AnonyMousKIT is turning stolen iPhones into an entry point for account theft. The phishing-as-a-service platform targets people already searching for a lost device, then uses convincing recovery messages to capture the Apple ID credentials needed to remove Activation Lock.
The operation combines email, text messages, WhatsApp, recorded calls and AI-generated voice calls. Its messages can draw on the phone model and live Find My status, making a fake recovery notice feel believable at exactly the moment an owner is anxious to get a device back.
Researchers at SOCRadar identified the platform as a credit-based service built for the stolen-device market. Their analysis linked its shared code to 506 domains and 168 storefront brands, showing that the activity is a broader reseller network rather than a single phishing site.
SOCRadar said in a report shared with Cyber Security News (CSN) The risk extends beyond the resale value of a handset.
A stolen Apple ID can expose cloud backups, saved credentials and work email, while a live verification code lets criminals complete account changes before a victim realizes the contact was fraudulent.
AnonyMousKIT begins with details taken from a stolen device, including its model, owner contact data and Find My state. It then sends a location-themed lure that leads to a fake Apple-style page.
Similar lost iPhone phishing campaigns have exploited the hope of recovering a phone, but this service automates the process across several channels.
The page asks for the screen passcode, Apple ID and a current six-digit two-factor authentication code in sequence. Those details are reportedly sent to the operator panel and Telegram webhooks in real time, allowing criminals to disable Activation Lock and prepare the device for resale.
AnonyMousKIT Attack Lifecycle (Source – SOCRadar)
Voice calls make the scheme more persuasive. The service used an AI persona posing as Apple Support to describe a supposed recovery case, ask the owner to confirm a passcode and steer them toward a texted link.
Of 200 recorded AI calls, 179 were placed to Brazilian numbers, illustrating how low-cost automated calling can scale personal scams.
Email remained a major delivery route, with 603 of 691 logged attempts reaching inboxes from March through July 2026.
Most successful messages used a free Gmail relay and familiar display names such as Find My or Apple Support, a tactic that resembles recent AI voice phishing attacks designed to pressure victims into sharing authentication data.
The researchers found that a coding mistake exposed production logs and operator records, providing an unusual view of the service’s supply chain, customer activity and infrastructure.
The exposed records showed 30 distinct backend installations across 42 domains, with 41 active backends in the wider family at the time of analysis.
One cluster ran three storefronts launched at the same time with shared Gmail relays, while the oldest known installation appears to have concentrated on WhatsApp after its email relay failed. This setup matters because it reduces the skill needed to run a device-unlocking scam.
Subscribers can enter a victim’s details once and use a panel to push lures through several channels, similar to the service model behind phishing kits targeting organizations that package complex account theft into an accessible service. Organizations should not rely only on blocking known domains because the infrastructure rotates quickly.
The researchers recommend filtering newly registered domains, watching for tokenized Apple-themed links, and flagging lookalike display names sent through free mail providers. Strong mobile-device management can also restrict sideloaded tools and jailbreak attempts.
For individuals, the key rule is simple: a legitimate support team will not call to request a device passcode or a one-time verification code. If a phone is stolen, remotely wipe it where possible and reset the associated Apple ID promptly.
The practical checks in this iPhone phishing safety guide can help users verify links and report suspicious messages before an account takeover occurs. This also limits damage to linked workplace accounts.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Infrastructure | anomkit[.]shop | AnonyMousKIT infrastructure |
| Infrastructure | apple-login-imaps[.]com | AnonyMousKIT infrastructure |
| Infrastructure | apple-thailand[.]co | AnonyMousKIT infrastructure |
| Infrastructure | findsupport[.]live | AnonyMousKIT infrastructure |
| Infrastructure | irealm-server[.]com | AnonyMousKIT infrastructure |
| Cross-Brand Backend | uktservice[.]sa[.]com | Related backend |
| Cross-Brand Backend | apple-unlock[.]com | Related backend |
| Cross-Brand Backend | key-unlock[.]com | Related backend |
| Cross-Brand Backend | alxescript[.]info | Related backend |
| Cross-Brand Backend | spider-off-unlock[.]one | Related backend |
| Cross-Brand Backend | icloud-findmy[.]app | Related backend |
| Cross-Brand Backend | gon-unlocker[.]pro | Related backend |
| Cross-Brand Backend | zu7pl[.]pro | Related backend |
| Cross-Brand Backend | projectpartapple[.]com | Related backend |
| Cross-Brand Backend | kit-pro-bot[.]click | Related backend |
| Cross-Brand Backend | b.pro-center[.]my[.]id | Related backend |
| Cross-Brand Backend | center-one[.]online | Related backend |
| Backend Origin | 75[.]119[.]135[.]83 | Backend host IP |
| Developer IP | 27[.]34[.]73[.]22 | Reported developer-linked IP |
| Developer IP | 27[.]34[.]73[.]46 | Reported developer-linked IP |
| High-Volume Range | 197[.]235[.]0[.]0/16 | Reported high-volume network range |
| High-Volume Range | 5[.]90[.]0[.]0/16 | Reported high-volume network range |
| High-Volume Range | 5[.]91[.]0[.]0/16 | Reported high-volume network range |
| High-Volume Range | 181[.]170[.]142[.]0/24 | Reported high-volume network range |
| Shared Operator IP | 196[.]196[.]102[.]74 | Shared operator-linked IP |
| Sender / Relay | noreplyapple00000[@]gmail[.]com | Sender or SMTP relay account |
| Sender / Relay | replycareapple010[@]gmail[.]com | Sender or SMTP relay account |
| Sender / Relay | noreplyil[@]icloud[.]com | Sender or SMTP relay account |
| Sender / Relay | apple[.]nonreply[.]fmi[@]gmail[.]com | Sender or SMTP relay account |
| Sender / Relay | applerecoverymanager[@]gmail[.]com | Sender or SMTP relay account |
| Suspected Developer Identity | underc0deapple[@]gmail[.]com | Reported developer-linked account |
| Buyer / Operator Identity | xgodauth[@]gmail[.]com | Reported buyer or operator account |
| Buyer / Operator Identity | naitebrown93[@]gmail[.]com | Reported buyer or operator account |
| File Hash | 5ea22f9777a34f461840c2a3988c717c0f9e6ec4bd95420c | Reported file hash |
| File Hash | d9e2881d3aa1ea40928dac65405fbe7e36989cad51ab46d | Reported file hash |
| File Hash | 32fa60c9099f53f194a6a63c9341dd115434584e0890120b | Reported file hash |
| File Hash | 07d4a6ac925f9f7e63c7332df1995de03f514931e9d97cb3 | Reported file hash |
| File Hash | 2c790296b404b3e7592da37b15311507b0e55989e1628ee | Reported file hash |
| URL / Path Pattern | shorturl[.]at/gXV0Y | Reported shortened URL pattern |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…