EFI Malware - DNS Hijacking
I have not been able to get much support or info back from Apple and I cannot afford a forensics team right now.
I know everyone says this kind of stuff isn't possible but I can confirm that some of it is. I have read most of the reports of the more advanced malware and dns hijacking techniques but due to my lack of expertise in this area it's been hard to be sure.
I believe I am infected with mojo_thor efi malware as how Rick describes it here is very similar to how I experienced it and still am. I don't want to waste a bunch of time so if you ask for logs or proof I'll do my best to get you exactly what you need to see. I have been trying to learn essentially how the inner workings of enterprise management tools and the OS work and for now it's more than I can handle.
I do know I have been under attack and I highly suspect it is stemming from my apple devices. I may, I know 100% that there are things I think are evidence or something malicious and they won't be. I've read every forum post like this and know it's going to be people giving me a hard time if I do that. Please hang in there I have spent enough time with this to know something is going on and I have almost a year of documentation, logs and photos and will as directed update here for anyone that is willing to help.
The stuff I post will not be in order of what's most convincing. If I post it it probably means it was or is the latest thing I'm trying to rule out and understand. If you want a log just ask.
Thanks,
First up and is pretty off topic unless there is EFI bootstrapping during boot but does anyone recognize failure installing with these errors and process.