Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: Medium
Victim: Owners of stolen Apple devices
Incident: Deployment of an AI-driven Phishing-as-a-Service platform targeting Apple device owners.
Impact: Unauthorized access to Apple accounts and the removal of Activation Lock on stolen hardware.
Attacker: Operators of AnonyMousKIT
Analysis: The AnonyMousKIT PhaaS platform leverages AI voice agents to impersonate Apple Support with high precision. By utilizing specific device data like model identifiers and Find My status, attackers create highly convincing lures to bypass Activation Lock. This systematic approach integrates AI voice, SMS, and email to harvest 2FA codes and credentials.
Recommendations: Never share device passcodes or 2FA codes over the phone, regardless of the caller’s claimed identity.; Verify all support requests through official Apple channels or the official Apple Support app.; Remind users that official support services will never request passwords or security codes to provide assistance.
Source: The Hacker News / SOCRadar
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source