AnonyMousKIT: AI-Powered PhaaS Automates iPhone Unlocking and Data Theft
A sophisticated phishing-as-a-service (PhaaS) platform, **AnonyMousKIT**, is leveraging AI voice agents to automate the retrieval of passcodes for stolen **Apple** devices. This illicit service facilitates a sprawling ecosystem for selling unlocked iPhones and harvesting sensitive user data, including **Apple IDs** and **iCloud** credentials.
A new phishing-as-a-service (PhaaS) platform, **AnonyMousKIT**, has emerged, specializing in the automated retrieval of unlock codes for stolen **Apple** devices and the disabling of the **Activation Lock** feature. Active since early 2024, this illegal service underpins a structured ecosystem dedicated to the sale of stolen iPhones, harvesting **Apple IDs**, and accessing **iCloud** backups and **Keychain** credentials.
Researchers at threat intelligence platform **SOCRadar** managed to gain insights into the platform's operations, its operators, and infrastructure by exploiting the use of bare relative paths.
**SOCRadar** discovered that **AnonyMousKIT** is linked to 506 domains and powers a substantial illicit business involving 168 storefront brands acting as resellers.

The researchers recovered records of 200 calls made to victims between August 2025 and May 2026. These calls utilized 55 distinct interaction transcripts handled by a voice AI agent operating under five different personas.
**SOCRadar** noted that these calls cost the operator approximately $0.10 per attempt, with 90% of the calls directed to Brazil.
.jpg)
### Retrieving Unlocking Codes
**Apple's Activation Lock** feature automatically engages when the **Find My** tracking service is enabled, linking an **iPhone** to its ownerβs **Apple Account**. Even after a factory reset, a stolen device remains tied to the original owner's account, requiring a valid authorization code for initial setup.
This robust protection feature means many stolen iPhones are sold for parts. However, their value significantly increases if they can be unlocked, especially when sensitive user data can also be recovered.
**AnonyMousKIT** extracts information from stolen devices, such as the ownerβs contact details provided via the **Lost Mode** feature. This information is then used to contact the owner through email, SMS, WhatsApp, or phone calls.
The phishing messages impersonate **Apple**, falsely claiming the missing device has been located. They include accurate model and **IMEI** details to enhance legitimacy.

The email directs victims to a fake **Find My** or **Apple** page, prompting them to enter their device passcode, **Apple Account** credentials, and two-factor authentication code.
In some cases analyzed by **SOCRadar**, an AI agent, using the persona βAlice from **Apple Support**,β informs victims that someone attempting to unlock the phone brought it to an **Apple** store, where it was retained. The AI agent then asks the victim to confirm ownership by dictating the passcode, subsequently directing them to the phishing page.
Once threat actors obtain these codes, they can access the victim's personal data, factory reset the device, and remove it from the **Find My** app before selling it.

A compromised **Apple ID** could expose **iCloud** backups, **Keychain** passwords, work email, and other corporate information stored on personal or employer-issued **Apple** devices, as **SOCRadar** warns. The researchers noted that a small percentage of emails from the platform were sent to government and corporate organizations.
**SOCRadar** reports that the campaigns facilitated by **AnonyMousKIT** had a global footprint, with higher concentrations in South Africa, Indonesia, Italy, India, Kenya, and Brazil.