EFI Malware - DNS Hijacking

I have not been able to get much support or info back from Apple and I cannot afford a forensics team right now.


I know everyone says this kind of stuff isn't possible but I can confirm that some of it is. I have read most of the reports of the more advanced malware and dns hijacking techniques but due to my lack of expertise in this area it's been hard to be sure.


I believe I am infected with mojo_thor efi malware as how Rick describes it here is very similar to how I experienced it and still am. I don't want to waste a bunch of time so if you ask for logs or proof I'll do my best to get you exactly what you need to see. I have been trying to learn essentially how the inner workings of enterprise management tools and the OS work and for now it's more than I can handle.


I do know I have been under attack and I highly suspect it is stemming from my apple devices. I may, I know 100% that there are things I think are evidence or something malicious and they won't be. I've read every forum post like this and know it's going to be people giving me a hard time if I do that. Please hang in there I have spent enough time with this to know something is going on and I have almost a year of documentation, logs and photos and will as directed update here for anyone that is willing to help.


The stuff I post will not be in order of what's most convincing. If I post it it probably means it was or is the latest thing I'm trying to rule out and understand. If you want a log just ask.


Thanks,



First up and is pretty off topic unless there is EFI bootstrapping during boot but does anyone recognize failure installing with these errors and process.





Posted on Feb 28, 2021 11:43 PM

Reply

Similar questions

50 replies

Aug 1, 2021 6:37 AM in response to AutoGenetix_Design

Anything those four screen shots are intended to show, beyond some personal info, what looks like a double install, and an iPhone synced with multiple systens?


As was mentioned earlier, you will want to learn about digital forensics and incident response, and how to do the work, and acquire the evidence. Or pay somebody to do the related forensics work.


Which can be expensive, tedious, and time-consuming.


Claims aside, most making these claims can have had something else happen; software and hardware problems being common. Exposed passwords, phishing, DNS errors, the usual sorts of Apple glitches and corruptions, lots of ways to get into trouble.


And for what I see with the four photos and beyond the included personal info posted here, a double-synced iPhone and/or confusion after a reload, and a doubled install or dual-boot or corrupt Spotlight database. And then a whole lot of forensics work requiring direct access, and some of which may well involve proving a negative; a difficult proposition, at best.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

EFI Malware - DNS Hijacking

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.