Find notable cyber news and cases, enriched with sources, timelines, and signals.

AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network

Threat Actor Meta
First reported
Last updated
Happening score
H score 40
2 unique sources, 2 articles

Summary

Hide ▲

AnonyMousKIT is a phishing-as-a-service ecosystem that uses AI voice agents and multi-channel lures to steal Apple device passcodes, Apple ID credentials, and 2FA codes from owners of recently lost or stolen Apple devices. SOCRadar says the platform is credit-metered, runs across email, SMS, WhatsApp, and voice, and uses stolen-device details such as the handset’s Apple model identifier and Find My status to drive victims to Apple-branded capture pages. The report also describes a shared-codebase network with 30 distinct installations reachable on 42 domains, while the broader family was scanned at 506 kit-family domains. The latest analysis says the platform was still running at the end of the review and that SOCRadar continues to track its sibling storefronts and wider shared-codebase family.

Related Happenings

AnonyMousKIT voice-AI phishing campaign against Apple device owners

Campaign
H score32 First: 25.08.2026 23:25 Last: 25.08.2026 23:25 Sources 1

How related: Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.

About this happening: SOCRadar disclosed AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents and other channels to impersonate Apple Support and target owners o...

RecruitTrap fake recruiter corporate credential phishing campaign

Campaign
H score7 First: 25.08.2026 16:00 Last: 25.08.2026 16:00 Sources 1

About this happening: RecruitTrap is a targeted phishing campaign impersonating employers and recruiters to steal corporate credentials on mobile devices. The operation uses full-scre...

GHOSTBLADE credential-stealing activity on Apple iOS

Malware Activity
H score34 First: 03.08.2026 13:49 Last: 03.08.2026 13:49 Sources 1

About this happening: The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...

Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service

Threat Actor Meta
H score36 First: 19.02.2026 14:00 Last: 19.02.2026 14:00 Sources 1

About this happening: The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...

Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse

Malware Activity
H score31 First: 12.02.2026 16:25 Last: 12.02.2026 16:25 Sources 1

About this happening: Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...

Timeline

  1. 25.08.2026 23:25 3 articles · 13d ago

    AnonyMousKIT PhaaS automates stolen iPhone unlocking and credential theft

    Initial Disclosure

    SOCRadar uncovered a phishing-as-a-service platform called AnonyMousKIT that automates retrieval of codes used to unlock stolen Apple devices and disable Activation Lock. The service has been active since early 2024 and supports a structured ecosystem that sells stolen iPhones, harvests Apple IDs, and accesses iCloud backups and Keychain credentials. SOCRadar tied the platform to 506 domains and 168 storefront brands acting as resellers, and recovered records of 200 victim calls between August 2025 and May 2026 handled by a voice AI agent using five personas; the calls cost about $0.10 per attempt and 90% were made to Brazil. The campaigns had a global footprint with heavier concentration in South Africa, Indonesia, Italy, India, Kenya, and Brazil.

    Show sources