AnonyMousKIT is a newly identified phishing-as-a-service (PhaaS) platform that automates the process of obtaining codes to unlock stolen Apple devices and bypass the Activation Lock feature. This platform has been operational since early 2024 and supports a structured criminal network involved in selling stolen iPhones, collecting Apple IDs, and accessing iCloud backups and Keychain credentials.
Researchers at SOCRadar uncovered details about AnonyMousKIT's operations, identifying its connection to 506 domains and 168 reseller storefronts. The platform utilizes AI voice agents to conduct phishing calls, with SOCRadar recovering records of 200 calls made to victims between August 2025 and May 2026. These calls used 55 distinct interaction transcripts and five different AI agent personas, costing approximately $0.10 per attempt, with 90% of calls directed to Brazil.
Apple's Activation Lock automatically links an iPhone to its owner's Apple Account when Find My is enabled, preventing unauthorized use even after a factory reset. AnonyMousKIT circumvents this by retrieving owner contact information via the Lost Mode feature and sending phishing messages through email, SMS, WhatsApp, or phone calls. These messages impersonate Apple, providing accurate device details to appear legitimate, and direct victims to fake Apple pages to input their passcodes, Apple Account credentials, and two-factor authentication codes. In some cases, AI agents, such as one posing as 'Alice from Apple Support,' directly ask victims to dictate their passcodes.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new phishing-as-a-service (PhaaS) platform named AnonyMousKIT automates the retrieval of iPhone passcodes and disables Apple's Activation Lock feature. This service facilitates a criminal ecosystem for selling stolen iPhones, harvesting Apple IDs, and accessing iCloud backups and Keychain credentials.