Not sure what takes precedent with respect to which forum to post in, Malware or Apple iOS, so I will post in here.
Good evening all,
To make a long story short, we have 5 iPhones in the household that have been compromised. I suspect that the infection occurred either through my laptop (currently being assisted in the Windows Malware forum for this) or through a questionable email/link from one of the phones that was able to affect the other phones as well. - I have seen that this has been experienced by other users in this forum as well.
In short, the Microphone, Camera, and Location services are being used/activated on the phones at random times throughout the day. In addition to that, on my phone, I've had full iMessage conversations of specific people get deleted. My MS Authenticator's main account was deleted - had to speak to Microsoft for a few days to get it back. My connectivity gets jammed "conveniently" when I'm trying to verify/recover compromised accounts, to name a few. -- I've attached a video and screen from today's events on an iPhone 15 Pro Max (iOS 17.6.1) with a description at the very bottom of this post.
I've reported this to local law enforcement - they don't have the resources or seem to care. I've reached out to Apple Support COUNTLESS amount of times and they don't seem to care. Their go-to is, to try a factory reset on the phone - which I have done many times. We (myself and the people in the household) can't get away from this. It doesn't stop. I bought a brand new device a few days ago from the Apple Store with a new SIM, number, and cloud account. Took no more than an hour before I started seeing abnormal behavior.
Sent my backup to a forensic who analyzed the phone. The results were clear of anything specific, but he did find logs of the phone's browser visiting hundreds of sites in foreign (questionable) countries. A few of these sites were financial institutions. Logs showed that scanned ten+ sites per second so we know it wasn't human browsing. And the list itself showed a breach into the device.
Questions:
1. Has anyone else here experienced the same thing? Did you fix it? If so, how? What did you do?
2. Did anyone work with a Cyber Security expert to assist? If so, did they help?
3. Does anyone have any knowledge of this and can help?
4. Does anyone know how to capture packets of iPhone data going out to see where it's going?
Thank you for your time.
Details of Microphone activated on its own randomly - August 19, 2024 - 12:12 pm EST:
This afternoon, our internet provider replaced the modem/router in our home. The tech and I left the condo and while waiting by the elevator, I noticed the orange indicator dot appear on my iPhone 15 Pro Max (iOS 17.6.1), which, as you are aware, signals active microphone usage. The indicator appeared a few seconds before the video recording began. Without alarming whoever was listening on the other end, I discreetly signaled to the technician to record the incident on his phone. The video clearly shows the orange indicator appearing at the top right-hand corner of my device before disappearing.
I would like to emphasize the following points regarding this incident:
- The phone was purchased brand new on August 12, 2024, at the Apple Store at <redacted location>. This is the replacement device for the iPhone 15 Pro Max that showed similar behaviors prior to this one.
- The device was factory reset approximately 13 hours before this event to prevent exactly such occurrences.
- The phone was NOT on a phone call at the time, which would have been evident on the island display.
- Only a few essential apps, all downloaded from the Apple App Store (e.g., banking apps, Facebook, WhatsApp, Instagram, Microsoft, and Google Authenticators), are installed.
- Microphone and camera permissions have not been enabled for any apps.
- No Apps were being used prior to or during this incident.
- Siri is disabled on the device.
- I have never used or opened the voice notes app on this phone.
- Screenshot: Privacy Report of Microphone being accessed by the Camera App while the phone was not even being used.
- Video: Orange indicator dot appearing randomly and disappearing with no use of Microphone being used by user. - Adding link since I can't attach a video to this post. Link: https://easyupload.io/i4p70e