#anonymouskit
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.
www.bleepingcomputer.com
August 25, 2026 at 8:25 PM
An apple a day, a phish away. [Research Saturday]

Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-as-…
#apple #hackernews #news
An apple a day, a phish away. [Research Saturday]
Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-as-a-Service platform designed to steal Apple credentials and disable Activation Lock on stolen devices. The platform uses email, SMS, WhatsApp, and AI-driven voice calls to impersonate Apple Support, with researchers uncovering a broader ecosystem spanning 506 domains, 168 storefront brands, and 30 backend installations. Despite its sophisticated social-engineering capabilities, basic coding flaws exposed extensive operational logs and revealed the shared infrastructure, developer activity, and reseller network behind the criminal operation. The research and executive brief can be found here: ⁠Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
thecyberwire.com
September 27, 2026 at 11:57 AM
AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones

cybersecuritynews.com/ai-powered-a...

#Cybersecurity #Tietoturva #Automaatio
AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones
AnonyMousKIT targets lost iPhone owners with AI-powered phishing, stealing Apple ID credentials to bypass Activation Lock.
cybersecuritynews.com
August 27, 2026 at 8:01 AM
-Major Nigerian scam operation uncovered, linked to web host
-NSA TAO impersonator arrested
-CERT-FR tells Apple spyware victims to reach out
-Supply chain attacks exploded this year
-New stealthy SLEEPWALKER backdoor
-New PhaaS platforms: AnonyMousKIT and ZeroTokens
-WeedHack stealer returns
August 26, 2026 at 8:36 AM
AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones
AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones
AnonyMousKIT is turning stolen iPhones into an entry point for account theft. The phishing-as-a-service platform targets people already searching for a lost device, then uses convincing recovery messages to capture the Apple ID credentials needed to remove Activation Lock. The operation combines email, text messages, WhatsApp, recorded calls and AI-generated voice calls. Its messages can draw on the phone model and live Find My status, making a fake recovery notice feel believable at exactly the moment an owner is anxious to get a device back. Researchers at SOCRadar identified the platform as a credit-based service built for the stolen-device market. Their analysis linked its shared code to 506 domains and 168 storefront brands, showing that the activity is a broader reseller network rather than a single phishing site. AnonyMousKIT Ecosystem Map (Source – SOCRadar) SOCRadar said in a report shared with Cyber Security News (CSN) The risk extends beyond the resale value of a handset. A stolen Apple ID can expose cloud backups, saved credentials and work email, while a live verification code lets criminals complete account changes before a victim realizes the contact was fraudulent. AI-Powered AnonyMousKIT PhaaS AnonyMousKIT begins with details taken from a stolen device, including its model, owner contact data and Find My state. It then sends a location-themed lure that leads to a fake Apple-style page. Similar  lost iPhone phishing campaigns  have exploited the hope of recovering a phone, but this service automates the process across several channels. The page asks for the screen passcode, Apple ID and a current six-digit two-factor authentication code in sequence. Those details are reportedly sent to the operator panel and Telegram webhooks in real time, allowing criminals to disable Activation Lock and prepare the device for resale. AnonyMousKIT Attack Lifecycle (Source – SOCRadar) Voice calls make the scheme more persuasive. The service used an AI persona posing as Apple Support to describe a supposed recovery case, ask the owner to confirm a passcode and steer them toward a texted link. Of 200 recorded AI calls, 179 were placed to Brazilian numbers, illustrating how low-cost automated calling can scale personal scams. Email remained a major delivery route, with 603 of 691 logged attempts reaching inboxes from March through July 2026. Most successful messages used a free Gmail relay and familiar display names such as Find My or Apple Support, a tactic that resembles  recent AI voice phishing attacks  designed to pressure victims into sharing authentication data. Network Shows Industrial Scale The researchers found that a coding mistake exposed production logs and operator records, providing an unusual view of the service’s supply chain, customer activity and infrastructure. The exposed records showed 30 distinct backend installations across 42 domains, with 41 active backends in the wider family at the time of analysis. One cluster ran three storefronts launched at the same time with shared Gmail relays, while the oldest known installation appears to have concentrated on WhatsApp after its email relay failed. This setup matters because it reduces the skill needed to run a device-unlocking