LIVE · cybersecurity feed
Live wire
Employee benefits platform Paylogix says hackers stole financial and health dataAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning Repair
phishing

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]

zeroday.news ·

A new phishing-as-a-service (PhaaS) platform named AnonyMousKIT has been identified as automating the process of obtaining passcodes for stolen Apple devices, enabling the disabling of Apple's Activation Lock feature and access to sensitive user data. Active since early 2024, the service supports an ecosystem for selling stolen iPhones, harvesting Apple IDs, and accessing iCloud backups and Keychain credentials.

Researchers at SOCRadar uncovered details of the platform's operations, infrastructure, and operators by exploiting bare relative paths in the system. Their investigation revealed that AnonyMousKIT is linked to 506 domains and powers a substantial illicit business involving 168 reseller storefront brands.

The platform's methods include retrieving owner contact information from stolen devices, often through Apple's Lost Mode feature. This information is then used to contact victims via email, SMS, WhatsApp, or phone calls. Phishing messages, impersonating Apple, claim the missing device has been located and include accurate model and IMEI details to appear legitimate. These messages direct victims to fake Find My or Apple web pages where they are prompted to enter their device passcode, Apple Account credentials, and two-factor authentication codes.

A notable aspect of AnonyMousKIT's operation is its use of voice AI agents in phone calls. Researchers recovered records of 200 such calls made between August 2025 and May 2026, utilizing 55 distinct interaction transcripts handled by AI agents operating under five different personas. One persona, "Alice from Apple Support," informs victims that someone attempting to unlock their phone brought it to an Apple store, where the device was retained. The AI agent then requests the victim to confirm ownership by dictating their passcode before directing them to a phishing page. These calls reportedly cost the operator approximately $0.10 per attempt, with 90% of the recorded calls targeting Brazil.

Once attackers obtain the necessary codes and credentials, they can access the victim's personal data, factory reset the device, and remove it from the Find My app, significantly increasing the device's resale value. A compromised Apple ID can expose iCloud backups, Keychain passwords, work email, and other corporate information stored on both personal and employer-issued Apple devices. While the campaigns facilitated by AnonyMousKIT have a global footprint, they show a higher concentration in South Africa, Indonesia, Italy, India, Kenya, and Brazil. A small percentage of phishing emails from the platform were also directed at government and corporate organizations.

phishingai
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]

breach

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]

breach

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cyber

ai

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.

breach

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

nation-state

58 arrested in international cybercrime crackdown

Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.