
A Phishing-as-a-Service (PhaaS) ecosystem dubbed AnonyMousKIT helps criminals steal Apple credentials and disable Activation Lock on stolen devices.
The platform combines phishing emails, SMS, WhatsApp messages, recorded calls, and AI-powered voice agents in a credit-based service.
SOCRadar Threat Research Unit (STRU) analyzed backend source code, production logs, operator panels, victim-facing phishing pages, and artifacts from an AI voice service. The researchers traced the underlying phishing-kit family to at least February 2024 and found evidence of active operations continuing through August 2026.

Unlocking stolen iPhones
AnonyMousKIT is designed around Apple's Activation Lock, a security feature introduced with iOS 7 that binds an Apple device to its owner's Apple ID. While this makes stolen iPhones difficult to resell intact, criminals can remove the lock if they obtain the owner's credentials, passcode, and two-factor authentication codes.
The platform turns that process into a commercial service. Operators enter information about a stolen device, including its model, victim contact details, and Find My status, and then launch social-engineering attempts through multiple channels. SOCRadar identified 6,092 phishing emails across 30 related backends, targeting 5,031 devices reported as online and 1,035 marked as locked.

SOCRadar
Victims who follow the phishing links encounter Apple-themed pages that use anti-bot checks, localized content, and animated maps to create the impression that their missing device has been located. The pages sequentially request the device passcode, Apple ID credentials, and live 2FA codes before forwarding captured information to the operator panel and Telegram webhooks.
AnonyMousKIT also integrates conversational AI for voice phishing. Researchers recovered 200 call records and 55 transcripts from a VAPI.ai account containing several configured personas, primarily an “Alice from Apple Support” character speaking Portuguese.
The automated agent tells victims that Apple has recovered their missing phone and asks them to confirm their four- or six-digit passcode. It can then direct them to an SMS-delivered phishing link. Of the 200 recovered calls, 179 targeted Brazilian numbers, while the entire campaign cost operators only $19.24, or roughly ten cents per attempt.

SOCRadar
Despite the platform's advanced automation, basic development mistakes exposed much of the operation. Bare relative file paths in the shared codebase left production logs accessible without authentication. Pivoting on the common code allowed researchers to connect 506 domains, 168 storefront brands, and 30 distinct backend installations.

SOCRadar
The threat extends beyond the resale value of stolen hardware. Compromised Apple IDs may provide access to iCloud backups, synced email, photos, documents, and credentials stored in iCloud Keychain. SOCRadar found phishing attempts reaching government, educational, and corporate addresses, apparently because employees' devices had been stolen rather than because the organizations were specifically targeted.
Apple users searching for lost devices should treat unsolicited calls, texts, or emails claiming that Apple has recovered a device as suspicious. Users should access Find My directly through trusted Apple apps or manually entered Apple domains, never disclose a device passcode to callers, and avoid entering Apple credentials or verification codes into links received through messages.







Leave a Reply