scam. Subscribers can enter a victim’s details once and use a panel to push lures through several channels, similar to the service model behind  phishing kits targeting organizations  that package complex account theft into an accessible service. Organizations should not rely only on blocking known domains because the infrastructure rotates quickly. The researchers recommend filtering newly registered domains, watching for tokenized Apple-themed links, and flagging lookalike display names sent through free mail providers. Strong mobile-device management can also restrict sideloaded tools and jailbreak attempts. For individuals, the key rule is simple: a legitimate support team will not call to request a device passcode or a one-time verification code. If a phone is stolen, remotely wipe it where possible and reset the associated Apple ID promptly. The practical checks in this  iPhone phishing safety guide  can help users verify links and report suspicious messages before an account takeover occurs. This also limits damage to linked workplace accounts. Indicators of Compromise (IoCs):- Type Indicator Description Infrastructure anomkit[.]shop AnonyMousKIT infrastructure Infrastructure apple-login-imaps[.]com AnonyMousKIT infrastructure Infrastructure apple-thailand[.]co AnonyMousKIT infrastructure Infrastructure findsupport[.]live AnonyMousKIT infrastructure Infrastructure irealm-server[.]com AnonyMousKIT infrastructure Cross-Brand Backend uktservice[.]sa[.]com Related backend Cross-Brand Backend apple-unlock[.]com Related backend Cross-Brand Backend key-unlock[.]com Related backend Cross-Brand Backend alxescript[.]info Related backend Cross-Brand Backend spider-off-unlock[.]one Related backend Cross-Brand Backend icloud-findmy[.]app Related backend Cross-Brand Backend gon-unlocker[.]pro Related backend Cross-Brand Backend zu7pl[.]pro Related backend Cross-Brand Backend projectpartapple[.]com Related backend Cross-Brand Backend kit-pro-bot[.]click Related backend Cross-Brand Backend b.pro-center[.]my[.]id Related backend Cross-Brand Backend center-one[.]online Related backend Backend Origin 75[.]119[.]135[.]83 Backend host IP Developer IP 27[.]34[.]73[.]22 Reported developer-linked IP Developer IP 27[.]34[.]73[.]46 Reported developer-linked IP High-Volume Range 197[.]235[.]0[.]0/16 Reported high-volume network range High-Volume Range 5[.]90[.]0[.]0/16 Reported high-volume network range High-Volume Range 5[.]91[.]0[.]0/16 Reported high-volume network range High-Volume Range 181[.]170[.]142[.]0/24 Reported high-volume network range Shared Operator IP 196[.]196[.]102[.]74 Shared operator-linked IP Sender / Relay noreplyapple00000[@]gmail[.]com Sender or SMTP relay account Sender / Relay replycareapple010[@]gmail[.]com Sender or SMTP relay account Sender / Relay noreplyil[@]icloud[.]com Sender or SMTP relay account Sender / Relay apple[.]nonreply[.]fmi[@]gmail[.]com Sender or SMTP relay account Sender / Relay applerecoverymanager[@]gmail[.]com Sender or SMTP relay account Suspected Developer Identity underc0deapple[@]gmail[.]com Reported developer-linked account Buyer / Operator Identity xgodauth[@]gmail[.]com Reported buyer or operator account Buyer / Operator Identity naitebrown93[@]gmail[.]com Reported buyer or operator account File Hash 5ea22f9777a34f461840c2a3988c717c0f9e6ec4bd95420c Reported file hash File Hash d9e2881d3aa1ea40928dac65405fbe7e36989cad51ab46d Reported file hash File Hash 32fa60c9099f53f194a6a63c9341dd115434584e0890120b Reported file hash File Hash 07d4a6ac925f9f7e63c7332df1995de03f514931e9d97cb3 Reported file hash File Hash 2c790296b404b3e7592da37b15311507b0e55989e1628ee Reported file hash URL / Path Pattern shorturl[.]at/gXV0Y Reported shortened URL pattern Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones appeared first on Cyber Security News .
cybersecuritynews.com
August 27, 2026 at 7:07 AM
AnonymousKit is using AI voice agents to phish iPhone passcodes - phishing-as-a-service is becoming autonomous. AI is scaling social engineering itself. 🤖📱 #AIThreats #SocialEngineering

www.bleepingcomputer.com/news/securit...
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.
www.bleepingcomputer.com
August 26, 2026 at 6:54 AM
SOCRadar Uncovers AI-Powered PhaaS “AnonyMousKIT” Stealing Apple IDs/Passwords

Today, SOCRadar's Threat Research Unit (STRU) published new research about AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform built to steal the Apple ID and passcode needed to unlock a stolen iPhone....
SOCRadar Uncovers AI-Powered PhaaS “AnonyMousKIT” Stealing Apple IDs/Passwords
Today, SOCRadar's Threat Research Unit (STRU) published new research about AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform built to steal the Apple ID and passcode needed to unlock a stolen iPhone. A basic coding mistake in its backend exposed the whole operation — developer, resellers, and operators. Apple's Activation Lock turns a stolen iPhone into scrap unless someone gets the owner's Apple ID and passcode.
itnerd.blog
August 24, 2026 at 5:36 PM
フィッシング詐欺サービス「AnonyMousKIT」、音声AIエージェントでiPhoneのパスコードを詐取

