AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

AnonyMousKIT is turning stolen iPhones into an entry point for account theft. The phishing-as-a-service platform targets people already searching for a lost device, then uses convincing recovery messages to capture the Apple ID credentials needed to remove Activation Lock.

The operation combines email, text messages, WhatsApp, recorded calls and AI-generated voice calls. Its messages can draw on the phone model and live Find My status, making a fake recovery notice feel believable at exactly the moment an owner is anxious to get a device back.

Researchers at SOCRadar identified the platform as a credit-based service built for the stolen-device market. Their analysis linked its shared code to 506 domains and 168 storefront brands, showing that the activity is a broader reseller network rather than a single phishing site.

AnonyMousKIT Ecosystem Map (Source - SOCRadar)
AnonyMousKIT Ecosystem Map (Source – SOCRadar)

SOCRadar said in a report shared with Cyber Security News (CSN) The risk extends beyond the resale value of a handset.

A stolen Apple ID can expose cloud backups, saved credentials and work email, while a live verification code lets criminals complete account changes before a victim realizes the contact was fraudulent.

AI-Powered AnonyMousKIT PhaaS

AnonyMousKIT begins with details taken from a stolen device, including its model, owner contact data and Find My state. It then sends a location-themed lure that leads to a fake Apple-style page.

Similar lost iPhone phishing campaigns have exploited the hope of recovering a phone, but this service automates the process across several channels.

The page asks for the screen passcode, Apple ID and a current six-digit two-factor authentication code in sequence. Those details are reportedly sent to the operator panel and Telegram webhooks in real time, allowing criminals to disable Activation Lock and prepare the device for resale.

AnonyMousKIT Attack Lifecycle (Source – SOCRadar)

Voice calls make the scheme more persuasive. The service used an AI persona posing as Apple Support to describe a supposed recovery case, ask the owner to confirm a passcode and steer them toward a texted link.

Of 200 recorded AI calls, 179 were placed to Brazilian numbers, illustrating how low-cost automated calling can scale personal scams.

Email remained a major delivery route, with 603 of 691 logged attempts reaching inboxes from March through July 2026.

Most successful messages used a free Gmail relay and familiar display names such as Find My or Apple Support, a tactic that resembles recent AI voice phishing attacks designed to pressure victims into sharing authentication data.

Network Shows Industrial Scale

The researchers found that a coding mistake exposed production logs and operator records, providing an unusual view of the service’s supply chain, customer activity and infrastructure.

The exposed records showed 30 distinct backend installations across 42 domains, with 41 active backends in the wider family at the time of analysis.

One cluster ran three storefronts launched at the same time with shared Gmail relays, while the oldest known installation appears to have concentrated on WhatsApp after its email relay failed. This setup matters because it reduces the skill needed to run a device-unlocking scam.

Subscribers can enter a victim’s details once and use a panel to push lures through several channels, similar to the service model behind phishing kits targeting organizations that package complex account theft into an accessible service. Organizations should not rely only on blocking known domains because the infrastructure rotates quickly.

The researchers recommend filtering newly registered domains, watching for tokenized Apple-themed links, and flagging lookalike display names sent through free mail providers. Strong mobile-device management can also restrict sideloaded tools and jailbreak attempts.

For individuals, the key rule is simple: a legitimate support team will not call to request a device passcode or a one-time verification code. If a phone is stolen, remotely wipe it where possible and reset the associated Apple ID promptly.

The practical checks in this iPhone phishing safety guide can help users verify links and report suspicious messages before an account takeover occurs. This also limits damage to linked workplace accounts.

Indicators of Compromise (IoCs):-

Type Indicator Description
Infrastructure anomkit[.]shop AnonyMousKIT infrastructure
Infrastructure apple-login-imaps[.]com AnonyMousKIT infrastructure
Infrastructure apple-thailand[.]co AnonyMousKIT infrastructure
Infrastructure findsupport[.]live AnonyMousKIT infrastructure
Infrastructure irealm-server[.]com AnonyMousKIT infrastructure
Cross-Brand Backend uktservice[.]sa[.]com Related backend
Cross-Brand Backend apple-unlock[.]com Related backend
Cross-Brand Backend key-unlock[.]com Related backend
Cross-Brand Backend alxescript[.]info Related backend
Cross-Brand Backend spider-off-unlock[.]one Related backend
Cross-Brand Backend icloud-findmy[.]app Related backend
Cross-Brand Backend gon-unlocker[.]pro Related backend
Cross-Brand Backend zu7pl[.]pro Related backend
Cross-Brand Backend projectpartapple[.]com Related backend
Cross-Brand Backend kit-pro-bot[.]click Related backend
Cross-Brand Backend b.pro-center[.]my[.]id Related backend
Cross-Brand Backend center-one[.]online Related backend
Backend Origin 75[.]119[.]135[.]83 Backend host IP
Developer IP 27[.]34[.]73[.]22 Reported developer-linked IP
Developer IP 27[.]34[.]73[.]46 Reported developer-linked IP
High-Volume Range 197[.]235[.]0[.]0/16 Reported high-volume network range
High-Volume Range 5[.]90[.]0[.]0/16 Reported high-volume network range
High-Volume Range 5[.]91[.]0[.]0/16 Reported high-volume network range
High-Volume Range 181[.]170[.]142[.]0/24 Reported high-volume network range
Shared Operator IP 196[.]196[.]102[.]74 Shared operator-linked IP
Sender / Relay noreplyapple00000[@]gmail[.]com Sender or SMTP relay account
Sender / Relay replycareapple010[@]gmail[.]com Sender or SMTP relay account
Sender / Relay noreplyil[@]icloud[.]com Sender or SMTP relay account
Sender / Relay apple[.]nonreply[.]fmi[@]gmail[.]com Sender or SMTP relay account
Sender / Relay applerecoverymanager[@]gmail[.]com Sender or SMTP relay account
Suspected Developer Identity underc0deapple[@]gmail[.]com Reported developer-linked account
Buyer / Operator Identity xgodauth[@]gmail[.]com Reported buyer or operator account
Buyer / Operator Identity naitebrown93[@]gmail[.]com Reported buyer or operator account
File Hash 5ea22f9777a34f461840c2a3988c717c0f9e6ec4bd95420c Reported file hash
File Hash d9e2881d3aa1ea40928dac65405fbe7e36989cad51ab46d Reported file hash
File Hash 32fa60c9099f53f194a6a63c9341dd115434584e0890120b Reported file hash
File Hash 07d4a6ac925f9f7e63c7332df1995de03f514931e9d97cb3 Reported file hash
File Hash 2c790296b404b3e7592da37b15311507b0e55989e1628ee Reported file hash
URL / Path Pattern shorturl[.]at/gXV0Y Reported shortened URL pattern

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post AI-Powered AnonyMousKIT PhaaS Steals Apple IDs and 2FA Codes to Unlock Stolen iPhones appeared first on Cyber Security News.