Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Did Republicans vote against a bill banning child marriage in Wisconsin?

    August 25, 2026

    There’s no place like a revered writer’s home | Museums

    August 25, 2026

    US-led Gaza peace board warns Hamas over kites after Israeli threat

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Did Republicans vote against a bill banning child marriage in Wisconsin?
    • There’s no place like a revered writer’s home | Museums
    • US-led Gaza peace board warns Hamas over kites after Israeli threat
    • Australia confronts its missile shortfall
    • Why do some Labour MPs want electoral reform and will it happen? | Electoral reform
    • Labour MPs will push Burnham to back voting reform in first 100 days | Andy Burnham
    • Foot Locker owner plunges after warning nervous consumers are cutting spending
    • GeForce Now is getting support for the Steam Controller
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.

    The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials.

    Researchers at threat intelligence platform SOCRadar took advantage of the platform operator’s use of bare relative paths to gather information on how the service works, its operators, and infrastructure.

    image

    SOCRadar found that AnonyMousKIT is connected to 506 domains and is fueling a sprawling business with 168 storefront brands acting as resellers.

    Overview of the operation
    Overview of the operation
    Source: SOCRadar

    The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.

    SOCRadar notes that the calls cost the operator about $0.10 per attempt, adding that 90% of the calls were made to Brazil.

    The AnonyMousKIT panel
    The AnonyMousKIT panel
    Source: SOCRadar

    Retrieving unlocking codes

    Apple’s Activation Lock feature activates automatically when the Find My tracking service is turned on, and links the iPhone device to the owner’s Apple Account.

    Even if a stolen device is factory-reset, it remains linked to the original owner’s account and requires a valid authorization code during first setup before it can be used.

    Because of this protection feature, many stolen iPhones are sold for parts. However, their value increases significantly if they can be unlocked, especially when sensitive data belonging to the owner can also be recovered.

    AnonyMousKIT retrieves information from stolen devices, such as the owner’s contact information supplied through the Lost Mode feature, and uses it to contact the owner through email, SMS, WhatsApp, or a phone call.

    The phishing messages impersonate Apple and claim that the missing device has been located, providing the correct model and IMEI details to make the email appear legitimate.

    Phishing email
    Phishing email
    Source: SOCRadar

    The email takes the victim to a fake Find My or Apple page where they are prompted to enter their device passcode, Apple Account credentials, and the two-factor authentication code.

    In some cases examined by SOCRadar, an AI agent with an “Alice from Apple Support” persona informs victims that someone trying to unlock the phone brought it to an Apple store, where the device was retained.

    The AI agent then asks the victim to confirm ownership by dictating the passcode, then directs them to the phishing page.

    Once the threat actors obtain those codes, they can access the victim’s personal data, factory reset the device, and remove it from the Find My app before selling it.

    Attack chain
    Attack chain
    Source: SOCRadar

    A compromised Apple ID could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices, SOCRadar warns.

    The researchers found that a small percentage of the emails from the platform were sent to government and corporate organizations.

    SOCRadar reports that the campaigns facilitated by the AnonuMousKIT had a global footprint, but were more concentrated in South Africa, Indonesia, Italy, India, Kenya, and Brazil.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Agents AnonyMousKIT iPhone passcodes PhaaS phish voice
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

    Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails

    A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

    Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

    Hospital operator Nutex Health says data stolen in cyberattack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Did Republicans vote against a bill banning child marriage in Wisconsin?

    August 25, 2026

    There’s no place like a revered writer’s home | Museums

    August 25, 2026

    US-led Gaza peace board warns Hamas over kites after Israeli threat

    August 25, 2026

    Australia confronts its missile shortfall

    August 25, 2026
    Latest Posts

    Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

    July 29, 2026

    Inside the rogue ChatGPT hack of Hugging Face

    July 29, 2026

    ECB wage tracker at 2.7% in Q1 2027, indicating stable negotiated wage pressures

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Did Republicans vote against a bill banning child marriage in Wisconsin?

    August 25, 2026

    There’s no place like a revered writer’s home | Museums

    August 25, 2026

    US-led Gaza peace board warns Hamas over kites after Israeli threat

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.