Breaking
Cyber CrimeDeveloping Story

Phishing kit targets iPhone Lock screen

AnonyMousKIT uses AI calls to trick iPhone owners into giving up passcodes.

··3 hours ago·3 min read
Hacker in hoodie working on multiple computer screens
Photo by Julio Lopez on Unsplash

Apple built Lost Mode to help owners recover misplaced iPhones, but criminals have figured out how to turn that feature against them. A phishing kit called AnonyMousKIT uses fake Find My pages and AI-powered phone calls to harvest the passcodes of stolen iPhones, according to security researchers.

A feature turned against its users

Apple devices rely on multiple anti-theft layers: Find My, Activation Lock, and Lost Mode. When an iPhone is lost or stolen, owners can use another device to enable Find My, locate the phone on a map, play a sound, remotely wipe it, or get notified when it's found. Enabling Find My also turns on Activation Lock, which locks the phone and prevents anyone else from setting it up, even after a factory reset. To exit Lost Mode, a thief needs the iPhone device passcode, and if Activation Lock or setup authentication is required, the Apple account password as well.

But Apple added another option for cases where the device isn't stolen, just lost: owners can display their contact information on the screen, so a good samaritan can return the phone. That well-intended feature is now being abused by the AnonyMousKIT campaign.

How the scheme works

Security researchers SOCRadar uncovered the operation. Attackers use AnonyMousKIT to create fake Find My or Apple pages, then use the contact information displayed on the stolen iPhone to reach out to the victim. Through the kit, they can send emails, SMS messages, WhatsApp texts, or even AI-powered phone calls. Reaching out to the victim, the attackers introduce themselves as Apple customer support agents and say the smartphone has been retrieved.

To make the claim seem credible, they provide the victim with the correct model and IMEI details. Then they ask the victim to confirm their identity by visiting the spoofed Find My page and providing the credentials needed to unlock the phone. The credentials end up with the attackers, who can then unlock the phone, wipe it, and sell it on the black market for a higher price.

Operational details

According to SOCRadar, the earliest records of AnonyMousKIT date back to early 2024. Since then, it has grown into a major operation, with more than 500 domains and over 150 storefront brands working as resellers and affiliates.

The researchers found records of roughly 200 calls made to victims between August 2025 and May 2026. The calls used five different AI agent personas and 55 different interaction transcripts. Each call cost the attackers $0.10, and 90% of them were made to Brazilian victims. A small percentage of email correspondence was directed at government and corporate addresses, including just under 30 attempts toward South African government domains and three to a local university. While the campaign has global reach, it's mostly focused on South Africa, Indonesia, India, Kenya, Brazil, and Italy.

An automated voice vector

What sets AnonyMousKIT apart is its automated, LLM-driven voice vector. At about $0.10 per call, the platform initiates dynamic vishing across three languages using structured pretexts synced with email and SMS lure data, removing the need for fluent human callers.

At the time the report was published, the campaign was still ongoing, and the researchers are continuing to track it.

Ongoing threat

The campaign remains active, and its scale—hundreds of domains, resellers, and cheap AI calls—points to a service that has industrialized phishing. The combination of spoofed pages and voice calls adds a layer of social engineering that can be harder for victims to spot.

The researchers describe AnonyMousKIT not as a phishing kit but as a small software business with a criminal customer base. As long as stolen iPhones can be unlocked and sold for a profit, such operations are likely to keep evolving.

#phishing#apple#iphone#vishing#lost mode#anonymouskit

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories