#ActivationLock
Fake Apple Support Agents Target Stolen-Device Owners in Credential Scam #ActivationLock #AIVoiceScam #AnonyMousKIT
Fake Apple Support Agents Target Stolen-Device Owners in Credential Scam
Using AI-powered voice calls and phishing messages, a new phishing-as-a-service platform targets owners of recently stolen Apple devices to obtain device passcodes, Apple ID credentials and two-factor authentication codes.  In response to SOCRadar Threat Research Unit (STRU) research, security researchers have identified AnonyMousKIT as a credit-based service designed to assist criminals in defeating Apple's Activation Lock. By using this platform, attackers can communicate with their victims via email, SMS, WhatsApp, recorded calls, and artificial intelligence-generated voice agents posing as Apple Support representatives.  AnonyMousKIT also makes the contact appear legitimate by utilizing information tied to the stolen device. By providing a serial number or IMEI to the platform, attackers can identify the device's model and determine whether it is currently in Find My. Victims can be directed to Apple-branded pages with an animated map showing the location of the device reported.  People whose devices have recently been lost or stolen are more likely to actively check for their whereabouts as a result of these campaigns. By providing accurate device information and describing the circumstances surrounding the theft, attackers can increase the likelihood that the communication is a genuine notification regarding recovery or support.  In most cases, the campaign seeks a device's passcode, followed by Apple ID credentials and an Apple 2FA code. Apple's support guidance states that legitimate representatives do not request passwords, device passcodes, or 2FA codes. With anonymousMousKIT, customers are permitted to choose from a variety of methods for contacting victims through a credit-based model.  Email campaigns cost 1.50 credits, recorded voice calls cost 1 credit, and artificial intelligence voice agents cost 2 credits. A single set of stolen-device details can also be used for SMS and WhatsApp, allowing attackers to take multiple approaches to the same victim from a single set. Researchers identified the operation as more than just a conventional phishing kit, describing it as similar to a subscription-based criminal service, with credit packages, pricing tiers, customer support, and mechanisms for replacing compromised infrastructure.  A stolen iPhone can have a number of consequences in addition to unlocking it. An attacker may be able to access the information stored in the account, including iCloud backups and other credentials, if he or she obtains the associated Apple ID credentials and 2FA code. Additionally, SOCRadar found coding errors within the platform that exposed links between multiple domains and backend installations, providing researchers with additional insights into the operation's infrastructure.  With the AI voice component, SOCRadar was able to locate 200 call records and 55 transcripts related to the commercial voice platform Vapi which provide a closer look at the social engineering process. The callers appeared as “Alice” from Apple Support, and were able to use five voice personas across English, Spanish and Brazilian Portuguese. Call recordings were collected between August 31, 2025, and May 30, 2026. 179 of 200 calls were directed to Brazilian telephone numbers. The fake support agent confirms ownership of the device before requesting the four- or six-digit passcode of the device in the reviewed conversations. After repeating the digits for confirmation, the agent claims to have been contacted by an Apple Store regarding an Activation Lock issue.  The conversation then moves to the recovery link that was supposedly sent via text message. As determined by the recovered records, the voice operation was relatively inexpensive to run, with all 200 calls requiring approximately $19.24 per call. However, the available data does not indicate how many victims actually surrendered their passcodes, Apple ID credentials or 2FA codes.  Among the recorded calls, 100 ended when the recipients hung up, 48 timed out due to silence, 24 did not receive an answer, and 28 ended because of platform errors or busy signals. The researchers also discovered that the call records had been retrieved due to an accessibility flaw in the platform's codebase.  Two file paths exposed through the shared code enabled unauthenticated access to files stored in the web root, enabling the recovery of call logs and transcripts. Since the vulnerability was inherited by deployments based on the same codebase, it provides valuable insight into the broader infrastructure supporting AnonyMousKIT. AnonyMousKIT demonstrates a structured criminal supply chain rather than a standalone phishing campaign, according to SOCRadar. Developers of the platform build and sell it, customers license the platform through storefronts, and operators use those services to conduct phishing campaigns. In addition to outsourcing the credential-harvesting process, criminals can concentrate on resale of stolen devices while criminals with limited technical expertise can perform the credential-harvesting process. Activation Lock represents an important threat to criminals who steal devices. Once Find My is activated, an iPhone remains associated with its owner's Apple ID even after a factory reset, which creates a broader threat.  By obtaining the account credentials and verification codes, attackers are able to defeat a security mechanism that otherwise makes activating and reselling stolen devices difficult. At the conclusion of SOCRadar's investigation, AnonyMousKIT was still active, emphasizing the increasing use of automated services to target stolen devices. According to the operation, criminals have been able to steal credentials from lost or stolen iPhones by combining stolen data, phishing and artificial intelligence.  Apple accounts that have been compromised can expose data far beyond the device itself, posing a significant security risk to those who receive them.
dlvr.it
August 27, 2026 at 3:17 PM
📰 Platform PhaaS AnonyMousKIT Manfaatkan Agen AI Suara untuk Curi Kode Sandi iPhone Curian

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/26/anonymouskit-phaas-gunakan-ai-suara-curi-passcode-iphone/

#activationLock #anonymouskit #appleId #iphoneCurian #keamananSiber #phaas #ph
August 26, 2026 at 4:09 AM
AnonyMousKIT PhaaS uses voice AI and fake Apple messages to steal iPhone passcodes, bypass Activation Lock, and harvest Apple IDs, iCloud backups, and Keychain data. #Apple #ActivationLock #Brazil
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
AnonyMousKIT is a phishing-as-a-service platform that automates stealing Apple device unlock codes, bypassing Activation Lock, and harvesting Apple IDs, iCloud backups, and Keychain credentials. SOCRadar linked the operation to 506 domains and 168 reseller storefronts, with campaigns focused heavily on Brazil and reaching victims in multiple countries. #AnonyMousKIT #SOCRadar #Apple #ActivationLock
www.hendryadrian.com
August 26, 2026 at 12:30 AM
Bobik Tool v1.2.0 2026 Activation Lock Bypass Tool

Download: go.cyberslinks.com/r.php?id=s2J...

