SOCRadar Reveals Supply Chain Behind AI-Powered iPhone Phishing
SOCRadar’s Threat Research Unit (STRU) has published new research detailing AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform that targets stolen iPhones by attempting to obtain the Apple ID and passcode needed to unlock them.
According to SOCRadar, a basic coding error in AnonyMousKIT’s backend exposed information about the platform’s developer, resellers and operators. Two exposed relative file paths provided STRU with months of production logs, allowing researchers to trace the operation to a shared codebase operating across 506 domains and 168 brand names.
AnonyMousKIT uses stolen device information to automate phishing attempts against iPhone owners. Once details about a stolen device are entered into the platform, it can send messages through email, SMS and WhatsApp as well as initiate a recorded call or an AI-powered phone call until the owner responds.
Device-Specific Phishing
STRU found that AnonyMousKIT uses device-specific information in its lures. Messages can reference an iPhone’s actual Apple model number, such as iPhone16,2, along with its live Find My location pulled from the stolen device.
The platform also uses an AI voice agent that poses as Apple Support. The agent is scripted as “Alice from Apple Support” and can communicate in English, Spanish and Portuguese. According to the research, the voice agent attempts to convince victims to provide their passcode during the call before directing them to a phishing link.
The research also identified a reseller network operating behind multiple storefronts. The shared codebase connected 506 domains and 168 storefronts, while scanning the associated family identified 30 still-active backends across 42 domains.
Low-Cost AI Calls
SOCRadar found that the operation can use AI voice calls at a relatively low cost. In one example, 200 AI voice calls, 90% of which were made to Brazil, cost the operator $19.24 in total.
The research also found that some of AnonyMousKIT’s advertised functionality does not work on most of the devices it targets. Four “free” jailbreak tools included in the panel only operate on chips up to the iPhone A11, while 92.7% of the targeted devices use A12 or newer chips.
STRU also identified indicators connecting multiple storefronts to the same operation. An identical setup-check email containing 26 log lines appeared in 12 of 24 exposed backends. Three storefronts launched in the same second on April 10, 2026, and shared the same Gmail relay accounts.
Implications for Defenders
SOCRadar said the clearest warning sign is a request for sensitive credentials. “No legitimate Apple or IT support team will ever call and request a passcode or 2FA code out loud,” according to the research.
The threat also extends beyond individual consumers. AnonyMousKIT emailed phishing lures to 27 South African government addresses and a local university, according to STRU. The research noted that a compromised personal Apple ID could potentially expose corporate Keychain credentials.
SOCRadar said AnonyMousKIT was still operating as of its last collection date and that STRU continues to track the wider family.
The company’s full report, “Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain,” includes additional research, indicators of compromise and ATT&CK mapping.
