Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unveiling the Malicious World of AnonyMousKIT: A Phishing-as-a-Service Platform Targeting Stolen-Device Owners


Phishing-as-a-Service Platform AnonyMousKIT Exploits Stolen Apple Devices, Leaving Owners Vulnerable to Credential Theft and Identity Exploitation. The platform's sophisticated AI voice agents pose as Apple Support, tricking victims into divulging their device passcodes and 2FA codes. Experts warn of the devastating consequences of this phishing campaign, emphasizing the need for increased security measures and vigilance among device owners.

  • Cybersecurity researchers have exposed a sophisticated phishing-as-a-service (PhaaS) platform called AnonyMousKIT that exploits stolen Apple devices.
  • The platform uses AI voice agents to pose as Apple Support and trick victims into divulging their device passcodes and 2FA codes.
  • The platform is rentable and utilizes a range of channels, including email, SMS, WhatsApp, and recorded voice calls, to reach its victims.
  • The targets of the phishing campaign are owners of Apple devices that were recently lost or stolen.
  • The platform's operators generate significant revenue from each exploited device.
  • The researchers' recommendations include moving high-value Apple IDs to physical hardware security keys to mitigate the threat.



  • In a disturbing revelation, cybersecurity researchers at SOCRadar Threat Research Unit (STRU) have exposed a sophisticated phishing-as-a-service (PhaaS) platform known as AnonyMousKIT, designed to exploit stolen Apple devices. This platform has been found to be renting AI voice agents to pose as Apple Support and trick victims into divulging their device passcodes and 2FA codes. The implications of this malicious endeavor are far-reaching, highlighting the need for increased vigilance and security measures among device owners.

    The AnonyMousKIT platform, which boasts a credit-metered pricing system, utilizes a range of channels to reach its victims, including email, SMS, WhatsApp, and a recorded voice call. The platform's primary innovation is an automated, LLM-driven voice vector that enables the AI voice agents to mimic human-like conversations, further deceiving the victims into compliance. This phishing-as-a-service model has been found to be both scalable and profitable, with the platform's operators generating significant revenue from each exploited device.

    According to the SOCRadar report, the targets of this phishing campaign are owners of Apple devices that were recently lost or stolen. The pages and calls ask each of them for the 4- or 6-digit device passcode, followed by the Apple ID credentials, and finally a live two-factor authentication (2FA) code. It is worth noting that Apple's official guidance explicitly states that the company never requests a password, device passcode, or 2FA code to provide support, underscoring the malicious nature of this attack.

    The AnonyMousKIT platform has been found to be remarkably sophisticated, with features such as credit bundles, published pricing, tiered subscriptions, customer support, and infrastructure replacement protocols. This level of sophistication highlights the complexity and scale of the threat posed by this phishing-as-a-service platform.

    The researchers also discovered that the platform's operators have utilized a range of tactics to evade detection, including the use of identical second-level labels across different top-level domains. This pattern match rather than an attribution to a single operator makes it challenging to track the source of the phishing campaign.

    In a related development, German and U.S. law enforcement agencies have dismantled the Kratos operation, pulling over 200 servers offline. Indonesian authorities have also arrested the individual they believe developed and ran Kratos, highlighting the international cooperation and efforts to combat cybercrime.

    In conclusion, the AnonyMousKIT platform serves as a stark reminder of the ongoing threat posed by phishing-as-a-service platforms. As device owners, it is essential to remain vigilant and take proactive measures to protect our personal data and devices. The researchers' recommendations for mitigating this threat include moving high-value Apple IDs to physical hardware security keys, which completely mitigates the real-time 2FA interception that is the ultimate objective of this phishing campaign.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unveiling-the-Malicious-World-of-AnonyMousKIT-A-Phishing-as-a-Service-Platform-Targeting-Stolen-Device-Owners-ehn.shtml

  • https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html

  • https://cybernews.com/cybercrime/stolen-iphone-ai-phishing-apple-support-scam-passcodes/


  • Published: Wed Aug 26 03:27:14 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us