Researchers exposed AnonyMousKIT, an AI-enabled phishing-as-a-service platform designed to harvest Apple ID credentials from victims of recent Apple device theft and use those credentials to disable Activation Lock on stolen iPhones and other Apple hardware. The operation automated phishing across email, SMS, WhatsApp, recorded voice messages, and AI-generated voice calls, including Apple-themed social engineering personas such as "Alice from Apple Support" to collect victim identity details and account access needed to compromise devices and associated cloud data.
Analysis of leaked backend logs tied the activity to a broader reseller ecosystem spanning 506 domains, 168 storefront brands, and at least 30 backend installations active since early 2024, with multiple storefronts linked to a shared codebase and likely common developer. Researchers said coding flaws exposed operator activity and infrastructure, showing a mature supply chain behind the service and underscoring the wider enterprise risk: stolen Apple IDs can provide access not only to hardware but also to iCloud backups, Keychain credentials, and potentially sensitive work-related information.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
The report states AnonyMousKIT remained active through August 2026, with panel logs showing operator activity continuing on August 10, 2026.
The exposed VAPI.ai artifacts showed the AI voice campaign placed 200 calls between August 31, 2025 and May 30, 2026, with the last logged calls occurring on May 30, 2026.
The i-Blocker, Key Unlock, and KG-KING storefronts launched in the same second and shared Gmail relay accounts. SOCRadar assessed the three brands as likely operated by a single buyer.
Within AnonyMousKIT itself, researchers observed 691 email send attempts between March and July 2026, with 603 messages reaching victims' inboxes. The emails impersonated Apple and used multiple lure domains, subject lines, and templates.
Artifacts from a VAPI.ai account showed the AI voice channel placed calls as part of the campaign, with the first logged calls occurring on August 31, 2025. The voice operation used configured personas to target victims, primarily in Brazil.
Researchers linked the broader phishing kit family to 506 domains and 168 storefront brands that were active since February 2024, indicating the reseller ecosystem was already operating by that month.
A coding error exposed AnonyMousKIT production logs and operator records, enabling researchers to identify 30 backend installations across 42 domains and observe 41 active backends in the broader family. The findings also identified related infrastructure, relay accounts, IP addresses, and other indicators tied to the reseller ecosystem.
Mirage Security reported on p1bot, a vishing platform that weaponizes ElevenLabs for voice-phishing operations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
13 references tracked. Mallory keeps watching after this page renders.
moonlock.com
Open sourcecysecurity.news
Open sourcexakep.ru
Open sourcecybersecuritynews.com
Open sourcesocradar.io
Open sourceinfoblox.com
Open sourceattack.mitre.org
Open sourcemiragesecurity.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.