A new phishing-as-a-service (PhaaS) platform, dubbed AnonyMousKIT, is actively being used to automate the theft of Apple ID credentials, which are necessary to bypass the Activation Lock feature on stolen iPhones. The platform leverages advanced AI voice calls to impersonate Apple Support and trick victims into revealing their device passcodes and other sensitive information.
An investigation into AnonyMousKIT revealed a reseller supply chain comprising 506 domains and 168 distinct storefront brands, which have been operational since early 2024. Researchers uncovered these connections by exploiting a critical flaw in the platform's design: the use of bare relative paths, which inadvertently exposed production logs and operator rosters.
The platform's operation is designed to monetize stolen devices by providing a service for thieves who lack the technical skills to bypass Apple's Activation Lock themselves. This security feature, introduced in iOS 7, links an iPhone to its owner's Apple ID when Find My is enabled, preventing unauthorized use even after a factory reset.
AnonyMousKIT subscribers initiate an attack by entering a stolen device's serial number or IMEI into the platform. The system then retrieves information about the device, including its model and current Find My status. This data is used to craft highly targeted phishing messages, delivered via email, SMS, WhatsApp, recorded calls, or live voice agents.
The phishing attempts are particularly effective because they target recent victims of device theft or loss, exploiting their active search efforts and leveraging accurate hardware data. Victims receive messages claiming their device has been found and asking them to verify their identity to retrieve it.
In calls reviewed by researchers, AI voice agents, often using the persona "Alice Dias, Apple Support," tell victims that someone attempted to unlock their phone at an Apple store, and the store is now holding it for security reasons. The agent follows a predefined script, beginning by confirming device ownership and then requesting the victim's four- or six-digit passcode.
After obtaining the passcode, the agent continues the narrative, claiming a recovery case has been opened and asking if the victim received a security link via text. If not, the agent resends the link and guides the victim through entering the unlock code from it. Once the code is confirmed, the call concludes. The stolen credentials can then be used to remove Activation Lock, allowing the device to be resold.
Researchers recovered 200 call logs and 55 transcripts from the voice agents. Of these, 179 calls were directed to Brazil, incurring a total cost of $19.24. The platform supports five voice-agent personas configured in English, Spanish, and Brazilian Portuguese.
AnonyMousKIT is structured in tiers, with a developer creating and selling the platform, buyers licensing it for their branded storefronts, and operators underneath them dispatching phishing messages. Researchers describe AnonyMousKIT as a "small software business with a criminal customer base" rather than a typical phishing kit. The platform was still active at the time of the investigation, with ongoing efforts to track its operations and associated storefronts.






