AnonyMousKIT PhaaS Hijacks Apple IDs & 2FA to Bypass Activation Lock

There’s a new phishing-as-a-service (PhaaS) tool in the wild called AnonyMousKIT, engineered to harvest Apple IDs and two-factor authentication (2FA) codes directly from users who are already anxious about losing their iPhones. It targets people searching for a missing device by sending fake recovery messages that impersonate Apple, aiming to breach iCloud Activation Lock and reroute the device into resale channels.

How the Scam Works

AnonyMousKIT uses stolen device info—like model specs, owner contact data, and the active status of Find My—to craft scam messages that feel timely and legitimate. Victims receive emails, texts, WhatsApp messages, AI-generated voice calls or recorded calls that reference real device details. A fake landing page mimics Apple’s design and requests passcode, Apple ID, and a valid 6-digit 2FA code in sequence. All captured credentials are immediately forwarded to a criminal operator panel and Telegram webhooks, enabling prompt activation lock removal. The voice messages are especially convincing: in many cases an AI persona posing as Apple Support will walk users through verifying passcodes and following a link sent via message—all part of the scam.

Industrial-Scale Network Behind It

Analysis by SOCRadar reveals that this isn’t just a single phishing site—it’s a sprawling reseller network. One report identified 506 domains and at least 168 storefront brands connected under the AnonyMousKIT umbrella, linked via shared infrastructure and operator panels. Several different backends, storefronts, and delivery channels are employed; one cluster ran multiple storefronts with shared email relays, others rely heavily on WhatsApp. Mistakes in their code exposed internal logs and backend setups—showing 30 distinct backend installs across 42 domains, with 41 active backends in total. This reveals a service built to scale, with low barriers to entry for the scammers involved.

Attack Channels, Victims & Indicators

From March through July 2026, over 600 of nearly 700 phishing email attempts made it past spam filters, often using free Gmail relays and display names like “Find My” or “Apple Support.” In one subset of 200 AI-generated calls, 179 were sent to Brazilian numbers, highlighting regional targeting. The attack’s timeline—from recognizing a stolen device through credential collection and 2FA retrieval—is tight, giving little time for victims to realize what’s happening.

What Can Individuals & Organizations Do?

Defenses at both ends are vital. For organizations, domain blocking alone won’t suffice when phishing panels and backend infrastructure rotate rapidly. SOCRadar recommends monitoring newly registered domains, watching for Apple-themed URLs or tokenized links, and flagging display names that mimic trusted services using free mail domains. Strong mobile device management policies, limitations on sideloading, and avoiding jailbreaks also help.

Every user should know legitimate support will never request both passcode and current verification codes via unsolicited calls or messages. If your device is lost or stolen, remote wipe, reset your Apple ID, and verify 2FA settings. Use reputable safety guides to scrutinize messages and URLs before engaging.

Indicators of Compromise (IoCs)

Some of the domains tied to AnonyMousKIT include anomkit[.]shop, apple-login-imaps[.]com, findsupport[.]live, and several backends like apple-unlock[.]com or key-unlock[.]com. Email senders often use free Gmail accounts—such as noreplyapple00000[@]gmail[.]com or applerecoverymanager[@]gmail[.]com—using display names designed to evoke authority. IP ranges and file hashes have also been exposed in research logs.

Although AnonyMousKIT is just one among many PhaaS operations, its sophistication and scale make it especially dangerous. What makes this case stand out is the automation across multiple channels, use of real-time device data, and rapid turn-around that narrows the window for defense. Individuals should be especially cautious when confronted with recovery messages that put them under pressure—phishing isn’t just sloppy grammar and stock images anymore; it’s precision-engineered.