A new phishing kit, sold on the dark web for cheap, allows thieves to break into stolen Apple devices. This phishing kit has, among other things, an AI agent that sweet-talks you on the phone. The goal? To steal the lock screen passcode for your stolen iPhone or Mac.
While you might have your iPhone or Mac on hand and safe today, if it is stolen, this kit can be used by cybercriminals to unlock it. This report will guide you on how this kit works. We’ll also cover what you can do on your end to keep your data safe.
AnonyMousKIT: The stolen iPhone, iPad, and Mac kit that comes with an AI agent caller
Recently, SOC Radar published an inside-out investigation on a new AI-driven phishing kit developed solely to unlock stolen iPhones, iPads, Macs, and other Apple devices.

When thieves physically steal your iPhone or Mac, they need the screen lock passcode to open them. Without the passcode, Apple security keeps your device “bricked.” This is a problem for thieves, who need to unlock devices before they can resell them.
Cybercriminal kits offer non-technical thieves the malware they need to unlock and resell those devices.
The stolen iPhone black market is massive. While there is no official figure on how many iPhones are stolen every year, the United Nations says that 70 million smartphones are stolen or lost worldwide every year. The classic stolen iPhone scam is widely known by most users. However, this new kit brings a whole set of new automated tricks to the table.
This new kit, dubbed AnonyMousKIT, uses a professional platform to extract a stolen iPhone’s user data, including name, email, phone number, and WhatsApp number. It then uses that data to automate phishing via SMS, WhatsApp, email, and even AI agent voice calls. All of this directs users to fake lure websites that spoof Apple Find My, Support, and Help to extract your lock screen passcode.
In addition to unlocking stolen iPhones or other devices, this kit could also be used by cybercriminals to go after your iCloud account or Keychain credentials. This can be used to gain access to other devices or online accounts.
AnonyMousKIT is prepped for global, large-scale criminal operations
At the time, SOC Radar identified hundreds of operators using this kit. While SOC Radar describes the operation as similar to a small software vendor operation, the AnonyMousKIT infrastructure is set up for high volume. The kit is already global. And evidently, it has plenty of room to become even more widely used than it is today.
SOC Radar said that so far, AnonyMousKIT has targeted 6,092 stolen iPhones (the majority of them using A12 chipsets or newer), alongside 379 Macs, 33 iPads, 17 Watches, and 4 iBridge devices.
The AnonyMousKIT reseller supply chain at the time includes 506 websites/domains and 168 storefront brands, all reselling the AnonyMousKIT under different brand names. The kit has been active since early 2024.
Furthermore, this kit brings AI agents to the stolen iPhone and stolen Mac world. This feature is likely to stick on the dark web and be replicated by other threat actors selling stolen iPhone unlock kits.

Like other malware-as-a-service (MaaS) operations, AnonyMousKIT uses a decentralized business model. At the top, we find the main seller and developer, followed a step down the ladder in hierarchy by 3 resellers, selling the kit under different brand names. Finally, at the very bottom, we have hundreds of operators who lease out the kit from resellers.
Despite its decentralized nature, SOC Radar said AnonyMousKIT has a centralized figure running the tech stack show: the developer. The same developer has installed AnonyMousKIT across all the kits that the resellers sell, SOC Radar said.
We checked several AnonyMousKIT panels, the main seller, and the resellers. We found that they are up, running, and operating. The lure websites that spoof Apple, however, are no longer live. They are likely to have been rotated when SOC Radar sounded the alarm on this new threat.
AnonyMousKIT will AI call you, email you, text you, and WhatsApp you
The cybercriminal structure of a threat is invisible to you as the end user. You only interact with operators far down the food chain using this malicious kit to steal your lock screen passcode. So, what do you need to know?
The main innovation that this kit brings is an AI agent that makes calls on behalf of stolen iPhone thieves for only about $0.10 per call. This means scammers can make thousands of calls at very low rates.
AnonyMousKIT offers criminals several AI Agents that can speak several languages, including Spanish, Portuguese, and English. All these AI agents share the same persona and introduce themselves to targeted users as “Alice from Apple Support.” Using AI agents to make phishing calls completely removes the need for human scam callers. Not only does this automate phishing, but it means the calls can run 24/7, nonstop.
Besides making AI agent calls, AnonyMousKIT users can also automate email, SMS, and WhatsApp phishing. Sometimes, these channels are combined. For example, the AI agent caller may send you a link via SMS during the call that directs you to a fake screen lock passcode-grabbing site. AnonyMousKIT also offers pre-recorded calls in addition to its AI agent.
How does the AnonyMousKIT AI phishing kit work?
From a cybercriminal perspective, AnonyMousKIT works on a pay-per-message model. This streamlines the entire process from extracting data from a stolen Apple device to stealing passcodes.

Using AnonyMousKIT, operators can do the following:
- Get your data from your Phone: Using the feature Serial Services, AnonyMousKIT extracts user data from the phone. This includes email, number, name, phone, model, tracking URL, etc.
- Send out lures: Once AnonyMousKIT has your data, the platform will send out automated lures via WhatsApp, SMS, email, or voice calls.
- Redirect you to credential-grabbing sites: The phishing emails, SMS, or calls direct you to online sites that attempt to convince you to type in your passcode. These sites steal your 4-digit passcode, Apple ID, and 6-digit 2FA code.
- Exfiltrate: AnonyMousKIT extracts the stolen data from these sites and sends it over to operators via the users’ panel and Telegram.
- Unlock, resale, and further risks: With the stolen unlocking data, your iPhone or other Apple device is resold. Additionally, the same data can be used for new phishing campaigns and other hacks into your accounts or connected devices.
While AnonyMousKIT represents the next step in stolen phishing kits with agentic voice capabilities included, the kit is not that easy to use. In fact, it has a bit of a technical learning curve.
So far, AnonyMousKIT has been registered in Europe, Africa, South America, and Indonesia.
The lure websites that AnonyMousKIT uses to steal your passcode look like this: apple-login-imaps[.]com, apple-thailand[.]co, findsupport[.]live, uktservice[.]sa[.]com, apple-unlock[.]com, icloud-findmy[.]app.
How to keep your data safe when your iPhone or Mac was lost or stolen
If, unfortunately, your iPhone or Mac was stolen, there are some things you can do to keep your data safe.
Get Moonlock. If iPhone thieves want to breach your Mac, Moonlock will flag it.
The Moonlock security app can help you better protect your data if your iPhone was stolen and criminals are trying to breach your Mac.
Once you download and install Moonlock, Real-Time Protection will run in the background, checking everything you interact with, including emails and online activity. If Moonlock finds anything amiss, it will let you know what it is and why it is dangerous, and move it to Quarantine. From there, you can remove the threat completely from your Mac.

To deal with stolen iPhone phishing scams, the Moonlock app ships with a built-in Scam Detector. The Scam Detector can flag phishing in any text, email, SMS, or other messages. All you have to do is copy the text into the Scam Detector, and it will tell you if it’s phishing and why.

Check out and test-drive Moonlock for free for 7 days. See how it feels on your end.
Don’t give away your lock screen passcode to anyone
If you have lost your iPhone, never under any circumstances give away your passcode to a caller, via email, through SMS, or by any other means.
If you lose your iPhone or Mac, don’t panic. Follow these simple steps.
Having your Apple device stolen is already a tough pill to swallow. However, it is likely that the experience is not over. When you start receiving emails, SMS, or voice calls trying to trick you into giving away your passcode, all this unpleasantness is likely to upset you and put you on edge.
It’s a good idea to remember that scammers count on emotionally unbalancing you to throw you off guard. The best thing you can do is remain calm and follow the steps in Apple’s official guides, “If your iPhone or iPad was stolen” and “If your Mac is lost or stolen.”
Final thoughts
Stolen iPhone AI-driven phishing kits are here to stay. AnonyMousKIT puts AI agents on the phone. And a decentralized malware-as-a-service business model for resellers puts this kit in the hands of hundreds of cybercriminals.
For Mac and iPhone users like yourself, there is still much you can do to remain safe. Follow the tips in this report and remain up to date with Apple cybersecurity news to gain an edge and stay safe out in the wild.
This is an independent publication, and it has not been authorized, sponsored, or otherwise approved by Apple Inc. Mac and iPhone are trademarks of Apple Inc.