Apple: AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones

Apple: AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones

AI-Powered Phishing Service AnonyMousKIT Targets Stolen iPhones with Sophisticated Social Engineering

Researchers have identified AnonyMousKIT, an AI-driven Phishing-as-a-Service (PhaaS) platform designed to help criminals unlock and resell stolen Apple devices. The service exploits Apple’s Activation Lock, a security feature that renders stolen iPhones unusable without the owner’s credentials, by tricking victims into surrendering their passcodes, Apple ID passwords, and two-factor authentication (2FA) codes through social engineering.

Operating as a credit-based criminal marketplace, AnonyMousKIT allows subscribers to input details of stolen devices including model, owner information, and Find My status to generate customized phishing lures. These attacks deploy multi-channel deception, including:

  • AI voice calls (using personas like "Alice," an alleged Apple Support agent, in English, Spanish, and Brazilian Portuguese)
  • SMS, WhatsApp, and email (sent via free Gmail accounts with Apple-themed display names)
  • Fake "device found" alerts and urgent "Apple Support" notifications

Between August 2025 and May 2026, the platform logged 200 AI voice calls, primarily targeting Brazilian phone numbers, at an average cost of 10 cents per attempt. Email-based attacks surged between March and July 2026, with 691 recorded send attempts using subject lines like "Your device has been found" and "Alert."

AnonyMousKIT is part of a larger criminal ecosystem, sharing a codebase with 506 domains and 168 storefront brands. Researchers uncovered 30 backend installations across 42 domains, revealing 389 WhatsApp operator accounts and evidence of shared management among multiple criminal resellers. A coding error exposed operational logs, including email activity, AI-call artifacts, and Telegram webhooks used to transmit stolen credentials to criminal panels.

The phishing flow employs tokenized links and fake Apple pages with simulated location data to build trust before prompting victims for sensitive information. Once obtained, the data enables attackers to bypass Activation Lock and resell the devices. The low cost and automation of AnonyMousKIT lower the barrier for criminals, increasing the scale and efficiency of iPhone theft schemes.

Source: https://cyberpress.org/anonymouskit-unlocks-stolen-iphones/

Apple cybersecurity rating report: https://www.rankiteo.com/company/apple

"id": "APP1787819560",
"linkid": "apple",
"type": "Cyber Attack",
"date": "8/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '200+ AI voice call targets, '
                                              '691+ email-based attack '
                                              'attempts',
                        'location': 'Brazil',
                        'name': 'Apple device owners (primarily in Brazil)',
                        'type': 'Individuals'}],
 'attack_vector': ['AI voice calls', 'SMS', 'WhatsApp', 'Email', 'Fake alerts'],
 'data_breach': {'data_exfiltration': 'Transmitted to criminal panels via '
                                      'Telegram webhooks',
                 'personally_identifiable_information': 'Yes (Apple ID '
                                                        'credentials, 2FA '
                                                        'codes)',
                 'sensitivity_of_data': 'High (PII, authentication '
                                        'credentials)',
                 'type_of_data_compromised': ['Passcodes',
                                              'Apple ID credentials',
                                              '2FA codes']},
 'date_detected': '2025-08-01',
 'description': 'Researchers identified AnonyMousKIT, an AI-driven '
                'Phishing-as-a-Service (PhaaS) platform designed to help '
                'criminals unlock and resell stolen Apple devices by tricking '
                'victims into surrendering passcodes, Apple ID passwords, and '
                '2FA codes through multi-channel social engineering attacks.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to Apple '
                                       'due to exploitation of Activation Lock',
            'data_compromised': ['Passcodes',
                                 'Apple ID passwords',
                                 'Two-factor authentication (2FA) codes'],
            'identity_theft_risk': 'High (PII exposure)',
            'operational_impact': 'Bypass of Activation Lock enabling resale '
                                  'of stolen devices',
            'systems_affected': ['Stolen iPhones']},
 'initial_access_broker': {'backdoors_established': 'Fake Apple support pages, '
                                                    'tokenized links',
                           'entry_point': 'Stolen iPhones with Activation Lock',
                           'high_value_targets': 'Apple device owners '
                                                 '(especially in Brazil)'},
 'investigation_status': 'Ongoing (researchers uncovered operational logs and '
                         'backend installations)',
 'lessons_learned': 'AI-driven phishing services lower the barrier for '
                    'criminals, increasing the scale and efficiency of device '
                    'theft schemes. Multi-channel deception (voice, SMS, '
                    'email) enhances attack success rates.',
 'motivation': ['Financial gain', 'Resale of stolen devices'],
 'post_incident_analysis': {'corrective_actions': ['Apple to strengthen '
                                                   'Activation Lock against '
                                                   'social engineering',
                                                   'Telecom providers to '
                                                   'detect and block AI voice '
                                                   'phishing calls',
                                                   'User education on '
                                                   'recognizing phishing '
                                                   'attempts across channels'],
                            'root_causes': ['Exploitation of Apple’s '
                                            'Activation Lock via social '
                                            'engineering',
                                            'Low-cost, automated AI-driven '
                                            'phishing tools (AnonyMousKIT)',
                                            'Multi-channel deception (voice, '
                                            'SMS, email) increasing attack '
                                            'success']},
 'recommendations': ['Enhance Apple Activation Lock security to resist social '
                     'engineering',
                     'Improve detection of AI-generated voice phishing calls',
                     'Educate users on recognizing multi-channel phishing '
                     'attempts',
                     'Monitor criminal marketplaces for emerging PhaaS '
                     'platforms'],
 'references': [{'source': 'Researchers (unspecified)'}],
 'response': {'third_party_assistance': 'Researchers (unspecified)'},
 'threat_actor': 'AnonyMousKIT (criminal marketplace operators and resellers)',
 'title': 'AI-Powered Phishing Service AnonyMousKIT Targets Stolen iPhones '
          'with Sophisticated Social Engineering',
 'type': 'Phishing-as-a-Service (PhaaS)',
 'vulnerability_exploited': 'Apple’s Activation Lock'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.