AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. The illegal service has been active since early 2024 and is powering a structured eco…
Intelligence analysis by Llama

Researchers at SOCRadar took advantage of the platform operator's use of bare relative paths to gather information on how the service works, its operators, and infrastructure. The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.
Imagine you lost your iPhone and someone found it. They might try to unlock it using a special code. AnonyMousKIT is a service that helps these people unlock stolen iPhones by using fake emails and phone calls to trick the owner into giving them the code. This is like a digital key that can unlock the phone and access all the owner's information.
Analysis
AnonyMousKIT's Business Model
AnonyMousKIT is a phishing-as-a-service (PhaaS) platform that has been active since early 2024. The platform automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. This allows attackers to sell stolen iPhones, harvest Apple IDs, access iCloud backups, and Keychain credentials.
How AnonyMousKIT Works
Researchers at SOCRadar took advantage of the platform operator's use of bare relative paths to gather information on how the service works, its operators, and infrastructure. The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.
Attack Chain
The attack chain involves the following steps:
- A compromised Apple ID is used to access the victim's iCloud account.
- The attacker uses the Apple ID to access the victim's Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices.
- The attacker then uses the Keychain passwords to access the victim's iCloud backups and Keychain credentials.
- The attacker uses the iCloud backups and Keychain credentials to factory reset the device and remove it from the Find My app.
- The attacker then sells the device, potentially leading to data breaches and identity theft.
Prevention
SOCRadar warns that a compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices. The researchers found that a small percentage of the emails from the platform were sent to government and corporate organizations.
Global Footprint
SOCRadar reports that the campaigns facilitated by the AnonyMousKIT had a global footprint, but were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil.
Key points
- AnonyMousKIT is a phishing-as-a-service (PhaaS) platform that automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.
- The platform has been active since early 2024 and has a global footprint, with a concentration in South Africa, Indonesia, Italy, India, Kenya, and Brazil.
- SOCRadar recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.
- The attack chain involves compromised Apple IDs, iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices.
- SOCRadar warns that a compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices.
If the authorities can identify and shut down AnonyMousKIT, it could prevent further data breaches and identity theft. Additionally, if Apple can improve its security measures, such as making it harder for attackers to access iCloud backups and Keychain credentials, it could reduce the effectiveness of AnonyMousKIT.
If AnonyMousKIT continues to operate, it could lead to a significant increase in data breaches and identity theft. Additionally, if the attackers can improve their methods, such as using more sophisticated phishing emails and phone calls, it could make it harder for victims to detect and prevent the attacks.



