Today, SOCRadar’s Threat Research Unit (STRU) published new research about AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform built to steal the Apple ID and passcode needed to unlock a stolen iPhone. A basic coding mistake in its backend exposed the whole operation — developer, resellers, and operators.
Apple’s Activation Lock turns a stolen iPhone into scrap unless someone gets the owner’s Apple ID and passcode. AnonyMousKIT turns that into a subscription service: load a stolen device’s details into the panel once, and it works through email, SMS, WhatsApp, a recorded call, and an AI phone call on its own until the owner responds. Two exposed relative file paths handed STRU months of production logs, tracing this one storefront back to a shared codebase running on 506 domains under 168 brand names.
What STRU found:
- Device-led lures: messages cite the phone’s real Apple model number, like iPhone16,2, and its live Find My location pulled straight off the stolen device.
- An AI voice agent posing as Apple Support: a rented commercial voice AI, scripted as “Alice from Apple Support” in English, Spanish, and Portuguese, talks victims into reading out their passcode live, then walks them to the phishing link.
- A reseller network behind the rebrands: the shared codebase ties 506 domains and 168 storefronts together; scanning that family found 30 still-active backends across 42 domains.
The color detail:
- Ten cents a call: 200 AI voice calls, 90% to Brazil, cost the operator $19.24 total — cheap enough that targets don’t need to be chosen carefully.
- The bait doesn’t even work: the panel’s four “free” jailbreak tools only run on chips up to the iPhone A11, while 92.7% of targeted devices are A12 or newer.
- One buyer, three storefronts: an identical setup-check email (26 log lines, every time) shows up in 12 of 24 exposed backends, and three storefronts launched in the same second on April 10, 2026, sharing the same Gmail relay accounts.
The defender takeaway:
- The tell is the ask: no legitimate Apple or IT support team will ever call and request a passcode or 2FA code out loud.
- Not just a consumer problem: AnonyMousKIT alone emailed lures to 27 South African government addresses and a local university — a compromised personal Apple ID can still expose corporate Keychain credentials.
- Still running as of our last collection date, and SOCRadar continues tracking the wider family.
To view the full research, IOCs, and ATT&CK mapping, see the just-published report Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
Related
This entry was posted on August 24, 2026 at 1:35 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
SOCRadar Uncovers AI-Powered PhaaS “AnonyMousKIT” Stealing Apple IDs/Passwords
Today, SOCRadar’s Threat Research Unit (STRU) published new research about AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform built to steal the Apple ID and passcode needed to unlock a stolen iPhone. A basic coding mistake in its backend exposed the whole operation — developer, resellers, and operators.
Apple’s Activation Lock turns a stolen iPhone into scrap unless someone gets the owner’s Apple ID and passcode. AnonyMousKIT turns that into a subscription service: load a stolen device’s details into the panel once, and it works through email, SMS, WhatsApp, a recorded call, and an AI phone call on its own until the owner responds. Two exposed relative file paths handed STRU months of production logs, tracing this one storefront back to a shared codebase running on 506 domains under 168 brand names.
What STRU found:
The color detail:
The defender takeaway:
To view the full research, IOCs, and ATT&CK mapping, see the just-published report Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
Share this:
Like this:
Related
This entry was posted on August 24, 2026 at 1:35 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.