Researchers at Zimperium's zLabs have identified these campaigns, tracked as RecruitTrap, impersonating major companies such as Amazon, Apple, and Deloitte.
AnonyMousKIT is specifically designed to circumvent Apple's Activation Lock, a security measure that links an Apple device to its owner's Apple ID, making stolen devices difficult to resell.
The attack involved threat actors calling employees and attempting to trick them into accessing a fake ReliaQuest single sign-on (SSO) page hosted on a lookalike domain, reliaquest[.]claims.