AnonyMousKIT phishing-as-a-service platform automates Apple ID credential theft using AI voice agents to bypass stolen iPhone activation locks.
A newly investigated phishing-as-a-service (PhaaS) platform designated as AnonyMousKIT is automating the acquisition of Apple ID credentials to remove Activation Lock from stolen iPhones, according to threat intelligence findings published by SOCRadar. Operating since early 2024, the operation spans a reseller supply chain incorporating 506 distinct domains and 168 individual storefront brands. Despite leveraging advanced artificial intelligence to impersonate Apple Support, fundamental coding errors within the platform exposed production logs and operator rosters.
Researchers recovered 200 call logs and 55 transcripts detailing automated voice interactions used to target victims by phone. The campaign heavily targeted Brazil, accounting for 179 of the 200 recorded calls, which cost a combined total of $19.24. The platform deployed five distinct voice-agent personas configured across English, Spanish, and Brazilian Portuguese, with three operational personas utilizing the alias “Alice Dias, Apple Support.”
Apple’s Activation Lock security feature, integrated since iOS 7, binds a device directly to an owner’s Apple ID upon activation of Find My. This security measure prevents factory-reset devices from being reused without valid authentication, historically forcing stolen hardware into black-market part scavenging unless credential harvesting succeeds. AnonyMousKIT bridges this gap by offering a commercial pay-per-action platform tailored for thieves lacking technical device-unlocking capabilities.
“By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mimic ‘Apple Support,’ basic coding errors exposed production logs and operator rosters,” researchers stated.
Subscribers to the platform input a compromised device’s serial number or IMEI to retrieve live Find My tracking status and hardware models. Automated workflows then contact victims via email, SMS, WhatsApp, pre-recorded audio, or real-time AI voice calls. Researchers noted that targeting recent victims during active loss searches maximizes social engineering success by weaponizing verified hardware context.
The structured voice scripts direct victims to supply four- or six-digit passcodes under the premise that an unauthorized party attempted an in-store device recovery at an Apple retail location. Once the passcode is captured, agents prompt victims to interact with an SMS security link to finalize the unlock procedure. SOCRadar classified the enterprise as a specialized software business servicing criminal operators rather than a conventional phishing kit.