Cybersecurity researchers from SOCRadar Threat Research Unit (STRU) have uncovered a phishing-as-a-service (PhaaS) platform called AnonyMousKIT designed to bypass Apple's Activation Lock on stolen devices. The platform uses rented AI voice agents to call theft victims, impersonating Apple Support, and tricks them into revealing their device passcode and two-factor authentication codes. The service operates on a credit-metered model, lowering the barrier for cybercriminals to conduct sophisticated social engineering attacks. By obtaining the passcode and 2FA codes, attackers can disable Activation Lock and fully take over stolen Apple devices. This represents a significant evolution in vishing (voice phishing) attacks, leveraging AI to scale and automate deceptive phone calls. The campaign highlights growing abuse of AI voice technology in cybercrime and the increasing sophistication of PhaaS platforms targeting Apple ecosystem users.
AnonyMousKIT is a Phishing-as-a-Service (PhaaS) platform tracked by SOCRadar STRU, designed to bypass Apple Activation Lock on stolen iOS devices. It operates on a credit-metered model with five attack channels per victim: email (1.50 credits), SMS (variable), WhatsApp, recorded voice call (1 credit), and AI voice agent via Vapi platform (2 credits). The AI voice agent impersonates 'Alice from Apple Support' in English, Spanish, and Portuguese. The attack sequence requests the 4- or 6-digit device passcode, Apple ID credentials, and live 2FA codes from theft victims. Lures include the device's internal Apple model identifier and live Find My status pulled from the stolen device. Email lures use tokenized URLs (/help?TOKEN) and animated maps showing the device's reported location. 200 AI voice calls were recorded between August 31, 2025 and May 30, 2026, with 179 targeting Brazilian numbers, at a total cost of $19.24 (~9.6 cents per call). A vulnerability in the kit's shared codebase exposes logs via two bare relative file paths accessible unauthenticated via HTTP, allowing SOCRadar to access the operator's data. A scan identified 506 kit-family domains with 30 distinct installations on 42 domains, 188 live. The platform logged 691 send attempts (one installation) vs 6,092 across 30 backends. Three storefronts (i-Blocker, Key Unlock, KG-KING) launched simultaneously on April 10, 2026, sharing Gmail relay accounts, suggesting one operator running multiple brands. 5,649 of 6,092 targeted devices (92.7%) run A12 silicon or newer, making advertised unlock tools largely ineffective as bait. A public bootrom exploit (USBLiter8) for A12/A13 was released June 18, 2026 but requires physical access, DFU mode, and does not bypass Secure Enclave, passcode, or Activation Lock.
1. Never provide your device passcode, Apple ID password, or 2FA code to anyone claiming to be Apple Support — Apple will never ask for these. 2. Forward Apple-branded phishing emails and texts to reportphishing@apple.com. 3. Move high-value Apple IDs to physical hardware security keys (FIDO2) to completely mitigate real-time 2FA interception. 4. Be suspicious of unsolicited calls, emails, or SMS messages claiming your device has been found. 5. Verify any support contact by calling Apple directly via official channels (apple.com/contact). 6. Organizations should monitor for the identified IOCs including the Gmail relay account and known domain patterns. 7. Security teams should block or alert on domains matching the AnonyMousKIT family patterns identified in SOCRadar and Infoblox research. 8. Report suspected vishing calls to Apple and local authorities. 9. Infoblox published a list of 4,244 malicious domains detected between March 2022 and May 2026 that can be used for blocking.
noreplyapple00000[@]gmail[.]com (Gmail relay account used for phishing sends), Email subject: 'Your device has been found', Email subject: 'Alert', Display names: Apple, Find My, Apple Support, Apple Assistance, URL pattern: /help?TOKEN (tokenized capture pages), 506 kit-family domains identified (188 live), 30 distinct installations across 42 domains, Storefronts: i-Blocker, Key Unlock, KG-KING (launched April 10, 2026)