent human callers." At the moment the report was published, the campaign was still ongoing, and the researchers are still tracking it. Via BleepingComputer Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Share
Copy Link
A phishing-as-a-service platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices. Active since early 2024, it operates across 506 domains with 168 storefront brands as resellers, using AI-powered voice calls that impersonate Apple Support to trick victims into revealing device passcodes and Apple ID credentials.
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT has been operating since early 2024, automating the retrieval of codes used to bypass Apple's Activation Lock and unlock stolen devices
1
. Researchers at threat intelligence platform SOCRadar discovered the illegal service while investigating bare relative paths that exposed operational details about the platform's infrastructure and operators1
. The platform represents a structured ecosystem that sells stolen iPhones, harvests Apple ID credentials, accesses iCloud backups, and retrieves Keychain credentials1
. SOCRadar found that AnonyMousKIT is connected to 506 domains and fuels a sprawling business with 168 storefront brands acting as resellers1
. The platform operates like a small software business with a criminal customer base, featuring credit bundles, published pricing, tiered subscriptions, customer support, status tracking, and infrastructure replacement protocols2
.The platform's primary innovation lies in its use of AI voice agents to conduct fake Apple Support AI calls targeting owners of stolen devices
2
. SOCRadar recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by AI voice agents operating under five personas1
. The calls cost the operator approximately $0.10 per attempt, making this cybercriminal tactic both scalable and cost-effective1
. All five personas carry the same translated identity, "Alice from Apple Support," across English, Spanish, and Portuguese2
. During these AI-powered voice calls, the agent informs victims that someone trying to unlock the phone brought it to an Apple store where the device was retained, then asks the victim to confirm ownership by dictating the passcode1
. The platform is credit-metered and drives lures across five channels from a single victim record: email at 1.50 credits, SMS priced per sender ID, WhatsApp, a recorded voice call at 1 credit, and an AI voice agent at 2 credits2
.
Source: Hacker News
AnonyMousKIT retrieves information from stolen devices, such as the owner's contact information supplied through the Lost Mode feature, and uses it to contact the owner through email, SMS, WhatsApp, or phone calls
1
. The phishing messages impersonate Apple and claim that the missing device has been located, providing the correct model and IMEI details to make the communication appear legitimate1
. The email takes the victim to fake Find My pages or Apple pages where they are prompted to enter their device passcode, Apple ID credentials, and the two-factor authentication code1
. Lures cite the handset's internal Apple model identifier and its live Find My status, both pulled from the stolen device itself2
. Victims who follow the link reach an Apple-branded capture page that renders an animated map of the handset's reported location2
. Once threat actors obtain those codes, they can access the victim's personal data, factory reset the device, and remove it from the Find My app before selling it1
.
Source: BleepingComputer
Related Stories
The campaigns facilitated by AnonyMousKIT had a global footprint but were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil
1
. Notably, 90% of the 200 documented calls were made to Brazil, with 179 of 200 going to numbers in that country1
2
. South Africa accounts for 1,735 of the 6,092 family-wide sends across all tracked installations2
. The researchers found that a small percentage of emails from the platform were sent to government and corporate organizations1
. Just under 30 attempts were made toward South African government domains, and three to a local university3
. The top two subject lines used in email lures were "Your device has been found" with 308 of 691 sends, and "Alert" with 157 sends2
.A compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices, SOCRadar warns
1
. This cybersecurity threat matters because Apple's Activation Lock feature, which activates automatically when the Find My tracking service is turned on, links the iPhone device to the owner's Apple Account1
. Even if a stolen device is factory-reset, it remains linked to the original owner's account and requires a valid authorization code during first setup before it can be used1
. Because of this protection feature, many stolen iPhones are sold for parts, but their value increases significantly if they can be unlocked for resale of unlocked devices, especially when sensitive data belonging to the owner can also be recovered1
. The platform's ability to unlock stolen devices at scale transforms what would otherwise be low-value parts into high-value functioning smartphones. A scan of 506 kit-family domains identified 30 distinct installations reachable on 42 domains, with 188 of the 506 live2
. The logs reached SOCRadar via two bare relative file paths in the shared codebase that resolve to the web root and allow unauthenticated HTTP access, meaning every deployment of that codebase inherits the flaw2
. At the time the report was published, the campaign was still ongoing, and researchers continue tracking this evolving vishing operation3
.Summarized by
Navi
[1]
1
Technology

2
Policy and Regulation

3
Technology
