AnonyMousKIT is an AI-enabled phishing-as-a-service ecosystem used by criminal operators to obtain Apple ID credentials, device passcodes, and live two-factor authentication codes from victims whose Apple devices have been lost or stolen. Its primary purpose is to defeat Apple Activation Lock and facilitate resale of stolen devices, while compromised Apple accounts may also expose iCloud backups, Keychain data, and organizational information. The service operates as a credit-metered criminal platform and supports Apple-themed phishing by email, SMS, WhatsApp, recorded calls, and AI voice agents impersonating Apple Support. It tailors lures using victim contact details, device information, and Find My status data, then delivers captured credentials to operator panels and messaging-based webhooks in real time. AnonyMousKIT is part of a broader reseller ecosystem built on a shared codebase, with related storefronts including PRO KIT, Painel-Rescue Unlocker, ULTIMATE KIT V5, AppleChecker, i-Blocker, Key Unlock, and KG-KING. The ecosystem operates as a decentralized criminal supply chain comprising developers, sellers, resellers, and subscriber operators rather than a single conventional intrusion group. It has targeted consumer accounts as well as government, education, and corporate accounts associated with owners of recent Apple-device thefts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service ecosystem that targets owners of stolen Apple devices to obtain Apple ID credentials, passcodes, and two-factor authentication codes, enabling Activation Lock bypass and access to associated iCloud data. It uses multichannel social engineering, including phishing email, SMS, WhatsApp, recorded calls, and AI-powered voice agents impersonating Apple Support.
Operates a phishing-as-a-service ecosystem focused on harvesting Apple ID credentials, device passcodes, and live 2FA codes from owners of stolen Apple devices in order to disable Activation Lock and monetize device resale. The platform supports email, SMS, WhatsApp, recorded voice, and AI-driven vishing, and is sold through a reseller/storefront model.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.