AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network
Threat Actor Meta
Summary
Hide ▲
Show ▼
AnonyMousKIT is a phishing-as-a-service ecosystem that uses AI voice agents and multi-channel lures to steal Apple device passcodes, Apple ID credentials, and 2FA codes from owners of recently lost or stolen Apple devices. SOCRadar says the platform is credit-metered, runs across email, SMS, WhatsApp, and voice, and uses stolen-device details such as the handset’s Apple model identifier and Find My status to drive victims to Apple-branded capture pages. The report also describes a shared-codebase network with 30 distinct installations reachable on 42 domains, while the broader family was scanned at 506 kit-family domains. The latest analysis says the platform was still running at the end of the review and that SOCRadar continues to track its sibling storefronts and wider shared-codebase family.
Related Happenings
AnonyMousKIT voice-AI phishing campaign against Apple device owners
Campaign
H score32
First: 25.08.2026 23:25
Last: 25.08.2026 23:25
Sources 1
How related:
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.
About this happening:
SOCRadar disclosed AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents and other channels to impersonate Apple Support and target owners o...
AnonyMousKIT voice-AI phishing campaign against Apple device owners
CampaignHow related: Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.
About this happening: SOCRadar disclosed AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents and other channels to impersonate Apple Support and target owners o...
RecruitTrap fake recruiter corporate credential phishing campaign
Campaign
H score7
First: 25.08.2026 16:00
Last: 25.08.2026 16:00
Sources 1
About this happening:
RecruitTrap is a targeted phishing campaign impersonating employers and recruiters to steal corporate credentials on mobile devices. The operation uses full-scre...
RecruitTrap fake recruiter corporate credential phishing campaign
CampaignAbout this happening: RecruitTrap is a targeted phishing campaign impersonating employers and recruiters to steal corporate credentials on mobile devices. The operation uses full-scre...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware Activity
H score34
First: 03.08.2026 13:49
Last: 03.08.2026 13:49
Sources 1
About this happening:
The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware ActivityAbout this happening: The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service
Threat Actor Meta
H score36
First: 19.02.2026 14:00
Last: 19.02.2026 14:00
Sources 1
About this happening:
The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...
Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service
Threat Actor MetaAbout this happening: The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...
Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse
Malware Activity
H score31
First: 12.02.2026 16:25
Last: 12.02.2026 16:25
Sources 1
About this happening:
Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...
Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse
Malware ActivityAbout this happening: Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...
Timeline
-
25.08.2026 23:25 3 articles · 13d ago
AnonyMousKIT PhaaS automates stolen iPhone unlocking and credential theft
Initial DisclosureSOCRadar uncovered a phishing-as-a-service platform called AnonyMousKIT that automates retrieval of codes used to unlock stolen Apple devices and disable Activation Lock. The service has been active since early 2024 and supports a structured ecosystem that sells stolen iPhones, harvests Apple IDs, and accesses iCloud backups and Keychain credentials. SOCRadar tied the platform to 506 domains and 168 storefront brands acting as resellers, and recovered records of 200 victim calls between August 2025 and May 2026 handled by a voice AI agent using five personas; the calls cost about $0.10 per attempt and 90% were made to Brazil. The campaigns had a global footprint with heavier concentration in South Africa, Indonesia, Italy, India, Kenya, and Brazil.
Show sources
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — www.bleepingcomputer.com — 25.08.2026 23:25
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — www.bleepingcomputer.com — 25.08.2026 23:25
- Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes — thehackernews.com — 26.08.2026 08:47