BleepingComputer reported on AnonyMousKIT, a phishing-as-a-service platform that automates retrieval of codes used to unlock stolen Apple devices and disable Activation Lock.
SOCRadar found that the service has been active since early 2024 and is connected to 506 domains.
The platform supports an ecosystem involving stolen iPhones, Apple ID harvesting, iCloud backup access, and Keychain credential exposure.
Researchers recovered records of 200 calls made to victims between August 2025 and May 2026 using 55 interaction transcripts handled by a voice AI agent across five personas.
AnonyMousKIT uses information from stolen devices, including owner contact details from Lost Mode, to contact victims through email, SMS, WhatsApp, or phone calls.
The phishing pages impersonate Apple or Find My and request device passcodes, Apple Account credentials, and two-factor authentication codes.
SOCRadar warned that compromised Apple IDs could expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices.
SOCRadar also found that a small percentage of campaign emails were sent to government and corporate organizations.
AnonyMousKIT shows how phishing-as-a-service operators combine AI voice agents with fraudulent Apple and Find My pages to trick stolen iPhone owners into revealing device passcodes, Apple Account credentials, and two-factor authentication codes.
How AnonyMousKIT Turns Stolen iPhones Into Phishing Targets
The campaign combines device-theft workflows, phishing infrastructure, and AI-powered voice automation. When an owner marks an iPhone as lost, Lost Mode can display a custom message and contact number on the lock screen to support recovery. AnonyMousKIT operators exploit these details to send targeted messages or place calls impersonating Apple Support.
The lures direct victims to fraudulent Find My or Apple-branded pages that harvest device passcodes, Apple Account credentials, and two-factor authentication codes. In some cases, an AI persona claims that someone attempted to remove Activation Lock at an Apple Store and that staff retained the device. The agent then asks the victim to confirm ownership by dictating the device passcode before directing them to the phishing page.
What is autonomous XDR and why it matters
Learn how autonomous XDR enables faster, context-aware threat response through controlled AI-driven action.
The Hexnode Solution
Hexnode UEM can mitigate Lost Mode exploitation by enabling administrators to centrally lock or remotely wipe managed iPhones. IT teams can also standardize the contact information displayed in Lost Mode, preventing employees’ personal phone numbers from appearing on lock screens and becoming OSINT for AI-enabled vishing attacks. For personally owned iPhones, Apple User Enrollment separates managed work data from personal data while limiting administrative control over the personal environment.
With Apple User Enrollment and Managed Apple Accounts, enterprise data remains separate from personal iCloud data and Keychain items. This isolation helps prevent compromised personal Apple Account credentials from exposing managed corporate data. Hexnode can also report iOS compliance status to Microsoft Entra ID as a third-party compliance partner. Organizations can use Conditional Access policies to restrict protected Microsoft cloud resources to registered, compliant devices.
Hexnode XDR complements these preventive controls by correlating endpoint security signals and supporting remediation on Windows and macOS endpoints. Even if an attacker tricks a user into surrendering a 2FA code, an Entra ID Conditional Access policy requiring device compliance can block the subsequent sign-in because the attacker’s device is unmanaged or fails Hexnode compliance checks. This defense-in-depth model helps contain malicious endpoint activity if phished credentials contribute to a broader compromise.
Feature Resource
Why XDR Is Stronger With UEM
Learn more on how Hexnode XDR's performance can be enhanced and elevated with deep integration with Hexnode UEM.
AnonyMousKIT demonstrates how stolen-device recovery workflows can become identity attack paths. Enterprises should strengthen lost-device response procedures, train users to recognize Apple-themed phishing and vishing, and require trusted, compliant devices to access corporate resources.
Try Hexnode free for 14 days
Secure your iPhone fleet against device and identity risks with Hexnode. Start your free trial.
I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.