新たに発見されたフィッシング・アズ・ア・サービス(PhaaS)プラットフォーム「AnonyMousKIT」は、盗まれたApple端末のロック解除やアクティベーションロック機能の無効化に使われるコードの取得を自動化しています。 この違法サービスは2024年初頭から稼働しており、盗難iPhoneの販売、Apple IDの...
フィッシング詐欺サービス「AnonyMousKIT」、音声AIエージェントでiPhoneのパスコードを詐取
新たに発見されたフィッシング・アズ・ア・サービス(PhaaS)プラットフォーム「AnonyMousKIT」は、盗まれたApple端末のロック解除やアクティベーションロック機能の無効化に使われるコードの取得を自動化しています。 この違法サービスは2024年初頭から稼働しており、盗難iPhoneの販売、Apple IDの
blackhatnews.tokyo
August 25, 2026 at 8:29 PM
A phishing-as-a-service platform now uses AI voice agents posing as “Apple Support” to unlock stolen iPhones, for under 10 cents a call 

Researchers identified AnonyMousKIT, a phishing-as-a-service platform built to bypass Apple's Activation Lock on stolen devices, using AI voice agents (all…
A phishing-as-a-service platform now uses AI voice agents posing as “Apple Support” to unlock stolen iPhones, for under 10 cents a call 
Researchers identified AnonyMousKIT, a phishing-as-a-service platform built to bypass Apple's Activation Lock on stolen devices, using AI voice agents (all posing as "Alice from Apple Support," running on the commercial Vapi voice platform in English, Spanish, and Portuguese) to trick victims into handing over passcodes, Apple ID credentials, and two-factor codes, information Apple says it never asks for. You can find more details here: …
itnerd.blog
August 26, 2026 at 6:44 PM
researchers at socradar exposed a phishing-as-a-service platform called anonymouskit, running since early 2024 across 506 domains and 168 reseller storefronts.
August 29, 2026 at 11:13 AM
🚨 Russia leak shows Bauman University training recruits for GRU cyber units APT28 & Sandworm — proof of state-backed cyber warfare.

🌐 darknetsearch.com/knowledge/ne...

#CyberSecurity #ThreatIntel #RussiaLeak #APT28 #Sandworm #GRU

Try it for FREE. 🆓
Cyber Threat Exposure: AnonyMousKIT Phishing Risk Explained | ThreatExposure.io
Cyber threat exposure is taking a new shape as AnonyMousKIT, a phishing-as-a-service operation documented by security researchers, automates social-engineering campaigns designed to capture Apple ID…
threatexposure.io
August 29, 2026 at 12:42 PM
🟢 Scammers Use AI Agents to Call Owners of Stolen iPhones

🗨️ Security specialists at SOCRadar have examined the AnonyMousKIT phishing platform, which helps criminals bypass Activati…

