AnonyMousKIT voice-AI phishing campaign against Apple device owners
Campaign
Summary
Hide ▲
Show ▼
A campaign run by AnonyMousKIT used voice AI personas to phish Apple device owners and steal passcodes, expanding a documented operation that made 200 calls from August 2025 to May 2026. The activity matters because the fake Apple contact flow can lead to Apple Account takeover, Activation Lock bypass, and device resale. SOCRadar also found the operation had a global footprint, with heavier targeting in Brazil and several other countries.
Related Happenings
AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network
Threat Actor Meta
H score36
First: 25.08.2026 23:25
Last: 25.08.2026 23:25
Sources 1
How related:
The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials.
About this happening:
Researchers uncovered AnonyMousKIT, a phishing-as-a-service ecosystem that automates stolen-iPhone unlocking and expands credential theft across a reseller network, increa...
AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network
Threat Actor MetaHow related: The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials.
About this happening: Researchers uncovered AnonyMousKIT, a phishing-as-a-service ecosystem that automates stolen-iPhone unlocking and expands credential theft across a reseller network, increa...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware Activity
H score34
First: 03.08.2026 13:49
Last: 03.08.2026 13:49
Sources 1
About this happening:
The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware ActivityAbout this happening: The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
AI-driven attack surge against customer-facing mobile apps in 2026
Trend
H score43
First: 19.05.2026 15:00
Last: 19.05.2026 15:00
Sources 1
About this happening:
Customer-facing mobile apps faced a sharp rise in attacks in 2026, with 87% of monitored apps hit versus 55% in 2022. The trend matters because agentic AI is l...
AI-driven attack surge against customer-facing mobile apps in 2026
TrendAbout this happening: Customer-facing mobile apps faced a sharp rise in attacks in 2026, with 87% of monitored apps hit versus 55% in 2022. The trend matters because agentic AI is l...
Bitter Middle East spear-phishing campaign targeting civil society figures
Campaign
H score28
First: 09.04.2026 13:45
Last: 09.04.2026 13:45
Sources 1
About this happening:
A spear-phishing campaign targeted civil society figures in Middle Eastern countries, including three journalists in Egypt and Lebanon, creating account-compromise ris...
Bitter Middle East spear-phishing campaign targeting civil society figures
CampaignAbout this happening: A spear-phishing campaign targeted civil society figures in Middle Eastern countries, including three journalists in Egypt and Lebanon, creating account-compromise ris...
ZeroDayRAT mobile spyware advertisement
Malware Activity
H score26
First: 10.02.2026 15:00
Last: 10.02.2026 15:00
Sources 1
About this happening:
The ZeroDayRAT mobile spyware platform is being advertised on Telegram as a commercial toolkit for Android and iOS devices, with support for Android 5 through 16...
ZeroDayRAT mobile spyware advertisement
Malware ActivityAbout this happening: The ZeroDayRAT mobile spyware platform is being advertised on Telegram as a commercial toolkit for Android and iOS devices, with support for Android 5 through 16...
Timeline
-
25.08.2026 23:25 2 articles · 2h ago
AnonyMousKIT phishes Apple device owners with voice AI agents
Initial DisclosureSOCRadar analyzed a newly uncovered phishing-as-a-service platform called AnonyMousKIT that uses voice AI agents to phish iPhone passcodes and Apple Account credentials so stolen Apple devices can be unlocked and Activation Lock can be bypassed. The platform had been active since early 2024, was linked to 506 domains and 168 storefront brands, and supported a structured ecosystem that sells stolen iPhones while harvesting Apple IDs, iCloud backups, and Keychain credentials.
Show sources
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — www.bleepingcomputer.com — 25.08.2026 23:25
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — www.bleepingcomputer.com — 25.08.2026 23:25