AnonyMousKIT: AI-Enabled Phishing-as-a-Service Platform Automates Apple Activation Lock Bypass
AnonyMousKIT (TL-2026-2164), also tracked as AnonyMousKIT PhaaS, is a high-severity phishing campaign, first published 2026-08-27. It is attributed to AnonyMousTeam with low confidence, affects Apple iPhone (Activation Lock / Find My / Apple ID), maps to 11 MITRE ATT&CK techniques (T1056.003, T1111, T1566.002), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-2164
- Threat ID
- TL-2026-2164
- Also known as
- AnonyMousKIT PhaaS
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-27
- Last reviewed
- 2026-08-27
- Attribution
- AnonyMousTeam
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, education, corporate, consumer
- Target regions
- brazil, south africa, indonesia, italy, india, kenya
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in AnonyMousKIT
Malware and tooling: USBliter8, Vapi
AnonyMousKIT is an AI-powered Phishing-as-a-Service (PhaaS) ecosystem that automates the theft of device passcodes, Apple ID credentials, and live 2FA codes from stolen-iPhone owners in order to remove Activation Lock. SOCRadar's inside-out analysis, enabled by an OPSEC flaw in the shared codebase, mapped 506 linked domains, 168 reseller storefront brands, and 30 backend deployments active since at least early 2024, including a Vapi-hosted "Alice from Apple Support" AI vishing agent.
How AnonyMousKIT works
AnonyMousKIT is a credit-metered Phishing-as-a-Service platform built to defeat Apple's Activation Lock on stolen iPhones by extracting the three credentials required to disable it: the device passcode, the Apple ID username/password, and a live two-factor authentication code. Operators begin by profiling the stolen device itself — pulling its internal model identifier, Find My/Lost Mode status, and the owner's contact details directly off the handset — to build a credible fraudulent "your device has been found" narrative.
Victims are then pushed through a coordinated, five-channel pressure campaign combining email, SMS, WhatsApp, pre-recorded voice calls, and AI-driven vishing, so that if one channel is ignored another reinforces it. The email leg was largely relayed through a single free Gmail account, noreplyapple00000@gmail.com, disguised as an Apple no-reply sender. Messages and calls direct victims to spoofed Apple/Find My-branded web pages that display an animated device-location map and anti-bot checks before sequentially harvesting the passcode, Apple ID, and a live 2FA code.
The AI vishing component rents commercial conversational-voice infrastructure from Vapi to run five configured personas — all styled "Alice from Apple Support" (one build uses "Alice Dias") — operating in English, Spanish, and Brazilian Portuguese. The script has the agent claim the device was brought into an Apple Store and is being held pending verification, then walks the victim through confirming their four- or six-digit passcode and any SMS security codes. SOCRadar recovered 200 call records (August 31, 2025 – May 30, 2026) with 55 usable transcripts, at a total automation cost of $19.24 (~9.6 cents per call) — a cost low enough that operators had little incentive to pre-qualify targets. None of the 200 analyzed calls resulted in a confirmed passcode capture: 100 victims hung up, 48 hit silence timeouts, 24 did not answer, and 28 hit platform errors.
The platform operates as a three-tier criminal supply chain: developers build and maintain the shared codebase, licensed resellers operate 168 branded storefronts (a reseller/franchise model), and operators run the actual phishing campaigns against theft victims, paying per-channel credits (e.g., 1.50 credits per email, 2 credits per AI voice call). SOCRadar identified 30 distinct backend installations across 42 of the 506 scanned kit-family domains (188 found live), including named clusters UKT (the oldest backend), and the linked i-Realm/KG-KING cluster. Three storefront brands — i-Blocker, Key Unlock, and KG-KING — launched within the same second on 2026-04-10 and shared Gmail relay infrastructure, evidence SOCRadar cites as one buyer operating multiple storefront brands rather than independent customers. A single core AnonyMousKIT deployment logged 691 send attempts (649 delivered) between March and July 2026; the wider 30-backend family reached 6,092 targets, including 64 sends to non-consumer South African government domains, and tracked 5,031 devices as online and 1,035 as locked. Geographic targeting concentrated on Brazil (179 of 200 AI calls; ~90% of the recovered call set) with additional volume into South Africa, Indonesia, Italy, India, and Kenya, and touched government, education, and corporate mail domains.
Successful credential theft gives operators everything needed to disable Activation Lock, factory-reset the device, and remove it from Find My for resale — while also exposing the victim's iCloud backups, iCloud Keychain-stored passwords, and any corporate data or credentials synced to a personally owned or employer-issued handset. The control panel also advertises four proprietary unlock/support binaries (two developed in-house) and references the public USBliter8 bootrom exploit (released 2026-06-18, affecting Apple A12–A13 silicon); SOCRadar assesses these as "bait" add-ons, since USBliter8 requires physical DFU-mode possession and cannot itself recover a passcode or remove Activation Lock — 92.7% of devices in the tracked dataset run A12 silicon or newer, keeping social engineering as the only practical path to unlock.
SOCRadar's Threat Research Unit discovered and mapped the operation via a basic operational-security failure: two bare relative file paths in the platform's shared codebase resolve to the web root and grant unauthenticated HTTP access to production logs and operator rosters. Because every deployment inherits the shared codebase, the flaw exposed operational data across the wider kit family, not just a single storefront. SOCRadar references an operator handle, "Owner OF AnonyMousTeam," advertising the platform, but does not attribute the operation to a named group or nation-state.
MITRE ATT&CK techniques used in TL-2026-2164
Credential Access
T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception
Initial Access
T1566.002 Spearphishing Link; T1566.004 Spearphishing Voice
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1585.002 Email Accounts
Reconnaissance
T1589.002 Email Addresses; T1592.001 Hardware
Impact
Defense Evasion
Affected products and versions in AnonyMousKIT
- Apple — iPhone (Activation Lock / Find My / Apple ID)
Vulnerable versions: Stolen iPhones with Activation Lock enabled; 92.7% of devices in the tracked dataset run Apple A12 silicon or newer
Remediation for AnonyMousKIT
Immediate actions
- Report suspicious 'device found'/Activation-Lock recovery messages and calls to Apple via reportphishing@apple.com and never provide a device passcode, Apple ID password, or 2FA code over a call, SMS, or WhatsApp link.
- Block or flag the identified AnonyMousKIT-family domains (anomkit.shop, apple-login-imaps.com, apple-thailand.co, findsupport.live, irealm-server.com, uktservice.sa.com, apple-unlock.com) and the noreplyapple00000@gmail.com relay at email/web gateways.
- Treat unsolicited 'Apple Support' voice calls in English, Spanish, or Brazilian Portuguese claiming a found or retained device as vishing; hang up and contact Apple only through official channels.
Workarounds
- Enable iOS Stolen Device Protection / Lost Mode security delays so Apple ID and passcode changes require additional authentication after a device is reported lost or stolen.
- Do not use unlock-service or bootrom-exploit tools (e.g., the advertised USBliter8 access) offered by these platforms; researchers assess such tools as bait that cannot recover a passcode or remove Activation Lock without owner credentials.
Longer-term hardening
- Move high-value or corporate-linked Apple IDs to physical FIDO2 hardware security keys, which SOCRadar assesses as fully mitigating the real-time 2FA interception this funnel depends on.
- Extend security-awareness training for device-theft victims and IT/helpdesk staff to cover the five-channel (email/SMS/WhatsApp/voice/AI-vishing) pressure pattern so credential requests are recognized regardless of channel.
- Monitor for newly registered lookalike domains combining 'apple', 'find', 'unlock', or 'support' terms, given this kit family's demonstrated pattern of rapid, coordinated storefront domain registration.
Weaknesses (CWE) in AnonyMousKIT
CWE-451
Timeline of AnonyMousKIT
- SOCRadar assesses AnonyMousKIT-family infrastructure as active since at least early February 2024.
- Recovered call logs show the Vapi-hosted 'Alice from Apple Support' AI vishing agent beginning its tracked campaign window.
- The core AnonyMousKIT installation begins the March-July 2026 window in which it logs 691 phishing send attempts (649 delivered).
- Storefront brands i-Blocker, Key Unlock, and KG-KING launch within the same second and share Gmail relay infrastructure, indicating single-operator control of multiple brands.
- Recovered AI vishing call logs end, closing out the 200-call, 55-transcript dataset SOCRadar analyzed.
- The public USBliter8 bootrom exploit for Apple A12-A13 silicon is released; later advertised on AnonyMousKIT's control panel as an unlock tool despite requiring physical DFU-mode access and not recovering passcodes.
- The core AnonyMousKIT installation's tracked March-July 2026 send window closes.
- SOCRadar's Threat Research Unit publishes 'Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain,' disclosing the platform's operations, scale, and the bare-relative-path OPSEC flaw used to uncover it.
- Security media outlets (BleepingComputer, Help Net Security, CyberInsider, The Hacker News) publish coverage amplifying the SOCRadar findings.
- GBHackers publishes coverage of the AnonyMousKIT PhaaS platform and its Activation Lock bypass workflow.
Sources cited for AnonyMousKIT
- AnonyMousKIT PhaaS Platform Automates iPhone Activation Lock Bypass
- Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
- AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
- AnonyMousKIT service uses AI calls to unlock stolen Apple devices
- Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
- SOCRadar Uncovers AI-Powered PhaaS "AnonyMousKIT" Stealing Apple IDs/Passwords
More in phishing
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)
- Trezor, BitBox, and CoinTracking Subscribers Targeted by Phishing After Brevo SAML SSO Authorization-Boundary Breach
Detection coverage for TL-2026-2164
As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2164 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.