Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Resume Delivers Malware to Cybersecurity Researchers
August 28, 2026
Russian University Leak Exposes GRU Cyber Training for APT28, Sandworm
August 28, 2026
Dark Caracal Hackers Use Ethereum Blockchain for Malware C2 Resilience
August 28, 2026
Home/Threats/AnonyMousKIT PhaaS Steals Apple IDs and 2FA to Unlock Stolen iPhones
Threats

AnonyMousKIT PhaaS Steals Apple IDs and 2FA to Unlock Stolen iPhones

Key Takeaways AnonyMousKIT is a sophisticated Phishing-as-a-Service (PhaaS) platform designed to steal Apple IDs and two-factor authentication (2FA) codes from owners of stolen iPhones. The platform...

David kimber
David kimber
August 27, 2026 4 Min Read
10 0

Key Takeaways

  • AnonyMousKIT is a sophisticated Phishing-as-a-Service (PhaaS) platform designed to steal Apple IDs and two-factor authentication (2FA) codes from owners of stolen iPhones.
  • The platform leverages multi-channel communication, including AI-generated voice calls, emails, SMS, and WhatsApp, to create highly convincing recovery scams.
  • Researchers identified a widespread network of 506 domains and 168 storefront brands associated with AnonyMousKIT, indicating a large-scale, organized operation.
  • The primary goal is to disable Activation Lock on stolen iPhones, allowing them to be resold, but stolen Apple IDs also expose users to broader account compromise.

A new Phishing-as-a-Service (PhaaS) platform, dubbed AnonyMousKIT, is exploiting the distress of iPhone owners whose devices have been stolen. This service employs a sophisticated multi-channel approach, including AI-generated voice calls, to trick victims into divulging their Apple ID credentials and two-factor authentication (2FA) codes, ultimately enabling the unlocking and resale of stolen iPhones.

Table Of Content

  • Key Takeaways
  • AI-Powered AnonyMousKIT PhaaS
  • Network Shows Industrial Scale

The operation integrates various communication methods such as email, text messages, WhatsApp, and even recorded or AI-generated voice calls. These highly personalized messages often incorporate details like the specific iPhone model and its live status from the “Find My” service, lending an air of authenticity to the fraudulent recovery notifications at a time when owners are most vulnerable and eager to retrieve their lost devices.

Security researchers at SOCRadar said in a report that they have identified AnonyMousKIT as a credit-based service tailored for the illicit stolen-device market. Their in-depth analysis revealed shared code across an expansive network, encompassing 506 distinct domains and 168 storefront brands. This extensive infrastructure points to a broad reseller network rather than a limited, isolated phishing operation.

Beyond the immediate financial gain from reselling a device, a compromised Apple ID poses significant risks. It can grant criminals access to cloud backups, stored credentials, and even linked work email accounts. Furthermore, obtaining a live 2FA code allows attackers to complete account changes swiftly, often before the victim realizes the contact was fraudulent, exacerbating the potential for widespread data theft and identity compromise.

AnonyMousKIT Ecosystem Map (Source – SOCRadar)
AnonyMousKIT Ecosystem Map (Source – SOCRadar)

AI-Powered AnonyMousKIT PhaaS

The AnonyMousKIT attack chain begins by extracting specific details from a stolen iPhone, including its model, the owner’s contact information, and its current “Find My” status. This data is then used to craft a highly personalized lure, typically a message suggesting the device has been located, which directs the victim to a fake Apple-branded webpage.

While similar lost iPhone phishing campaigns have surfaced previously, exploiting the hope of device recovery, AnonyMousKIT distinguishes itself through its automated, multi-channel execution. The fraudulent webpage meticulously requests the device’s screen passcode, Apple ID, and a current six-digit 2FA code in a sequential manner.

Once these critical details are entered, they are reportedly transmitted in real-time to the operator’s control panel and Telegram webhooks. This immediate access allows the criminals to bypass Apple’s Activation Lock, effectively preparing the stolen device for quick resale on the black market.

AnonyMousKIT Attack Lifecycle (Source – SOCRadar)
AnonyMousKIT Attack Lifecycle (Source – SOCRadar)

A particularly insidious feature of this scheme is the use of voice calls to enhance its persuasiveness. The service employs an AI-generated persona, mimicking Apple Support, to describe a supposed device recovery case. During these calls, the AI prompts the owner to confirm a passcode and directs them to a link sent via text message. Analysis of 200 recorded AI calls revealed that 179 were placed to Brazilian numbers, underscoring how low-cost, automated calling can enable personalized scams at scale.

Email remains a significant vector for the campaign, with 603 out of 691 attempted messages successfully reaching inboxes between March and July 2026. Most of these successful phishing emails originated from free Gmail relay services and utilized deceptive display names such as “Find My” or “Apple Support.” This tactic mirrors recent AI voice phishing attacks aimed at pressuring victims into revealing authentication data.

Network Shows Industrial Scale

A critical coding error by the AnonyMousKIT operators inadvertently exposed production logs and internal records, providing researchers with an unprecedented glimpse into the service’s supply chain, customer activity, and operational infrastructure. These exposed records detailed 30 distinct backend installations across 42 domains, with 41 active backends identified within the broader network at the time of analysis.

One notable cluster operated three separate storefronts simultaneously, all leveraging shared Gmail relays. The oldest identified installation appeared to shift its focus to WhatsApp-based lures after its email relay system failed. This modular and adaptable setup significantly lowers the technical barrier for individuals seeking to operate device-unlocking scams.

Subscribers to AnonyMousKIT can input victim details once and then use a centralized panel to deploy phishing lures across multiple communication channels. This mirrors the service model of

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

New Backdoor Hides in ESET Agent, Activated by Network Packet

Next Post

OpenAI Agents Chain Zero-Days to Breach Hugging Face and Internal Systems

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Tech and Security Orgs Unite to Combat AI Cyberattacks
August 28, 2026
Cyberattack on Three UK Airports Exposes 8.7 Million Customer Records
August 28, 2026
AD Misconfigurations Enable Stealthy Kerberoasting Attacks
August 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us