SOCRadar Uncovers AI-Powered PhaaS “AnonyMousKIT” Stealing Apple IDs/Passwords

Today, SOCRadar’s Threat Research Unit (STRU) published new research about AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform built to steal the Apple ID and passcode needed to unlock a stolen iPhone. A basic coding mistake in its backend exposed the whole operation — developer, resellers, and operators.

Apple’s Activation Lock turns a stolen iPhone into scrap unless someone gets the owner’s Apple ID and passcode. AnonyMousKIT turns that into a subscription service: load a stolen device’s details into the panel once, and it works through email, SMS, WhatsApp, a recorded call, and an AI phone call on its own until the owner responds. Two exposed relative file paths handed STRU months of production logs, tracing this one storefront back to a shared codebase running on 506 domains under 168 brand names.

What STRU found:

  • Device-led lures: messages cite the phone’s real Apple model number, like iPhone16,2, and its live Find My location pulled straight off the stolen device.
  • An AI voice agent posing as Apple Support: a rented commercial voice AI, scripted as “Alice from Apple Support” in English, Spanish, and Portuguese, talks victims into reading out their passcode live, then walks them to the phishing link.
  • A reseller network behind the rebrands: the shared codebase ties 506 domains and 168 storefronts together; scanning that family found 30 still-active backends across 42 domains.

The color detail:

  • Ten cents a call: 200 AI voice calls, 90% to Brazil, cost the operator $19.24 total — cheap enough that targets don’t need to be chosen carefully.
  • The bait doesn’t even work: the panel’s four “free” jailbreak tools only run on chips up to the iPhone A11, while 92.7% of targeted devices are A12 or newer.
  • One buyer, three storefronts: an identical setup-check email (26 log lines, every time) shows up in 12 of 24 exposed backends, and three storefronts launched in the same second on April 10, 2026, sharing the same Gmail relay accounts.

The defender takeaway:

  • The tell is the ask: no legitimate Apple or IT support team will ever call and request a passcode or 2FA code out loud.
  • Not just a consumer problem: AnonyMousKIT alone emailed lures to 27 South African government addresses and a local university — a compromised personal Apple ID can still expose corporate Keychain credentials.
  • Still running as of our last collection date, and SOCRadar continues tracking the wider family.

To view the full research, IOCs, and ATT&CK mapping, see the just-published report  Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading