AnonyMousKIT subscriber (operator)
At a Glance
| Actor/Group | AnonyMousKIT; a reseller supply chain with a developer, buyers, and hundreds of operators |
| Activity | Credit-metered AI-powered PhaaS to harvest Apple credentials and disable Activation Lock |
| Targets | Owners of stolen or lost Apple devices, plus some government and education inboxes |
| Scale | 506 domains, 168 storefront brands, 6,092 phishing emails, 200 AI calls; active since February 2024 |
| Status | No law-enforcement action reported; platform live through August 2026 |
| Source | SOCRadar Threat Research Unit (STRU) |
TL;DR
An AI-powered PhaaS platform called AnonyMousKIT calls iPhone theft victims while posing as Apple Support. Its rented voice agents extract passcodes and 2FA codes to remove Apple’s Activation Lock from stolen devices. SOCRadar cracked the operation open after a basic coding flaw exposed its logs and operators.
What Happened
SOCRadar’s Threat Research Unit ran an “inside-out” analysis of the platform. The team read backend source code, production logs, and operator consoles. It even pulled AI voice prompts and call transcripts.
AnonyMousKIT targets the stolen Apple device market. Apple’s Activation Lock ties hardware to an Apple ID. A stolen iPhone stays bricked without the owner’s credentials. So thieves pay this AI-powered PhaaS to trick victims into handing those credentials over.
The platform runs on credits. An operator enters a stolen device’s serial or IMEI once. The kit then pulls the model and live Find My status. From there, it fires lures across five channels: email, SMS, WhatsApp, recorded calls, and AI voice agents.
The AI Voice Calls
The voice channel is the standout. SOCRadar recovered 200 call logs and 55 transcripts. The agent used a persona named “Alice Dias, Apple Support” in English, Spanish, and Portuguese.
The script is tight. It confirms ownership, then requests the four or six-digit passcode. Next, it spins a fake in-store recovery case. Finally, it guides the victim to a phishing link mid-call.
The economics are grim. Over 200 calls, 90% aimed at Brazil, cost just $19.24 total. That works out to roughly ten cents per attempt. As SOCRadar notes, there is “no economic pressure to be selective.”
Who Is Behind It
SOCRadar frames AnonyMousKIT as a business, not a lone crew. The report calls it best understood “not as a phishing kit but as a small software business with a criminal customer base.” Attribution to a named person stays open.
The structure splits into tiers. A single developer builds and sells the platform. Buyers then license backends to run branded storefronts. Operators sit below them, sending the lures.
The logs exposed the layers. One buyer, “Cluster B,” allegedly launched three storefronts on the same second on April 10, 2026. They shared Gmail relays and operators. As SOCRadar puts it, “they are not three customers; they are one buyer operating three storefronts.” SOCRadar redacted operator email handles here, so no personal data beyond what the researchers published appears.
Impact and Scale
The reach is wide. A shared codebase links 506 domains and 168 storefront brands. Across 30 backends, SOCRadar counted 6,092 phishing emails. Those hit 5,031 devices marked online and 1,035 marked locked.
The deception often worked. Nearly 97.7% of delivered emails relayed through a single free Gmail account disguised as Apple no-reply support. Simple tricks beat filters on small mobile screens.
The risk goes past phones. Harvested Apple IDs can expose iCloud backups and Keychain credentials. For AnonyMousKIT alone, 9.3% of traffic hit non-consumer domains, including 27 sends to South African government addresses.
How to Stay Protected
Treat any “device found” message with doubt. Apple does not call to ask for your passcode. Never share a passcode or 2FA code by phone or text.
Report a stolen device through official Apple channels only. Keep Find My on and Activation Lock engaged. Enable strong two-factor protection on your Apple ID.
For defenders, block the listed indicators and watch for Apple-themed lookalike domains. This AI-powered PhaaS shows how cheap voice AI now fuels fraud. Awareness and slow, careful verification remain the best guard.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!