Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

5 Apple iPhone's in the household are compromised. Can't remove it. HELP!


  • Please log in to reply
7 replies to this topic

#1 Stratego1

Stratego1

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:27 AM

Posted 19 August 2024 - 07:08 PM

Not sure what takes precedent with respect to which forum to post in, Malware or Apple iOS, so I will post in here.

 

Good evening all,

 

To make a long story short, we have 5 iPhones in the household that have been compromised. I suspect that the infection occurred either through my laptop (currently being assisted in the Windows Malware forum for this) or through a questionable email/link from one of the phones that was able to affect the other phones as well. - I have seen that this has been experienced by other users in this forum as well.

 

In short, the Microphone, Camera, and Location services are being used/activated on the phones at random times throughout the day. In addition to that, on my phone, I've had full iMessage conversations of specific people get deleted. My MS Authenticator's main account was deleted - had to speak to Microsoft for a few days to get it back.  My connectivity gets jammed "conveniently" when I'm trying to verify/recover compromised accounts, to name a few. -- I've attached a video and screen from today's events on an iPhone 15 Pro Max (iOS 17.6.1) with a description at the very bottom of this post.

 

I've reported this to local law enforcement - they don't have the resources or seem to care. I've reached out to Apple Support COUNTLESS amount of times and they don't seem to care. Their go-to is, to try a factory reset on the phone - which I have done many times. We (myself and the people in the household) can't get away from this. It doesn't stop. I bought a brand new device a few days ago from the Apple Store with a new SIM, number, and cloud account. Took no more than an hour before I started seeing abnormal behavior.

 

Sent my backup to a forensic who analyzed the phone. The results were clear of anything specific, but he did find logs of the phone's browser visiting hundreds of sites in foreign (questionable) countries. A few of these sites were financial institutions. Logs showed that scanned ten+ sites per second so we know it wasn't human browsing. And the list itself showed a breach into the device.

 

Questions:

1. Has anyone else here experienced the same thing? Did you fix it? If so, how? What did you do?

2. Did anyone work with a Cyber Security expert to assist? If so, did they help?

3. Does anyone have any knowledge of this and can help?

4. Does anyone know how to capture packets of iPhone data going out to see where it's going?

 

Thank you for your time.

 

 

 

Details of Microphone activated on its own randomly - August 19, 2024 - 12:12 pm EST:

 

This afternoon, our internet provider replaced the modem/router in our home. The tech and I left the condo and while waiting by the elevator, I noticed the orange indicator dot appear on my iPhone 15 Pro Max (iOS 17.6.1), which, as you are aware, signals active microphone usage. The indicator appeared a few seconds before the video recording began. Without alarming whoever was listening on the other end, I discreetly signaled to the technician to record the incident on his phone. The video clearly shows the orange indicator appearing at the top right-hand corner of my device before disappearing.

I would like to emphasize the following points regarding this incident:

  • The phone was purchased brand new on August 12, 2024, at the Apple Store at <redacted location>. This is the replacement device for the iPhone 15 Pro Max that showed similar behaviors prior to this one.
  • The device was factory reset approximately 13 hours before this event to prevent exactly such occurrences.
  • The phone was NOT on a phone call at the time, which would have been evident on the island display.
  • Only a few essential apps, all downloaded from the Apple App Store (e.g., banking apps, Facebook, WhatsApp, Instagram, Microsoft, and Google Authenticators), are installed.
  • Microphone and camera permissions have not been enabled for any apps.
  • No Apps were being used prior to or during this incident.
  • Siri is disabled on the device.
  • I have never used or opened the voice notes app on this phone.
Attachments:
  • Screenshot: Privacy Report of Microphone being accessed by the Camera App while the phone was not even being used.
  • Video: Orange indicator dot appearing randomly and disappearing with no use of Microphone being used by user. - Adding link since I can't attach a video to this post. Link: https://easyupload.io/i4p70e

 

Attached Files



BC AdBot (Login to Remove)

 


#2 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:27 AM

Posted 19 August 2024 - 07:46 PM

Was just notified now that Bleeping Computer doesn't assist with mobile devices. I wasn't aware of this prior to the post. My apologies.



#3 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 36,797 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:27 PM

Posted 19 August 2024 - 08:53 PM

Factory restore all phones.
US Navy Veteran from 2002 to 2006
Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015
Arch Desktop - https://termbin.com/1h62
Arch Laptop - hhttps://www.termbin.com/98dd
Ubuntu Server - https://termbin.com/ng9t

#4 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:27 AM

Posted 19 August 2024 - 09:17 PM

Factory restore all phones.

Second Bullet: 

  • The device was factory reset approximately 13 hours before this event to prevent exactly such occurrences.


#5 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 36,797 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:27 PM

Posted 20 August 2024 - 06:01 AM

<p>


Factory restore all phones.

Second Bullet: 
  • The device was factory reset approximately 13 hours before this event to prevent exactly such occurrences.

Do it again because you'd have a greater chance at winning 5 powerballs then having 5 iphones infected and compromised
US Navy Veteran from 2002 to 2006
Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015
Arch Desktop - https://termbin.com/1h62
Arch Laptop - hhttps://www.termbin.com/98dd
Ubuntu Server - https://termbin.com/ng9t

#6 xrobwx71

xrobwx71

    REN LLC


  •  Avatar image
  • Members
  • 1,265 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Panama City Beach, FL USA
  • Local time:07:27 AM

Posted 20 August 2024 - 06:53 AM

The camera app must have permission to use the camera to take pictures. The camera app must have permission to use mic to take a video with audio.

 

I'm not sure if it's default that permission is granted. It would seem so as the camera app is useless without the permission to use the camera or mic.


The very first thing you should always do after setting up a system? Have a valid backup image of your drives.

Hasleo Backup Suite Free

Aomei Backupper

Acronis True Image (not free but very good)

 

 


#7 Stratego1

Stratego1
  • Topic Starter

  •  Avatar image
  • Members
  • 85 posts
  • OFFLINE
  •  
  • Local time:09:27 AM

Posted 20 August 2024 - 08:45 AM

By default, the camera app has permission for these functions. Anything additional such as instagram or whatsapp would requore user permission. Therefore, by default, the camera app in itself wouldnt require permission for its own function.

#8 greg18

greg18

  •  Avatar image
  • Members
  • 1,761 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Los Angeles, CA
  • Local time:07:27 AM

Posted 02 September 2024 - 01:00 PM

No, your iOS devices are not and cannot be infected unless you install "Jailbreak", which only Jailbreak would be the infection not underlying iOS which would still reside on the device.




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users