AnonyMousKIT PhaaS Uses Voice AI to Steal iPhone Passcodes
A newly identified phishing-as-a-service (PhaaS) platform, known as AnonyMousKIT, is automating attacks designed to steal iPhone passcodes, Apple account credentials, and verification codes. The stolen information can help criminals bypass Activation Lock and resell compromised Apple devices.
The illegal service has reportedly been active since early 2024. It supports an organized cybercrime ecosystem involved in selling stolen iPhones, harvesting Apple IDs, accessing iCloud backups, and stealing passwords stored in Apple Keychain.
Researchers from threat intelligence company SOCRadar investigated the platform after discovering that its operators used exposed relative paths. This allowed researchers to gather information about AnonyMousKIT’s infrastructure, services, and affiliated operators.
SOCRadar found that AnonyMousKIT is connected to 506 domains and supports a large criminal business network involving 168 storefront brands that operate as resellers.

Source: SOCRadar
Researchers recovered records of 200 calls made to victims between August 2025 and May 2026. The calls were represented by 55 individual interaction recordings and were handled by voice AI agents operating under five different personas.
According to SOCRadar, each call cost the operators approximately $0.10. Around 90% of the analyzed calls targeted victims in Brazil.
.jpg)
Source: SOCRadar
How AnonyMousKIT Steals iPhone Unlock Codes
Apple’s Activation Lock is automatically enabled when the Find My service is turned on. The security feature links an iPhone to its owner’s Apple account and is designed to prevent unauthorized use after a device is lost or stolen.
Even after a factory reset, a protected iPhone remains linked to the original owner’s account. During setup, the device requires valid authorization from that account before it can be used.
Because of Activation Lock, many stolen iPhones are sold for parts. However, an unlocked device can be worth considerably more—particularly if criminals can also access the owner’s personal data.
AnonyMousKIT reportedly targets iPhones placed in Lost Mode. The platform enables attackers to contact device owners through email, text messages, WhatsApp, or phone calls.
The phishing messages impersonate Apple and claim that the missing iPhone has been found. Attackers include accurate details such as the device model and IMEI number to make the scam appear authentic.

Source: SOCRadar
The messages direct victims to fake Find My or Apple websites. These fraudulent pages ask users to enter their iPhone passcode, Apple account credentials, and two-factor authentication code.
In some cases examined by SOCRadar, an AI voice agent using the persona “Alice from Apple Support” told victims that someone had taken their iPhone to an Apple Store to unlock it and that the device was being held there.
The AI agent then instructed the victim to provide a passcode to verify ownership before redirecting them to a phishing page designed to capture the information.
Once criminals obtain the passcode and account credentials, they may be able to access personal data, erase the iPhone, disable Find My, and remove Activation Lock before reselling the device.

Source: SOCRadar
A compromised Apple ID could expose iCloud backups, Keychain passwords, work email accounts, and other sensitive corporate information stored on personal or employer-issued Apple devices, SOCRadar warns.
Researchers also found that a small number of phishing emails sent through the platform targeted government agencies and business organizations.
Although the AnonyMousKIT campaign is global, SOCRadar identified a stronger focus on victims in South Africa, Indonesia, Italy, India, Kenya, and Brazil.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




