AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhones
AnonyMousKIT (TL-2026-2141) is a high-severity phishing campaign, first published 2026-08-24. It has no confirmed attribution, affects Apple Apple ID / iCloud Activation Lock (Find My iPhone) on lost or, maps to 10 MITRE ATT&CK techniques (T1056, T1566, T1567), and is covered by 9 detection rules and 13 indicators of compromise.
Key facts for TL-2026-2141
- Threat ID
- TL-2026-2141
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-24
- Last reviewed
- 2026-08-24
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, education, consumer
- Target regions
- south africa, brazil
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in AnonyMousKIT
Malware and tooling: AnonyMousKIT
SOCRadar's Threat Research Unit (STRU) exposed AnonyMousKIT, an AI-powered Phishing-as-a-Service platform that turns Apple's Activation Lock into a subscription-based crime: operators load a stolen iPhone's real model number and live Find My location into a panel, then automated email, SMS, WhatsApp, recorded-call, and AI-voice ('Alice from Apple Support') lures run until the owner is tricked into surrendering their Apple ID and passcode. A backend misconfiguration leaked months of production logs, exposing a shared codebase running 506 domains under 168 brand names across a four-tier criminal supply chain (developer, resellers, 689 WhatsApp operator accounts, and paying buyers), including lures sent to 27 South African government email addresses and a local university.
How AnonyMousKIT works
AnonyMousKIT is an AI-powered Phishing-as-a-Service (PhaaS) platform, disclosed by SOCRadar's Threat Research Unit (STRU) on 2026-08-24, that exists specifically to steal the Apple ID credential and device passcode a criminal needs to clear Activation Lock on a stolen iPhone and resell or trade it, including on marketplaces such as Telegram. STRU traces the underlying kit family back to at least February 2024, with active operations continuing through August 2026 (panel logs record operator activity as recently as 2026-08-10). The business model is credit-metered/pay-per-message: a buyer (typically a phone thief or a reseller downstream of one) enters the stolen device's details into a web panel once, and the platform then runs an automated, multi-channel harassment campaign against the device's original owner across email, SMS (smishing), WhatsApp, an automated recorded phone call, and an AI-generated voice phone call — continuing until the victim responds.
The lures are device-led: rather than generic phishing bait, each message cites the phone's real Apple model identifier (e.g., iPhone16,2) and its live Find My location, both pulled directly off the physically stolen device, which lends the lure false legitimacy. The phishing landing pages carry that device-led deception further with anti-bot checks, localized/multilingual content, and an interactive animated map that renders the handset's real-time Find My status and location to build trust and urgency before sequentially harvesting the device passcode, then the Apple ID credentials, then a live 2FA code — each captured value forwarded from the page to both the operator's panel and a Telegram webhook. Across 30 related backends, researchers identified 6,092 phishing emails sent targeting 5,031 devices marked online and 1,035 locked devices; those email backends run on 24 identified SMTP instances, 12 of which share an identical developer test pattern that STRU used to fingerprint a single core developer behind the platform.
The AI voice channel goes further, renting commercial conversational AI agents from VAPI.ai and scripting them as 'Alice from Apple Support,' delivered in English, Spanish, and Portuguese; 'Alice' confirms ownership of the stolen device, claims Apple recovered the missing phone, and talks the victim into reading their 4-6 digit passcode (or a 2FA code) aloud before redirecting them to a phishing link to capture their Apple ID credentials. SOCRadar recovered 200 call records and 55 transcripts — including the agents' underlying prompts — directly from the VAPI.ai account, with 179 of the 200 calls (roughly 90%) placed to Brazilian numbers. The economics make indiscriminate targeting viable: the operator's cost for those 200 AI voice calls was only $19.24 total, about ten cents per call.
STRU's disclosure resulted from a basic backend coding mistake: two exposed relative file paths, left accessible without authentication, handed researchers months of production logs, which traced a single storefront back to a shared codebase powering 506 domains under 168 distinct brand names — evidence of a reseller network rebranding the same kit. The leaked logs reveal a four-tier criminal supply chain beneath that storefront layer: a single developer (fingerprinted via the shared SMTP test pattern); a reseller tier of 506 domains / 168 brands built on the shared codebase; an operator tier of 689 distinct WhatsApp accounts running phishing operations across the 30-backend family; and a buyer tier of 27 paying email-based customers sourced from a pool of 120 WhatsApp users. A scan found 30 backend instances still active across 42 of those domains at the time of research.
While the kit's stated purpose is unlocking stolen consumer iPhones, STRU's research documents lures sent to 27 South African government email addresses and a local South African university — targeting that extends the risk beyond individual device theft victims. Because a personal Apple ID can be tied to a device's Keychain, a successful takeover of a government or university employee's personal Apple ID creates a plausible path to exposure of corporate credentials synced to that Keychain, an organizational risk distinct from the underlying stolen-phone fraud.
No CVE, CVSS score, or software vulnerability is associated with this threat — AnonyMousKIT is a social-engineering/PhaaS operation, not an exploit against a technical flaw in Apple's platform; the only technical weakness in the reporting is the operators' own exposed relative file paths, which is what enabled the disclosure.
MITRE ATT&CK techniques used in TL-2026-2141
Credential Access
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Impact
Defense Evasion
Affected products and versions in AnonyMousKIT
- Apple — Apple ID / iCloud Activation Lock (Find My iPhone) on lost or stolen iPhones
Vulnerable versions: Any iPhone with Activation Lock/Find My enabled that has been lost or stolen and whose original owner can be reached via email, SMS, WhatsApp, or phone
Remediation for AnonyMousKIT
Immediate actions
- Treat any unsolicited email, SMS, WhatsApp message, recorded call, or AI-voice call that references your iPhone's exact model number or live Find My location as a phishing attempt, not proof of Apple/carrier legitimacy — that data can be read directly off a physically stolen device.
- Never enter your Apple ID password or read your device passcode/2FA code aloud in response to an inbound call, text, or message; contact Apple only through apple.com or the built-in Support app.
- Report and block the sending numbers, WhatsApp accounts, and domains used in the lure, and forward phishing emails to reportphishing@apple.com.
Workarounds
- Enable Apple ID two-factor authentication and Stolen Device Protection, and treat any request to disclose a 2FA code or passcode over a call as fraudulent by default.
- Do not engage with automated or AI-voice calls claiming to be Apple Support about a lost/stolen device; hang up and initiate contact with Apple independently.
Longer-term hardening
- Train government/university staff and general users that AI-voice ('Apple Support') and recorded-call phishing is now automated and cheap enough to run at scale (~$0.10/call), so voice alone is not a trust signal.
- For lost/stolen devices, use Apple's official 'Report a lost or stolen device' / Find My workflow directly rather than any link supplied by an inbound message or call.
- Audit and rotate any corporate credentials stored in Keychain and synced to a personal Apple ID for staff who may have been targeted, since a compromised personal Apple ID can expose corporate secrets stored in that Keychain.
Timeline of AnonyMousKIT
- SOCRadar's Threat Research Unit traces the underlying AnonyMousKIT phishing-kit family back to at least February 2024, the earliest activity identified in the leaked production logs.
- Panel logs recovered by SOCRadar record AnonyMousKIT operator activity as recently as 2026-08-10, the most recent dated activity identified in the leaked production logs prior to publication.
- itnerd.blog publishes same-day coverage summarizing SOCRadar's AnonyMousKIT findings, extending public visibility of the disclosure.
- SOCRadar publishes 'Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain' on the SOCRadar blog, disclosing the platform's architecture, scale, and the operators/resellers exposed via the leaked logs.
- SOCRadar's research documents AnonyMousKIT phishing lures sent to 27 South African government email addresses and a local South African university.
- STRU maps the leaked logs into a four-tier criminal supply chain: a single developer (fingerprinted via a shared SMTP test pattern across 12 of 24 backends), a 506-domain/168-brand reseller tier, a 689-account WhatsApp operator tier, and a 27-buyer purchaser tier drawn from 120 WhatsApp users.
- STRU discloses that a backend coding mistake — two exposed relative file paths — leaked months of AnonyMousKIT production logs, exposing the identities and activity of its developer, resellers, and operators.
- SOCRadar's Threat Research Unit (STRU) traces the exposed storefront back to a single shared codebase powering 506 domains under 168 distinct brand names, with 30 backend instances confirmed still active across 42 of those domains.
- As of SOCRadar's last collection date prior to publication, the AnonyMousKIT PhaaS storefront network and its shared codebase remain live and operational across the identified domains.
- CyberInsider and Cybernews publish independent follow-on coverage of SOCRadar's AnonyMousKIT research, adding detail on the VAPI.ai-hosted 'Alice' voice-AI persona and the 6,092 phishing emails identified across 30 related backends.
Sources cited for AnonyMousKIT
- Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
- SOCRadar Uncovers AI-Powered PhaaS "AnonyMousKIT" Stealing Apple IDs/Passwords
- AnonyMousKIT Campaign Details — SOCRadar LABS
- AnonyMousKIT service uses AI calls to unlock stolen Apple devices
- Hackers using fake "Apple Support" calls to unlock stolen iPhones
- SOCRadar — "AI is now cold-calling iPhone theft victims" (AnonyMousKIT disclosure thread)
More in phishing
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google API Open-Redirect and nxcli.io Infrastructure
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data
Detection coverage for TL-2026-2141
As of 2026-08-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2141 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.