An innovative phishing-as-a-service (PhaaS) platform known as AnonyMousKIT is exploiting stolen iPhones to facilitate account theft. This service specifically targets individuals looking for their lost devices by sending convincing recovery messages to extract Apple ID credentials, which are critical for bypassing Activation Lock.
How AnonyMousKIT Operates
The operation employs a multi-channel approach, utilizing email, text, WhatsApp, and AI-generated voice calls. These messages incorporate the stolen phone’s model and real-time Find My status, crafting a believable narrative for anxious owners seeking device recovery.
Research from SOCRadar has identified AnonyMousKIT as a credit-based service within the stolen-device market. The investigation connected it to over 500 domains and numerous storefronts, revealing it as a widespread network rather than a single phishing site.
Risks Beyond Device Resale
The dangers extend beyond merely selling stolen phones. Acquiring an Apple ID can expose cloud backups, stored credentials, and work-related emails. The use of live verification codes allows criminals to make unauthorized account changes swiftly, often before the victim realizes the breach.
Details from stolen devices, like model and owner contact, are used to craft location-based lures leading to fake Apple-like websites. These pages request screen passcodes, Apple IDs, and two-factor authentication codes, which are then transmitted to operators in real-time, enabling them to deactivate Activation Lock and prepare the device for resale.
Understanding the Scope of the Attack
AI-enhanced voice calls add credibility to the scheme. Impersonating Apple Support, the service guides users to confirm passcodes and follow texted links. A significant number of these calls, 179 out of 200, targeted Brazilian numbers, showcasing the scalability of low-cost automated scams.
Emails remain a primary delivery method, with hundreds of attempts logged. Many messages use free Gmail relays and familiar sender names like Find My or Apple Support. This tactic mirrors recent AI voice phishing attacks that coerce victims into sharing sensitive information.
Implications and Recommendations
Researchers exposed coding errors that unveiled the service’s backend operations, shedding light on its supply chain and infrastructure. They discovered 30 backend installations across 42 domains, indicating a sophisticated operation.
To counteract such threats, it is recommended to filter newly registered domains and monitor for Apple-themed links and deceptive display names. Strong mobile-device management can help prevent unauthorized apps and jailbreak attempts.
For individuals, the rule is clear: legitimate support will not request a device passcode or verification code. If a phone is stolen, it should be wiped remotely, and the Apple ID should be reset immediately. Adhering to guidelines in phishing safety guides can help identify and report suspicious activities, protecting both personal and workplace accounts.
In conclusion, as phishing schemes grow more sophisticated, staying informed and vigilant is crucial to safeguarding personal data and devices.
