A new phishing-as-a-service (PhaaS) platform named AnonyMousKIT has been identified as automating the process of obtaining passcodes for stolen Apple devices, enabling the disabling of Apple's Activation Lock feature and access to sensitive user data. Active since early 2024, the service supports an ecosystem for selling stolen iPhones, harvesting Apple IDs, and accessing iCloud backups and Keychain credentials.
Researchers at SOCRadar uncovered details of the platform's operations, infrastructure, and operators by exploiting bare relative paths in the system. Their investigation revealed that AnonyMousKIT is linked to 506 domains and powers a substantial illicit business involving 168 reseller storefront brands.
The platform's methods include retrieving owner contact information from stolen devices, often through Apple's Lost Mode feature. This information is then used to contact victims via email, SMS, WhatsApp, or phone calls. Phishing messages, impersonating Apple, claim the missing device has been located and include accurate model and IMEI details to appear legitimate. These messages direct victims to fake Find My or Apple web pages where they are prompted to enter their device passcode, Apple Account credentials, and two-factor authentication codes.
A notable aspect of AnonyMousKIT's operation is its use of voice AI agents in phone calls. Researchers recovered records of 200 such calls made between August 2025 and May 2026, utilizing 55 distinct interaction transcripts handled by AI agents operating under five different personas. One persona, "Alice from Apple Support," informs victims that someone attempting to unlock their phone brought it to an Apple store, where the device was retained. The AI agent then requests the victim to confirm ownership by dictating their passcode before directing them to a phishing page. These calls reportedly cost the operator approximately $0.10 per attempt, with 90% of the recorded calls targeting Brazil.
Once attackers obtain the necessary codes and credentials, they can access the victim's personal data, factory reset the device, and remove it from the Find My app, significantly increasing the device's resale value. A compromised Apple ID can expose iCloud backups, Keychain passwords, work email, and other corporate information stored on both personal and employer-issued Apple devices. While the campaigns facilitated by AnonyMousKIT have a global footprint, they show a higher concentration in South Africa, Indonesia, Italy, India, Kenya, and Brazil. A small percentage of phishing emails from the platform were also directed at government and corporate organizations.






