Feeds2.Feedburner
AnonyMousKIT PhaaS Automates Phishing for iPhone Unlock Codes
Article Content
The AnonyMousKIT phishing-as-a-service (PhaaS) platform has been identified as automating the theft of Apple ID credentials necessary to bypass Activation Lock on stolen iPhones. Active since early 2024, this service has created a network of 506 domains and 168 storefronts. Researchers from SOCRadar discovered that the platform uses voice AI agents to impersonate Apple Support, conducting phishing calls primarily targeting victims in Brazil. Between August 2025 and May 2026, 200 calls were recorded, with AI agents using five distinct personas to extract sensitive information. The phishing attempts involve fake emails and messages that appear legitimate, prompting victims to enter their passcodes and Apple ID credentials. The compromised accounts can lead to unauthorized access to iCloud backups and other sensitive data. The platform's operational flaws were exploited by researchers, revealing its extensive infrastructure and operational details. The ongoing campaigns have also targeted government and corporate organizations, increasing the potential impact of the phishing attacks.
Key Points: • AnonyMousKIT automates phishing for Apple ID credentials using AI. • The platform has a network of 506 domains and 168 storefronts since early 2024. • 90% of phishing calls were made to victims in Brazil, with significant data exposure risks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.