Researchers have uncovered AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform designed to help criminals unlock and resell stolen Apple devices.
The service targets iPhone owners with convincing Apple-themed emails, SMS messages, WhatsApp chats, recorded calls, and AI voice calls.
The platform abuses a common problem in phone theft. Apple’s Activation Lock makes a stolen iPhone difficult to reuse unless the thief obtains the owner’s Apple ID credentials.
Instead of technically bypassing the protection, AnonyMousKIT uses social engineering to trick victims into giving away their device passcode, Apple ID password, and six-digit two-factor authentication (2FA) code.
AnonyMousKIT runs as a credit-based criminal service. Subscribers enter information about a stolen device, including its model, owner details, and Find My status.
The platform then creates customized phishing lures that falsely claim the device was found or is being held by Apple Support.
AnonyMousKIT Unlocks Stolen iPhones
The most concerning feature is its use of conversational AI voice agents. Researchers found five voice personas, including English, Spanish, and Brazilian Portuguese versions of an alleged Apple Support representative called “Alice.”
The AI agent can use victim-specific details, ask the target to confirm ownership, request the iPhone passcode, and direct the victim to a phishing page sent by SMS.
The campaign logged 200 AI voice calls between August 2025 and May 2026. Most calls targeted Brazilian phone numbers, while the platform’s AI-call costs averaged roughly 10 cents per attempt.
This low cost allows criminals to repeatedly target victims without needing fluent human operators. Email was another major delivery method. Between March and July 2026, the AnonyMousKIT deployment recorded 691 email-send attempts.
The lures used Apple- and Find My-themed display names, often sent through free Gmail accounts, to make messages look legitimate on mobile devices. Common subject lines included “Your device has been found” and “Alert.”
The investigation found that AnonyMousKIT is not a single phishing site. It is part of a wider shared-codebase ecosystem with 506 domains and 168 storefront brands.
Researchers identified 30 backend installations across 42 domains, showing that multiple criminal sellers and resellers were offering similar iPhone-unlocking services.
A coding error exposed extensive operational logs. The data included email activity, WhatsApp operator records, AI-call artifacts, configuration details, and backend information.
Researchers identified 689 distinct WhatsApp operator accounts and found that several storefronts appeared to be managed by the same operators, socradar said.
The phishing flow uses tokenized links and fake Apple pages displaying device-location visuals to build trust. Victims are then asked for their passcode, Apple ID, password, and live 2FA code.
The stolen data is reportedly sent to operator panels and Telegram webhooks, allowing criminals to attempt Activation Lock removal and sell the device.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN
