A sophisticated phishing operation is targeting people whose iPhones have been lost or stolen, using automated emails, messages and AI-generated phone calls to obtain the credentials needed to unlock the devices.
Researchers at SOCRadar identified the platform as AnonyMousKIT, describing it as a phishing-as-a-service operation built specifically to automate attacks across several communication channels. Instead of relying on a single phishing message, customers of the service can repeatedly approach the same victim through email, SMS, WhatsApp, prerecorded calls and conversational AI voice agents.
The objective is to obtain an iPhone passcode, two-factor authentication code or other information that could help criminals overcome Apple’s security protections and make a stolen device easier to resell.
Attackers first create a profile of the stolen phone using information such as its model, associated phone number and Find My status. Those details can then be incorporated into personalized messages that make the approach more convincing.
Some of the phishing messages examined by researchers claimed that a missing iPhone had been located. One email told its recipient that an iPhone 15 Plus had been detected near another Apple device in Johannesburg and provided a button supposedly allowing the owner to view its location. Another message claimed that a lost iPhone 14 had been found online.
The operation extends beyond written messages. SOCRadar recovered records showing that commercial conversational AI technology was being used to make automated calls while impersonating Apple support personnel.
One AI persona, called “Alice,” was configured to tell victims that someone had attempted to remove Activation Lock from their device. The agent could then ask for the phone’s four- or six-digit passcode, request a 2FA code, and direct the target toward a phishing website.
Researchers recovered approximately 200 AI call records, five AI personas and 55 conversation transcripts. About 90% of the recovered calls targeted Brazilian numbers. Thousands of WhatsApp attempts were also identified, while researchers counted 691 email attempts associated with AnonyMousKIT and more than 6,000 across related versions of the platform.
The infrastructure resembles a commercial software service rather than a basic collection of phishing pages. Operators can purchase credits and manage campaigns through a dashboard containing information about orders, balances, links, blocked attempts, and successful attacks.
SOCRadar said a development error exposed significant portions of the operation’s backend, providing researchers with an unusual view of its infrastructure. Their investigation identified 30 backend installations across 42 domains sharing the same underlying code.
The findings also suggest that AnonyMousKIT supports a broader criminal supply chain involving developers, sellers, customers, storefront operators and numerous WhatsApp accounts.
Owners of stolen iPhones should be particularly cautious about unexpected calls or messages claiming that their device has been recovered. A message containing accurate information about the missing phone does not establish that the sender represents Apple.
Apple advises users never to share their device passcode, account password, or verification codes with another person and warns that it will not contact users to say that a lost iPhone has been found.