#news
Scammers Use AI Agents to Call Owners of Stolen iPhones
Read more
hackmag.com
August 28, 2026 at 3:30 PM
AnonyMousKIT deploys AI voice & fake recovery pages to steal Apple IDs and bypass Activation Lock. #Security #Phishing #AppleID #2FA #PhaaS #CyberThreats https://thedailytechfeed.com/anonymouskit-phaas-hijacks-apple-ids-2fa-to-bypass-activation-lock/
August 27, 2026 at 6:49 AM
AI voice agents posing as Apple Support are vishing stolen-iPhone owners for passcodes and 2FA codes. https://intel.threadlinqs.com/threat/TL-2026-2164 #ThreatIntel #Vapi #USBliter8 #AnonyMousKIT
August 27, 2026 at 5:30 AM
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveragin…
#apple #hackernews #news
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mimic ‘Apple Support,’ basic coding errors exposed production logs and operator rosters,” researchers wrote. Researchers …
www.helpnetsecurity.com
August 27, 2026 at 9:06 AM
Fake Apple Support Agents Target Stolen-Device Owners in Credential Scam #ActivationLock #AIVoiceScam #AnonyMousKIT
Fake Apple Support Agents Target Stolen-Device Owners in Credential Scam
Using AI-powered voice calls and phishing messages, a new phishing-as-a-service platform targets owners of recently stolen Apple devices to obtain device passcodes, Apple ID credentials and two-factor authentication codes.  In response to SOCRadar Threat Research Unit (STRU) research, security researchers have identified AnonyMousKIT as a credit-based service designed to assist criminals in defeating Apple's Activation Lock. By using this platform, attackers can communicate with their victims via email, SMS, WhatsApp, recorded calls, and artificial intelligence-generated voice agents posing as Apple Support representatives.  AnonyMousKIT also makes the contact appear legitimate by utilizing information tied to the stolen device. By providing a serial number or IMEI to the platform, attackers can identify the device's model and determine whether it is currently in Find My. Victims can be directed to Apple-branded pages with an animated map showing the location of the device reported.  People whose devices have recently been lost or stolen are more likely to actively check for their whereabouts as a result of these campaigns. By providing accurate device information and describing the circumstances surrounding the theft, attackers can increase the likelihood that the communication is a genuine notification regarding recovery or support.  In most cases, the campaign seeks a device's passcode, followed by Apple ID credentials and an Apple 2FA code. Apple's support guidance states that legitimate representatives do not request passwords, device passcodes, or 2FA codes. With anonymousMousKIT, customers are permitted to choose from a variety of methods for contacting victims through a credit-based model.  Email campaigns cost 1.50 credits, recorded voice calls cost 1 credit, and artificial intelligence voice agents cost 2 credits. A single set of stolen-device details can also be used for SMS and WhatsApp, allowing attackers to take multiple approaches to the same victim from a single set. Researchers identified the operation as more than just a conventional phishing kit, describing it as similar to a subscription-based criminal service, with credit packages, pricing tiers, customer support, and mechanisms for replacing compromised infrastructure.  A stolen iPhone can have a number of consequences in addition to unlocking it. An attacker may be able to access the information stored in the account, including iCloud backups and other credentials, if he or she obtains the associated Apple ID credentials and 2FA code. Additionally, SOCRadar found coding errors within the platform that exposed links between multiple domains and backend installations, providing researchers with additional insights into the operation's infrastructure.  With the AI voice component, SOCRadar was able to locate 200 call records and 55 transcripts related to the commercial voice platform Vapi which provide a closer look at the social engineering process. The callers appeared as “Alice” from Apple Support, and were able to use five voice personas across English, Spanish and Brazilian Portuguese. Call recordings were collected between August 31, 2025, and May 30, 2026. 179 of 200 calls were directed to Brazilian telephone numbers. The fake support agent confirms ownership of the device before requesting the four- or six-digit passcode of the device in the reviewed conversations. After repeating the digits for confirmation, the agent claims to have been contacted by an Apple Store regarding an Activation Lock issue.  The conversation then moves to the recovery link that was supposedly sent via text message. As determined by the recovered records, the voice operation was relatively inexpensive to run, with all 200 calls requiring approximately $19.24 per call. However, the available data does not indicate how many victims actually surrendered their passcodes, Apple ID credentials or 2FA codes.  Among the recorded calls, 100 ended when the recipients hung up, 48 timed out due to silence, 24 did not receive an answer, and 28 ended because of platform errors or busy signals. The researchers also discovered that the call records had been retrieved due to an accessibility flaw in the platform's codebase.  Two file paths exposed through the shared code enabled unauthenticated access to files stored in the web root, enabling the recovery of call logs and transcripts. Since the vulnerability was inherited by deployments based on the same codebase, it provides valuable insight into the broader infrastructure supporting AnonyMousKIT. AnonyMousKIT demonstrates a structured criminal supply chain rather than a standalone phishing campaign, according to SOCRadar. Developers of the platform build and sell it, customers license the platform through storefronts, and operators use those services to conduct phishing campaigns. In addition to outsourcing the credential-harvesting process, criminals can concentrate on resale of stolen devices while criminals with limited technical expertise can perform the credential-harvesting process. Activation Lock represents an important threat to criminals who steal devices. Once Find My is activated, an iPhone remains associated with its owner's Apple ID even after a factory reset, which creates a broader threat.  By obtaining the account credentials and verification codes, attackers are able to defeat a security mechanism that otherwise makes activating and reselling stolen devices difficult. At the conclusion of SOCRadar's investigation, AnonyMousKIT was still active, emphasizing the increasing use of automated services to target stolen devices. According to the operation, criminals have been able to steal credentials from lost or stolen iPhones by combining stolen data, phishing and artificial intelligence.  Apple accounts that have been compromised can expose data far beyond the device itself, posing a significant security risk to those who receive them.
dlvr.it
August 27, 2026 at 3:17 PM
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
#apple #hackernews #news
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
www.bleepingcomputer.com
August 26, 2026 at 8:28 PM