AnonyMousKIT PhaaS Automates Phishing for iPhone Unlock Codes

AnonyMousKIT PhaaS Automates Phishing for iPhone Unlock Codes

First seen 26 Aug 2026, 15:18 UTC BleepingcomputerFeeds2.Feedburner 63.5

Article Content

Browse articles
ThreatCluster

The AnonyMousKIT phishing-as-a-service (PhaaS) platform has been identified as automating the theft of Apple ID credentials necessary to bypass Activation Lock on stolen iPhones. Active since early 2024, this service has created a network of 506 domains and 168 storefronts. Researchers from SOCRadar discovered that the platform uses voice AI agents to impersonate Apple Support, conducting phishing calls primarily targeting victims in Brazil. Between August 2025 and May 2026, 200 calls were recorded, with AI agents using five distinct personas to extract sensitive information. The phishing attempts involve fake emails and messages that appear legitimate, prompting victims to enter their passcodes and Apple ID credentials. The compromised accounts can lead to unauthorized access to iCloud backups and other sensitive data. The platform's operational flaws were exploited by researchers, revealing its extensive infrastructure and operational details. The ongoing campaigns have also targeted government and corporate organizations, increasing the potential impact of the phishing attacks.

Key Points: • AnonyMousKIT automates phishing for Apple ID credentials using AI. • The platform has a network of 506 domains and 168 storefronts since early 2024. • 90% of phishing calls were made to victims in Brazil, with significant data exposure risks.

Timeline

2024-01-01
AnonyMousKIT platform launched
The phishing-as-a-service platform began operations, targeting Apple device users.
BleepingComputer
2025-08-01
Phishing campaigns recorded
SOCRadar documented 200 phishing calls made to victims, primarily in Brazil, using AI impersonation tactics.
BleepingComputer
2026-05-01
Research findings published
SOCRadar published findings on AnonyMousKIT's operational methods and infrastructure.
BleepingComputer
2026-08-25
BleepingComputer article published
BleepingComputer reported on the AnonyMousKIT platform, detailing its phishing methods and impact.
BleepingComputer
2026-08-26
HelpNetSecurity article published
HelpNetSecurity provided additional coverage on AnonyMousKIT, confirming its phishing operations and AI usage.
Feeds2.Feedburner