Actor Profile
AnonyMousKIT is a phishing-as-a-service (PhaaS) platform active since early 2024, operated by unknown threat actors who provide automated infrastructure for stealing iPhone passcodes and disabling Apple's Activation Lock. The platform supports a structured criminal ecosystem with 168 storefront brands acting as resellers of unlocked stolen devices. The operation is financially motivated, targeting Apple device owners globally to monetize stolen hardware by bypassing security features and harvesting credentials. SOCRadar attributed the platform through OPSEC failures including exposed relative paths in the operator's infrastructure, revealing connections to 506 domains.
TTPs (Tactics, Techniques, Procedures)
AnonyMousKIT employs social engineering (T1598 - Phishing for Information) via multiple channels including email, SMS, WhatsApp, and voice calls. The platform leverages AI-powered voice agents using personas such as "Alice from Apple Support" to conduct vishing attacks (T1566.004 - Phishing: Spearphishing Voice). Phishing pages impersonate legitimate Apple services (T1566.002 - Phishing: Spearphishing Link) to harvest device passcodes, Apple Account credentials, and two-factor authentication codes (T1111 - Multi-Factor Authentication Interception). The operation exploits Apple's Lost Mode feature to retrieve victim contact information for targeting. Post-compromise activities include credential harvesting for iCloud backups and Keychain access, factory resets to remove Activation Lock, and device removal from Find My tracking.
Targets & Patterns
Primary targets are individual owners of stolen Apple iPhones, with 90% of observed voice calls directed at victims in Brazil between August 2025 and May 2026. Geographic concentration includes South Africa, Indonesia, Italy, India, Kenya, and Brazil, indicating global reach with regional focus. While predominantly targeting consumers in the mobile device sector, SOCRadar identified a small percentage of phishing emails sent to government and corporate organizations, creating risk of corporate data exposure through compromised personal or employer-issued devices. The targeting pattern is opportunistic, driven by the theft of physical devices rather than pre-selected victim profiles, though the infrastructure scales to support mass phishing operations across 168 reseller brands.
Historical Context
AnonyMousKIT has been operational since early 2024, representing an evolution in PhaaS platforms by integrating voice AI agents for automated social engineering. SOCRadar recovered records of 200 calls made between August 2025 and May 2026, utilizing 55 distinct interaction transcripts across five AI personas. The platform's economic model charges approximately $0.10 per call attempt, demonstrating a low-cost, high-volume approach. The service parallels other PhaaS platforms such as Kratos, Forg365, and Bluekit in providing turnkey phishing infrastructure, but distinguishes itself through specialized focus on Apple device security bypass and integration of voice-based AI automation. The 506 connected domains and 168 reseller storefronts indicate sustained growth and maturation of the criminal operation over its two-year lifespan.
Defensive Recommendations
- Educate users that Apple will never proactively call or email requesting device passcodes, Apple ID credentials, or 2FA codes; implement security awareness training specifically addressing vishing and AI-generated voice impersonation
- Monitor for phishing domains impersonating Apple services (icloud.com, apple.com) using brand monitoring tools and DNS threat intelligence feeds; block known AnonyMousKIT infrastructure domains at email gateways and web proxies
- Deploy email security controls to detect phishing messages containing device-specific details (IMEI, model numbers) combined with urgency tactics and links to non-Apple domains
- Implement conditional access policies requiring phishing-resistant authentication (FIDO2/WebAuthn) for Apple ID and corporate accounts to mitigate credential theft even when users are socially engineered
- For organizations issuing Apple devices, enforce Mobile Device Management (MDM) policies that prevent users from disabling Find My, and monitor for unauthorized device removals from corporate Apple Business Manager accounts
