AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhones — Threadlinqs Intelligence
As of 2026-08-25, AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhones is a high-severity phishing threat attributed to Unknown (AnonyMousKIT developer, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 13 indicators of compromise.
Threat ID: TL-2026-2141 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Unknown (AnonyMousKIT developer · FINANCIAL
SOCRadar's Threat Research Unit (STRU) exposed AnonyMousKIT, an AI-powered Phishing-as-a-Service platform that turns Apple's Activation Lock into a subscription-based crime: operators load a stolen
AnonyMousKIT is an AI-powered Phishing-as-a-Service (PhaaS) platform, disclosed by SOCRadar's Threat Research Unit (STRU) on 2026-08-24, that exists specifically to steal the Apple ID credential and device passcode a criminal needs to clear Activation Lock on a stolen iPhone and resell or trade it, including on marketplaces such as Telegram. STRU traces the underlying kit family back to at least February 2024, with active operations continuing through August 2026 (panel logs record operator activity as recently as 2026-08-10). The business model is credit-metered/pay-per-message: a buyer (typically a phone thief or a reseller downstream of one) enters the stolen device's details into a web panel once, and the platform then runs an automated, multi-channel harassment campaign against the device's original owner across email, SMS (smishing), WhatsApp, an automated recorded phone call, and an AI-generated voice phone call — continuing until the victim responds.
The lures are device-led: rather than generic phishing bait, each message cites the phone's real Apple model identifier (e.g., iPhone16,2) and its live Find My location, both pulled directly off the physically stolen device, which lends the lure false legitimacy. The phishing landing pages carry that device-led deception further with anti-bot checks, localized/multilingual content, and an interactive animated map that renders the handset's real-time Find My status and location to build trust and urgency before sequentially harvesting the device passcode, then the Apple ID credentials, then a live 2FA code — each captured value forwarded from the page to both the operator's panel and a Telegram webhook. Across 30 related backends, researchers identified 6,092 phishing emails sent targeting 5,031 devices marked online and 1,035 locked devices; those email backends run on 24 identified SMTP instances, 12 of which share an identical developer test pattern that STRU used to fingerprint a single core developer behind the platform.
The AI voice channel goes further, renting commercial conversational AI agents from VAPI.ai and scripting them as 'Alice from Apple Support,' delivered in English, Spanish, and Portuguese; 'Alice' confirms ownership of the stolen device, claims Apple recovered the missing phone, and talks the victim into reading their 4-6 digit passcode (or a 2FA code) aloud before redirecting them to a phishing link to capture their Apple ID credentials. SOCRadar recovered 200 call records and 55 transcripts — including the agents' underlying prompts — directly from the VAPI.ai account, with 179 of the 200 calls (roughly 90%) placed to Brazilian numbers. The economics make indiscriminate targeting viable: the operator's cost for those 200 AI voice calls was only $19.24 total, about ten cents per call.
STRU's disclosure resulted from a basic backend coding mistake: two exposed relative file paths, left accessible without authentication, handed researchers months of production logs, which traced a single storefront back to a shared codebase powering 506 domains under 168 distinct brand names — evidence of a reseller network rebranding the same kit. The leaked logs reveal a four-tier criminal supply chain beneath that storefront layer: a single developer (fingerprinted via the shared SMTP test pattern); a reseller tier of 506 domains / 168 brands built on the shared codebase; an operator tier of 689 distinct WhatsApp accounts running phishing operations across the 30-backend family; and a buyer tier of 27 paying email-based customers sourced from a pool of 120 WhatsApp users. A scan found 30 backend instances still active across 42 of those domains at the time of research.
While the kit's stated purpose is unlocking stolen consumer iPhones, STRU's research documents lures sent to 27 South African government email addresses and a local South African university — targeting that extends the risk beyond individual device theft victims. Because a personal Apple ID can be
Target sectors: government administration, education, consumer
Target regions: south africa, brazil
Timeline
- SOCRadar's Threat Research Unit traces the underlying AnonyMousKIT phishing-kit family back to at least February 2024, the earliest activity identified in the leaked production logs.
- Panel logs recovered by SOCRadar record AnonyMousKIT operator activity as recently as 2026-08-10, the most recent dated activity identified in the leaked production logs prior to publication.
- As of SOCRadar's last collection date prior to publication, the AnonyMousKIT PhaaS storefront network and its shared codebase remain live and operational across the identified domains.
- SOCRadar's Threat Research Unit (STRU) traces the exposed storefront back to a single shared codebase powering 506 domains under 168 distinct brand names, with 30 backend instances confirmed still active across 42 of those domains.
- STRU discloses that a backend coding mistake — two exposed relative file paths — leaked months of AnonyMousKIT production logs, exposing the identities and activity of its developer, resellers, and operators.
- STRU maps the leaked logs into a four-tier criminal supply chain: a single developer (fingerprinted via a shared SMTP test pattern across 12 of 24 backends), a 506-domain/168-brand reseller tier, a 689-account WhatsApp operator tier, and a 27-buyer purchaser tier drawn from 120 WhatsApp users.
- SOCRadar's research documents AnonyMousKIT phishing lures sent to 27 South African government email addresses and a local South African university.
- SOCRadar publishes 'Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain' on the SOCRadar blog, disclosing the platform's architecture, scale, and the operators/resellers exposed via the leaked logs.
- itnerd.blog publishes same-day coverage summarizing SOCRadar's AnonyMousKIT findings, extending public visibility of the disclosure.
- CyberInsider and Cybernews publish independent follow-on coverage of SOCRadar's AnonyMousKIT research, adding detail on the VAPI.ai-hosted 'Alice' voice-AI persona and the 6,092 phishing emails identified across 30 related backends.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 13 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1598, T1583, T1608, T1585, T1566, T1684.001, T1056, T1567, T1657