AnonyMousKIT phishing kit steals iPhone passcodes
A criminal service called AnonyMousKIT helps thieves unlock stolen iPhones and wipe out the original owner's data. It tricks the phone's real owner into giving up their passcode and Apple ID so the phone can be reset and resold.
- Report priority
- Medium
- Targets
- iPhone+1 more
How it works
- The service pulls the owner's contact details off a stolen phone through its Lost Mode feature, then contacts them by email, text, WhatsApp, or a phone call pretending the phone was found or turned in to an Apple Store.
- A voice AI agent posing as Apple support talks the owner into speaking their passcode aloud and then sends them to a fake Apple or Find My...
What to do
If your iPhone was recently lost or stolen and you then received an unexpected email, text, WhatsApp message, or phone call claiming the device was found or handed in to an Apple Store, never say your passcode out loud or type your Apple Account password and two factor code into a link from an unexpected message or call. Apple does not call, text, or email you to ask for your passcode, and any "found my iPhone" contact should be verified only through the official Find My app or apple.com/icloud/find, not a link in a message.
Technical details
Affected software: iPhone, iCloud
A phone is stolen and put into AnonyMousKIT's system. The owner gets an email or a call from an AI voice agent using the persona "Alice from Apple Support," saying someone tried to unlock the phone at an Apple Store and the store kept it. The agent asks the owner to confirm ownership by saying their passcode out loud, then sends them a link to a fake Find My page to enter their Apple Account password and two factor code. With the passcode and login handed over, the operators unlock the phone, factory reset it, remove it from Find My, and sell it.
AnonyMousKIT is a phishing-as-a-service platform, active since early 2024, that automates recovery of passcodes and Apple Account credentials from stolen iPhones so operators can clear Activation Lock. Researchers at SOCRadar linked it to 506 domains and 168 reseller storefronts, and recovered records of about 200 victim calls handled by a voice AI agent running under five personas, costing roughly $0.10 per call. The kit abuses Lost Mode contact data to send Apple-branded phishing messages with the correct device model and IMEI, directing victims to fake Find My or Apple pages that capture passcode, Apple Account password, and two factor code.