EFI Malware - DNS Hijacking

I have not been able to get much support or info back from Apple and I cannot afford a forensics team right now.


I know everyone says this kind of stuff isn't possible but I can confirm that some of it is. I have read most of the reports of the more advanced malware and dns hijacking techniques but due to my lack of expertise in this area it's been hard to be sure.


I believe I am infected with mojo_thor efi malware as how Rick describes it here is very similar to how I experienced it and still am. I don't want to waste a bunch of time so if you ask for logs or proof I'll do my best to get you exactly what you need to see. I have been trying to learn essentially how the inner workings of enterprise management tools and the OS work and for now it's more than I can handle.


I do know I have been under attack and I highly suspect it is stemming from my apple devices. I may, I know 100% that there are things I think are evidence or something malicious and they won't be. I've read every forum post like this and know it's going to be people giving me a hard time if I do that. Please hang in there I have spent enough time with this to know something is going on and I have almost a year of documentation, logs and photos and will as directed update here for anyone that is willing to help.


The stuff I post will not be in order of what's most convincing. If I post it it probably means it was or is the latest thing I'm trying to rule out and understand. If you want a log just ask.


Thanks,



First up and is pretty off topic unless there is EFI bootstrapping during boot but does anyone recognize failure installing with these errors and process.





Posted on Feb 28, 2021 11:43 PM

Reply

Similar questions

50 replies

May 25, 2021 7:25 AM in response to REPORTED_THIS_FOR_9_MONTHS

ive been dealing with the same , and fibally found this discussion after trashing enough .plist files to have some some of control back. And I have changed all hardware, carriers, services, and devices . i changed everything but my physical address and brought nothing forward with with but my robinhood acct. I smashed my 2016 macbook of pure frustration. i had to take it apart and disconect the battery the battery to stop the peer2peer control. factory reset all the iphones and changed wifi companys and equipment and then ordered a M1 air and nevergave it wifi access before setup or during. Tge new computer came with it on it . Now Im right back where i started. so anyother suggestions? my theory now is that its Apple and they are using us without permission of knowledge ( for most) to map out the sidewalk internet and it is leaving up vulnerable so infiltration. What say y'all?

Jun 9, 2021 2:46 AM in response to MrHoffman

Great stuff Mr. Hoffman !!


You're for sure smarter than I am when it comes to this stuff, but I'm not too far behind ya !!! I have been studying for countless hrs, then reading more, then reading more than more reading, just straight fighting for my life with Apple since Oct 2019. I just don't know anymore if I have the energy in me or funds that will allow me to put more and more time into this with still no paycheck coming in because my $3,000 dollar MacBook is completely nonfunctional.


However, I do think that it is imperative that we all get together and collaborate our data, talk a bit and see if we can come up with a way to end this madness. I'm literally feeling beat down mentally, emotionally, and physically by Apple Support and their Senior advisors from the Mac Tier II team. Every single call they keep doing the same redundant, cookie-cutter process of troubleshooting actions all the while thinking they're are going to produce a different result. ( Definition of Insanity) and while using my time as well) Anyway, can we get our Phone 3 numbers to each other through here?

Jun 16, 2021 10:12 PM in response to REPORTED_THIS_FOR_9_MONTHS

Are we allowed to contact each other by phone or in-person to collaborate on our findings, and data problems? I mean it's the least we can do now and put our heads together and save each other, god-wiling.


I'm sorry, but I'm just not as clear as you are as to how we deserve to go this mega beast problem alone? This has to end NOW I am slowly deteriorating in both mental and physical health. This whole ordeal, to date, has cost me a little north of $300,000 dollars. That's pretty much every dime I saved for retirement. Yet I'm still sitting here redundantly mercy of Apple Support. They keep doing the exact same troubleshooting process & actions over, and over, and over, again. (It's the truest definition of insanity), and the irony is It's really the only process offered to help the billions of people who trusted the world's largest, most expensive inovating tech company in the world. That's why we all paid the premium, so to speak. to own the best products on the market, in case something like this did happen to us.


