AnonyMousKIT PhaaS Steals Apple IDs and 2FA to Unlock Stolen iPhones
Key Takeaways AnonyMousKIT is a sophisticated Phishing-as-a-Service (PhaaS) platform designed to steal Apple IDs and two-factor authentication (2FA) codes from owners of stolen iPhones. The platform...
Key Takeaways
- AnonyMousKIT is a sophisticated Phishing-as-a-Service (PhaaS) platform designed to steal Apple IDs and two-factor authentication (2FA) codes from owners of stolen iPhones.
- The platform leverages multi-channel communication, including AI-generated voice calls, emails, SMS, and WhatsApp, to create highly convincing recovery scams.
- Researchers identified a widespread network of 506 domains and 168 storefront brands associated with AnonyMousKIT, indicating a large-scale, organized operation.
- The primary goal is to disable Activation Lock on stolen iPhones, allowing them to be resold, but stolen Apple IDs also expose users to broader account compromise.
A new Phishing-as-a-Service (PhaaS) platform, dubbed AnonyMousKIT, is exploiting the distress of iPhone owners whose devices have been stolen. This service employs a sophisticated multi-channel approach, including AI-generated voice calls, to trick victims into divulging their Apple ID credentials and two-factor authentication (2FA) codes, ultimately enabling the unlocking and resale of stolen iPhones.
Table Of Content
The operation integrates various communication methods such as email, text messages, WhatsApp, and even recorded or AI-generated voice calls. These highly personalized messages often incorporate details like the specific iPhone model and its live status from the “Find My” service, lending an air of authenticity to the fraudulent recovery notifications at a time when owners are most vulnerable and eager to retrieve their lost devices.
Security researchers at SOCRadar said in a report that they have identified AnonyMousKIT as a credit-based service tailored for the illicit stolen-device market. Their in-depth analysis revealed shared code across an expansive network, encompassing 506 distinct domains and 168 storefront brands. This extensive infrastructure points to a broad reseller network rather than a limited, isolated phishing operation.
Beyond the immediate financial gain from reselling a device, a compromised Apple ID poses significant risks. It can grant criminals access to cloud backups, stored credentials, and even linked work email accounts. Furthermore, obtaining a live 2FA code allows attackers to complete account changes swiftly, often before the victim realizes the contact was fraudulent, exacerbating the potential for widespread data theft and identity compromise.

AI-Powered AnonyMousKIT PhaaS
The AnonyMousKIT attack chain begins by extracting specific details from a stolen iPhone, including its model, the owner’s contact information, and its current “Find My” status. This data is then used to craft a highly personalized lure, typically a message suggesting the device has been located, which directs the victim to a fake Apple-branded webpage.
While similar lost iPhone phishing campaigns have surfaced previously, exploiting the hope of device recovery, AnonyMousKIT distinguishes itself through its automated, multi-channel execution. The fraudulent webpage meticulously requests the device’s screen passcode, Apple ID, and a current six-digit 2FA code in a sequential manner.
Once these critical details are entered, they are reportedly transmitted in real-time to the operator’s control panel and Telegram webhooks. This immediate access allows the criminals to bypass Apple’s Activation Lock, effectively preparing the stolen device for quick resale on the black market.

A particularly insidious feature of this scheme is the use of voice calls to enhance its persuasiveness. The service employs an AI-generated persona, mimicking Apple Support, to describe a supposed device recovery case. During these calls, the AI prompts the owner to confirm a passcode and directs them to a link sent via text message. Analysis of 200 recorded AI calls revealed that 179 were placed to Brazilian numbers, underscoring how low-cost, automated calling can enable personalized scams at scale.
Email remains a significant vector for the campaign, with 603 out of 691 attempted messages successfully reaching inboxes between March and July 2026. Most of these successful phishing emails originated from free Gmail relay services and utilized deceptive display names such as “Find My” or “Apple Support.” This tactic mirrors recent AI voice phishing attacks aimed at pressuring victims into revealing authentication data.
Network Shows Industrial Scale
A critical coding error by the AnonyMousKIT operators inadvertently exposed production logs and internal records, providing researchers with an unprecedented glimpse into the service’s supply chain, customer activity, and operational infrastructure. These exposed records detailed 30 distinct backend installations across 42 domains, with 41 active backends identified within the broader network at the time of analysis.
One notable cluster operated three separate storefronts simultaneously, all leveraging shared Gmail relays. The oldest identified installation appeared to shift its focus to WhatsApp-based lures after its email relay system failed. This modular and adaptable setup significantly lowers the technical barrier for individuals seeking to operate device-unlocking scams.
.webp)
Subscribers to AnonyMousKIT can input victim details once and then use a centralized panel to deploy phishing lures across multiple communication channels. This mirrors the service model of
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.