Cyber Security News

AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones

AnonyMousKIT is turning stolen iPhones into an entry point for account theft. The phishing-as-a-service platform targets people already searching for a lost device, then uses convincing recovery messages to capture the Apple ID credentials needed to remove Activation Lock.

The operation combines email, text messages, WhatsApp, recorded calls and AI-generated voice calls. Its messages can draw on the phone model and live Find My status, making a fake recovery notice feel believable at exactly the moment an owner is anxious to get a device back.

Researchers at SOCRadar identified the platform as a credit-based service built for the stolen-device market. Their analysis linked its shared code to 506 domains and 168 storefront brands, showing that the activity is a broader reseller network rather than a single phishing site.

AnonyMousKIT Ecosystem Map (Source – SOCRadar)

SOCRadar said in a report shared with Cyber Security News (CSN) The risk extends beyond the resale value of a handset.

A stolen Apple ID can expose cloud backups, saved credentials and work email, while a live verification code lets criminals complete account changes before a victim realizes the contact was fraudulent.

AI-Powered AnonyMousKIT PhaaS

AnonyMousKIT begins with details taken from a stolen device, including its model, owner contact data and Find My state. It then sends a location-themed lure that leads to a fake Apple-style page.

Similar lost iPhone phishing campaigns have exploited the hope of recovering a phone, but this service automates the process across several channels.

The page asks for the screen passcode, Apple ID and a current six-digit two-factor authentication code in sequence. Those details are reportedly sent to the operator panel and Telegram webhooks in real time, allowing criminals to disable Activation Lock and prepare the device for resale.

AnonyMousKIT Attack Lifecycle (Source – SOCRadar)

Voice calls make the scheme more persuasive. The service used an AI persona posing as Apple Support to describe a supposed recovery case, ask the owner to confirm a passcode and steer them toward a texted link.

Of 200 recorded AI calls, 179 were placed to Brazilian numbers, illustrating how low-cost automated calling can scale personal scams.

Email remained a major delivery route, with 603 of 691 logged attempts reaching inboxes from March through July 2026.

Most successful messages used a free Gmail relay and familiar display names such as Find My or Apple Support, a tactic that resembles recent AI voice phishing attacks designed to pressure victims into sharing authentication data.

Network Shows Industrial Scale

The researchers found that a coding mistake exposed production logs and operator records, providing an unusual view of the service’s supply chain, customer activity and infrastructure.

The exposed records showed 30 distinct backend installations across 42 domains, with 41 active backends in the wider family at the time of analysis.

One cluster ran three storefronts launched at the same time with shared Gmail relays, while the oldest known installation appears to have concentrated on WhatsApp after its email relay failed. This setup matters because it reduces the skill needed to run a device-unlocking scam.

Subscribers can enter a victim’s details once and use a panel to push lures through several channels, similar to the service model behind phishing kits targeting organizations that package complex account theft into an accessible service. Organizations should not rely only on blocking known domains because the infrastructure rotates quickly.

The researchers recommend filtering newly registered domains, watching for tokenized Apple-themed links, and flagging lookalike display names sent through free mail providers. Strong mobile-device management can also restrict sideloaded tools and jailbreak attempts.

For individuals, the key rule is simple: a legitimate support team will not call to request a device passcode or a one-time verification code. If a phone is stolen, remotely wipe it where possible and reset the associated Apple ID promptly.

The practical checks in this iPhone phishing safety guide can help users verify links and report suspicious messages before an account takeover occurs. This also limits damage to linked workplace accounts.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Infrastructureanomkit[.]shopAnonyMousKIT infrastructure
Infrastructureapple-login-imaps[.]comAnonyMousKIT infrastructure
Infrastructureapple-thailand[.]coAnonyMousKIT infrastructure
Infrastructurefindsupport[.]liveAnonyMousKIT infrastructure
Infrastructureirealm-server[.]comAnonyMousKIT infrastructure
Cross-Brand Backenduktservice[.]sa[.]comRelated backend
Cross-Brand Backendapple-unlock[.]comRelated backend
Cross-Brand Backendkey-unlock[.]comRelated backend
Cross-Brand Backendalxescript[.]infoRelated backend
Cross-Brand Backendspider-off-unlock[.]oneRelated backend
Cross-Brand Backendicloud-findmy[.]appRelated backend
Cross-Brand Backendgon-unlocker[.]proRelated backend
Cross-Brand Backendzu7pl[.]proRelated backend
Cross-Brand Backendprojectpartapple[.]comRelated backend
Cross-Brand Backendkit-pro-bot[.]clickRelated backend
Cross-Brand Backendb.pro-center[.]my[.]idRelated backend
Cross-Brand Backendcenter-one[.]onlineRelated backend
Backend Origin75[.]119[.]135[.]83Backend host IP
Developer IP27[.]34[.]73[.]22Reported developer-linked IP
Developer IP27[.]34[.]73[.]46Reported developer-linked IP
High-Volume Range197[.]235[.]0[.]0/16Reported high-volume network range
High-Volume Range5[.]90[.]0[.]0/16Reported high-volume network range
High-Volume Range5[.]91[.]0[.]0/16Reported high-volume network range
High-Volume Range181[.]170[.]142[.]0/24Reported high-volume network range
Shared Operator IP196[.]196[.]102[.]74Shared operator-linked IP
Sender / Relaynoreplyapple00000[@]gmail[.]comSender or SMTP relay account
Sender / Relayreplycareapple010[@]gmail[.]comSender or SMTP relay account
Sender / Relaynoreplyil[@]icloud[.]comSender or SMTP relay account
Sender / Relayapple[.]nonreply[.]fmi[@]gmail[.]comSender or SMTP relay account
Sender / Relayapplerecoverymanager[@]gmail[.]comSender or SMTP relay account
Suspected Developer Identityunderc0deapple[@]gmail[.]comReported developer-linked account
Buyer / Operator Identityxgodauth[@]gmail[.]comReported buyer or operator account
Buyer / Operator Identitynaitebrown93[@]gmail[.]comReported buyer or operator account
File Hash5ea22f9777a34f461840c2a3988c717c0f9e6ec4bd95420cReported file hash
File Hashd9e2881d3aa1ea40928dac65405fbe7e36989cad51ab46dReported file hash
File Hash32fa60c9099f53f194a6a63c9341dd115434584e0890120bReported file hash
File Hash07d4a6ac925f9f7e63c7332df1995de03f514931e9d97cb3Reported file hash
File Hash2c790296b404b3e7592da37b15311507b0e55989e1628eeReported file hash
URL / Path Patternshorturl[.]at/gXV0YReported shortened URL pattern

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

3 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

3 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago