The AnonyMousKIT PhaaS platform automates Apple ID theft to bypass iPhone Activation Lock by using AI-generated voice calls impersonating Apple Support. The operation was exposed due to a critical flaw in its infrastructure involving the use of bare relative paths, which revealed production logs and a reseller supply chain of over 500 domains. The article does not specify a software vulnerability in Apple products but details a criminal service exploiting social engineering.
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. βBy leveraging a critical flaw β the use of bare relative paths β the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mimic βApple Support,β basic coding errors exposed production logs and operator rosters,β researchers wrote. Researchers β¦ More β The post AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes appeared first on Help Net Security .