AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network
Threat Actor Meta
Summary
Hide ▲
Show ▼
Researchers uncovered AnonyMousKIT, a phishing-as-a-service ecosystem that automates stolen-iPhone unlocking and expands credential theft across a reseller network, increasing the risk of Activation Lock bypass and Apple ID compromise. The operation has been active since early 2024 and extends beyond device theft into access to iCloud backups and Keychain data. Its footprint spans 506 domains and 168 storefront brands, showing a scaled underground service rather than a single phishing site. The use of voice AI agents and global targeting, with heavy concentration in Brazil, raises the likelihood of repeated abuse against both consumer and workplace accounts.
Related Happenings
AnonyMousKIT voice-AI phishing campaign against Apple device owners
Campaign
H score30
First: 25.08.2026 23:25
Last: 25.08.2026 23:25
Sources 1
How related:
The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.
About this happening:
A campaign run by AnonyMousKIT used voice AI personas to phish Apple device owners and steal passcodes, expanding a documented operation that made 200 calls fr...
AnonyMousKIT voice-AI phishing campaign against Apple device owners
CampaignHow related: The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.
About this happening: A campaign run by AnonyMousKIT used voice AI personas to phish Apple device owners and steal passcodes, expanding a documented operation that made 200 calls fr...
RecruitTrap fake recruiter corporate credential phishing campaign
Campaign
H score7
First: 25.08.2026 16:00
Last: 25.08.2026 16:00
Sources 1
About this happening:
RecruitTrap is a targeted phishing campaign impersonating employers and recruiters to steal corporate credentials on mobile devices. The operation uses full-scre...
RecruitTrap fake recruiter corporate credential phishing campaign
CampaignAbout this happening: RecruitTrap is a targeted phishing campaign impersonating employers and recruiters to steal corporate credentials on mobile devices. The operation uses full-scre...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware Activity
H score34
First: 03.08.2026 13:49
Last: 03.08.2026 13:49
Sources 1
About this happening:
The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware ActivityAbout this happening: The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service
Threat Actor Meta
H score36
First: 19.02.2026 14:00
Last: 19.02.2026 14:00
Sources 1
About this happening:
The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...
Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service
Threat Actor MetaAbout this happening: The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...
ZeroDayRAT mobile spyware advertisement
Malware Activity
H score26
First: 10.02.2026 15:00
Last: 10.02.2026 15:00
Sources 1
About this happening:
The ZeroDayRAT mobile spyware platform is being advertised on Telegram as a commercial toolkit for Android and iOS devices, with support for Android 5 through 16...
ZeroDayRAT mobile spyware advertisement
Malware ActivityAbout this happening: The ZeroDayRAT mobile spyware platform is being advertised on Telegram as a commercial toolkit for Android and iOS devices, with support for Android 5 through 16...
Timeline
-
25.08.2026 23:25 2 articles · 2h ago
AnonyMousKIT PhaaS automates stolen iPhone unlocking and credential theft
Initial DisclosureSOCRadar uncovered a phishing-as-a-service platform called AnonyMousKIT that automates retrieval of codes used to unlock stolen Apple devices and disable Activation Lock. The service has been active since early 2024 and supports a structured ecosystem that sells stolen iPhones, harvests Apple IDs, and accesses iCloud backups and Keychain credentials. SOCRadar tied the platform to 506 domains and 168 storefront brands acting as resellers, and recovered records of 200 victim calls between August 2025 and May 2026 handled by a voice AI agent using five personas; the calls cost about $0.10 per attempt and 90% were made to Brazil. The campaigns had a global footprint with heavier concentration in South Africa, Indonesia, Italy, India, Kenya, and Brazil.
Show sources
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — www.bleepingcomputer.com — 25.08.2026 23:25
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — www.bleepingcomputer.com — 25.08.2026 23:25