Added iCloud fix support for iOS 9 to iOS 12 devices

Added sideloading fix for better app installation support

#BobikTool #ActivationLock #BypassTool #FreeTool #LockBypass
April 28, 2026 at 12:33 PM
Bobik v1.2.0 Activation Lock Bypass Tool Free

Download: go.cyberslinks.com/r.php?id=s2J...

Added iCloud fix support for iOS 9 to iOS 12 devices

Added sideloading fix for better app installation support

#BobikTool #ActivationLock #BypassTool #FreeTool #LockBypass
April 18, 2026 at 7:48 AM
Underground Telegram markets are fueling the iPhone theft economy with unlocking tools, smishing kits, and fake Apple pages that trick owners into giving up passcodes and credentials. #iPhoneTheft #ActivationLock #Telegram
Lookalike Domains Expose the iPhone Theft Economy
The article describes a Telegram-based underground marketplace that sells iPhone unlocking tools, smishing kits, and social-engineering services to help thieves turn stolen devices into resaleable goods. It also shows how threat actors use Apple lookalike domains, Telegram bots, and detection-evasion tricks to scale smishing campaigns and monetize stolen iPhones. #Apple #Telegram #iCloud #ActivationLock
www.hendryadrian.com
May 28, 2026 at 4:30 PM
Bobik Tool v1.2.0 2026 Activation Lock Bypass Tool

Download: go.cyberslinks.com/r.php?id=s2J...

Added iCloud fix support for iOS 9 to iOS 12 devices

Added sideloading fix for better app installation support

#BobikTool #ActivationLock #BypassTool #FreeTool #LockBypass
April 28, 2026 at 11:25 AM
Bobik v1.2.0 Activation Lock Bypass Tool Free

Download: go.cyberslinks.com/r.php?id=s2J...

Added iCloud fix support for iOS 9 to iOS 12 devices

Added sideloading fix for better app installation support

#BobikTool #ActivationLock #BypassTool #FreeTool #LockBypass
April 18, 2026 at 7:47 AM
www.updatefrp.com/2025/04/lock...
🔒 Wondering if Apple can remove Activation Lock? ✅ Yes, but only with valid proof of ownership! Visit the Apple Store with your original receipt or contact Apple Support. No proof = no unlock. #AppleSupport #iCloudLock #ActivationLock #TechTips
www.updatefrp.com
May 17, 2025 at 9:27 PM
www.updatefrp.com/2025/04/blog...
Forgot your Apple ID and stuck with Activation Lock? 😓 Don't worry — recovery is possible! Try Apple’s account recovery at iforgot.apple.com or contact Apple Support with proof of purchase. 🛠️📱
#AppleID #ActivationLock #iPhoneTips #TechHelp
www.updatefrp.com
May 6, 2025 at 8:37 PM
www.updatefrp.com
www.updatefrp.com/search/label...
🔓 Stuck on iPhone Activation Lock after an update? Learn safe, legal ways to unlock your device, recover access, and avoid scams. A must-read for second-hand iPhone users! 📱
#iPhone #ActivationLock #AppleSupport #TechHelp #iOS
May 1, 2025 at 10:08 PM
🔒 Apple's new Activation Lock for iPhone components is set to strike a major blow to the stolen iPhone market. However, it also creates an extra hurdle for DIY repairs, raising questions about repair accessibility. 📱🔧 #Apple #ActivationLock #iPhone #RightToRepair #TechNews
September 16, 2024 at 9:44 AM
Bobik v1.2.0 Activation Lock Bypass Tool

go.cyberslinks.com/r.php?id=Eqd...

Added iCloud fix support for iOS 9 to iOS 12 devices

Added sideloading fix for better app installation support

#BobikTool #ActivationLock #BypassTool #FreeTool #LockBypass
April 17, 2026 at 4:59 PM
Προσφέρει μέγιστη ασφάλεια για το κινητό η eSIM; Ακόμα και αν χαθεί ή κλαπεί η συσκευή, μπορεί να στείλει την τοποθεσία της και να προστατεύσει τα προσωπικά σου δεδομένα; Μάθε στο παρακάτω άρθρο!
greek-nea.com/giati-to-esi...
#eSIM #MobileSecurity #ActivationLock #SIMvsESIM #Κινητό #Τεχνολογία
Γιατί η eSIM είναι πιο ασφαλές από την κλασική SIM
Γιατί το eSIM είναι πιο ασφαλές από την κλασική SIM; Στον σύγχρονο ψηφιακό κόσμο, η ασφάλεια των κινητών τηλεφώνων και των προσωπικών
greek-nea.com
September 25, 2025 at 11:27 PM
#Apple #AppleSupport another #iPhone Pro Max amongst millions of others put in my #drawer untill #activationlock disappears from #inactive #icloud accounts. Most likely #never. Who cares. This iPhone will have to rust away then. Very #world #ecofriendly iPhone #brick #icloudlock
December 11, 2024 at 10:24 AM