AnonyMousKIT voice-AI phishing campaign against Apple device owners
Campaign
Summary
Hide ▲
Show ▼
SOCRadar disclosed AnonyMousKIT, a phishing-as-a-service platform that uses AI voice agents and other channels to impersonate Apple Support and target owners of recently lost or stolen Apple devices. The campaign asks for the 4- or 6-digit device passcode, then Apple ID credentials and a live 2FA code, with Activation Lock as the main unlock target. SOCRadar said the AI voice channel had 200 call records, 55 transcripts, and five personas recovered from a commercial voice platform account, with the calls running from August 31, 2025 to May 30, 2026 and 179 of 200 going to numbers in Brazil. The report also says the platform used credit-metered lures across email, SMS, WhatsApp, recorded voice calls, and AI voice agents, and that logs were exposed through a shared-codebase flaw allowing unauthenticated HTTP access.
Related Happenings
AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network
Threat Actor Meta
H score40
First: 25.08.2026 23:25
Last: 25.08.2026 23:25
Sources 1
How related:
The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials.
About this happening:
AnonyMousKIT is a phishing-as-a-service ecosystem that uses AI voice agents and multi-channel lures to steal Apple device passcodes, Apple ID credentials, and...
AnonyMousKIT PhaaS ecosystem expands stolen-iPhone unlocking reseller network
Threat Actor MetaHow related: The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials.
About this happening: AnonyMousKIT is a phishing-as-a-service ecosystem that uses AI voice agents and multi-channel lures to steal Apple device passcodes, Apple ID credentials, and...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware Activity
H score34
First: 03.08.2026 13:49
Last: 03.08.2026 13:49
Sources 1
About this happening:
The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware ActivityAbout this happening: The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
Beats Studio Buds Bluetooth BR/EDR missing-authentication security flaw (multiple vulnerabilities)
Vulnerability
H score24
First: 18.06.2026 15:23
Last: 18.06.2026 15:23
Sources 1
About this happening:
Beats Studio Buds are affected by CVE-2025-20701, a missing-authentication flaw in Airoha system-on-a-chip (SoCs) and the Bluetooth BR/EDR radio that can let a...
Beats Studio Buds Bluetooth BR/EDR missing-authentication security flaw (multiple vulnerabilities)
VulnerabilityAbout this happening: Beats Studio Buds are affected by CVE-2025-20701, a missing-authentication flaw in Airoha system-on-a-chip (SoCs) and the Bluetooth BR/EDR radio that can let a...
AI-driven attack surge against customer-facing mobile apps in 2026
Trend
H score43
First: 19.05.2026 15:00
Last: 19.05.2026 15:00
Sources 1
About this happening:
Customer-facing mobile apps faced a sharp rise in attacks in 2026, with 87% of monitored apps hit versus 55% in 2022. The trend matters because agentic AI is l...
AI-driven attack surge against customer-facing mobile apps in 2026
TrendAbout this happening: Customer-facing mobile apps faced a sharp rise in attacks in 2026, with 87% of monitored apps hit versus 55% in 2022. The trend matters because agentic AI is l...
Bitter Middle East spear-phishing campaign targeting civil society figures
Campaign
H score28
First: 09.04.2026 13:45
Last: 09.04.2026 13:45
Sources 1
About this happening:
A spear-phishing campaign targeted civil society figures in Middle Eastern countries, including three journalists in Egypt and Lebanon, creating account-compromise ris...
Bitter Middle East spear-phishing campaign targeting civil society figures
CampaignAbout this happening: A spear-phishing campaign targeted civil society figures in Middle Eastern countries, including three journalists in Egypt and Lebanon, creating account-compromise ris...
Timeline
-
25.08.2026 23:25 3 articles · 13d ago
AnonyMousKIT phishes Apple device owners with voice AI agents
Initial DisclosureSOCRadar analyzed a newly uncovered phishing-as-a-service platform called AnonyMousKIT that uses voice AI agents to phish iPhone passcodes and Apple Account credentials so stolen Apple devices can be unlocked and Activation Lock can be bypassed. The platform had been active since early 2024, was linked to 506 domains and 168 storefront brands, and supported a structured ecosystem that sells stolen iPhones while harvesting Apple IDs, iCloud backups, and Keychain credentials.
Show sources
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — www.bleepingcomputer.com — 25.08.2026 23:25
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — www.bleepingcomputer.com — 25.08.2026 23:25
- Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes — thehackernews.com — 26.08.2026 08:47