Find notable cyber news and cases, enriched with sources, timelines, and signals.

AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network

Threat Actor Meta
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

Researchers uncovered AnonyMousKIT, a phishing-as-a-service ecosystem that automates stolen-iPhone unlocking and expands credential theft across a reseller network, increasing the risk of Activation Lock bypass and Apple ID compromise. The operation has been active since early 2024 and extends beyond device theft into access to iCloud backups and Keychain data. Its footprint spans 506 domains and 168 storefront brands, showing a scaled underground service rather than a single phishing site. The use of voice AI agents and global targeting, with heavy concentration in Brazil, raises the likelihood of repeated abuse against both consumer and workplace accounts.

Related Happenings

AnonyMousKIT voice-AI phishing campaign against Apple device owners

Campaign
H score30 First: 25.08.2026 23:25 Last: 25.08.2026 23:25 Sources 1

How related: The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.

About this happening: A campaign run by AnonyMousKIT used voice AI personas to phish Apple device owners and steal passcodes, expanding a documented operation that made 200 calls fr...

RecruitTrap fake recruiter corporate credential phishing campaign

Campaign
H score7 First: 25.08.2026 16:00 Last: 25.08.2026 16:00 Sources 1

About this happening: RecruitTrap is a targeted phishing campaign impersonating employers and recruiters to steal corporate credentials on mobile devices. The operation uses full-scre...

GHOSTBLADE credential-stealing activity on Apple iOS

Malware Activity
H score34 First: 03.08.2026 13:49 Last: 03.08.2026 13:49 Sources 1

About this happening: The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...

Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service

Threat Actor Meta
H score36 First: 19.02.2026 14:00 Last: 19.02.2026 14:00 Sources 1

About this happening: The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...

ZeroDayRAT mobile spyware advertisement

Malware Activity
H score26 First: 10.02.2026 15:00 Last: 10.02.2026 15:00 Sources 1

About this happening: The ZeroDayRAT mobile spyware platform is being advertised on Telegram as a commercial toolkit for Android and iOS devices, with support for Android 5 through 16...

Timeline

  1. 25.08.2026 23:25 2 articles · 2h ago

    AnonyMousKIT PhaaS automates stolen iPhone unlocking and credential theft

    Initial Disclosure

    SOCRadar uncovered a phishing-as-a-service platform called AnonyMousKIT that automates retrieval of codes used to unlock stolen Apple devices and disable Activation Lock. The service has been active since early 2024 and supports a structured ecosystem that sells stolen iPhones, harvests Apple IDs, and accesses iCloud backups and Keychain credentials. SOCRadar tied the platform to 506 domains and 168 storefront brands acting as resellers, and recovered records of 200 victim calls between August 2025 and May 2026 handled by a voice AI agent using five personas; the calls cost about $0.10 per attempt and 90% were made to Brazil. The campaigns had a global footprint with heavier concentration in South Africa, Indonesia, Italy, India, Kenya, and Brazil.

    Show sources