Anyway, this is now, June 16th, 2021, and my first call to Apple about these issues was in Oct 2019. So it will be 2 solid years I have been calling, trouble-shooting with Apple Support every day. HELP MAY DAY, HELP MAY DAY

Jun 17, 2021 7:29 AM in response to AutoGenetix_Design

Nobody here can assist you with this. Forensics requires direct access, and lots of time and effort and skill.


USD$300,000 is in the price range of hiring a fairly skilled and full-time IT provider, or a whole lot of forensics work (and which didn’t find anything or we wouldn’t be having this discussion), or some sort of scam.


I’d also suggest seeing your preferred medical provider, and discussing this situation and particularly given the “I am slowly deteriorating in both mental and physical health” that you’ve reported here, as your medical provider may or will have some cogent opinions about what to do about that.


Jun 17, 2021 11:25 PM in response to AutoGenetix_Design

I can’t believe there are more of you out there! I’ve been fighting this **** for EVER!! Anyone make any headway? I’ve got a boneyard of iOS devices, hard drives, memory sticks, you name it!! Apple has failed me forever! They don’t do anything about it! I’ve done a ton of investigating also and if we all share little by little we may tackle this thing! Just became a developer also with Apple so I can dig deeper. I know where and when mine started but have been fighting ever since.. looking forward to this….

Jul 31, 2021 2:03 AM in response to REPORTED_THIS_FOR_9_MONTHS

Get an EMF Cambridge Labs from EBAY for about $45 and you can see where there's the Satelite Connection dropping into your Lat/Long coordinates [in my case anyway]. The one that was so obvious with my nonsense is when the Routers would go down by disconnecting the ONT.Terminal and somehow someway All the TV's , Set box, Devices, still had magical WiFi Connections even though no router and no ONT/MOCCA/ETHERNET nothing at all to give it the Data Connection. Straight Free Service

Jul 31, 2021 8:21 AM in response to CLZQ

CLZQ wrote:

…the Satelite Connection dropping into your Lat/Long coordinates [in my case anyway]. The one that was so obvious with my nonsense is when the Routers would go down by disconnecting the ONT.Terminal and somehow someway All the TV's , Set box, Devices, still had magical WiFi Connections even though no router and no ONT/MOCCA/ETHERNET nothing at all to give it the Data Connection.


Optical Network Terminals (ONTs) are an upstream network connection for terrestrial optical broadband, and not AFAIK for consumer satellite in GPS (HughesNet, etc) or LEO (Starlink, etc) networks. Most satellite network connections are within the realm of gigabit Ethernet and don’t need the added costs and complexity and distances of an optical network connection between the antenna and receiver gear and the local network.


A larger shared satellite receiver or a high-end home network or a medium-sized or larger business network will have optical connections external or internal or both. Most other smaller networks and smaller satellite connections, not so much.


If the ISP network is out, then anything outside the local network will not be reachable. Local Wi-Fi will work and will show connectivity, but remotely-located servers including ISP DNS servers won’t be reachable. Which is a fairly common case that makes the more simplistic connectivity checks fail.

Jul 31, 2021 4:18 PM in response to MrHoffman

Considering that almost all Internet connections are routed under water through Cables theirs a lot to be still be considered in terms of what's what. I agree with what you are saying but this second message of mine [cambridge EMF] was a support to my first thoroughly typed message. It's gone missing and that's pretty weird and suspicious as is. It's an Enterprise MDM Configuration Profile Virtually Bridged by THUNDERBOLT onto a Remote [remote network settings] can run BT OTA AirDrop even if you don't think it's turned on. Router can be a Slave to "Jenkins" and Satelite Lat/Long can be the Boss taking over all connections to Data. As soon as you hook anything up to any Router that's within The Lat/Long Geo Spatial Coordinates it's first call out is to whos the Boss/slave owner and that's that. Check your Active Directory settings and go thru everyone Open Directory and go thru your Forrest Branch Trees item per item.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

EFI Malware - DNS Hijacking

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.