Particle.news

AnonyMousKIT PhaaS Uses AI to Harvest iPhone Passcodes and Bypass Activation Lock

SOCRadar's late‑August 2026 report shows the platform leverages Find My data and cheap AI voice calls to trick owners into surrendering passcodes, Apple IDs, and live 2FA codes.

Overview

  • Researchers accessed exposed production logs because the kit's shared code used bare relative file paths that allowed unauthenticated HTTP access, which revealed the platform's operations.
  • SOCRadar found the ecosystem spans roughly 506 domains and supports about 168 reseller storefronts that have run the service since early 2024.
  • Operators feed device details from Find My and Lost Mode, then send coordinated email, SMS, WhatsApp, recorded-call and AI‑voice lures to direct victims to fake Apple/Find My pages that capture credentials and passcodes.
  • Investigators recovered 200 recorded calls from August 2025 to May 2026 with 55 transcripts and five AI personas, about 90% of calls went to Brazil, and calls cost roughly $0.10 each to run.
  • Researchers warn that captured Apple IDs can expose iCloud backups, Keychain items and corporate data, that Apple never asks for passcodes or 2FA codes by phone or web, and they recommend hardware security keys and continued tracking as no public takedown has been reported.