MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

I am a personal 'User' I have cycled through many hours and days with support. No one knows what is going on. Most likely because I am never able to speak with someone that understands the Enterprise platform. I feel this is happening via my carrier- but Fraud sent me to Tech support. Tech support told me my phone is hacked and to file a police report.

In combination I suspect that MDM is a gateway for an external developer to access my phone via various methods: webkit, Xcode, Apple Store Connect, SDK

I am about 99.99% sure I know why, but that is something that I will not disclose because most likely all of my activity is monitored; despite the very strict privacy settings I try to maintain.


Symptoms:

  1. My apps will sometimes tell me they did not come from the App Store (Maps, FindMyiPhone, etc..)
  2. When I make an attempt to chat with Apple support I receive a message to Use Messages to Connect with Business. When I have my iPhone in LOCKDOWN mode I receive a message that I cannot use Messages for Business when my device is locked down.
  3. I only have one device. However, I am sharing across devices- many times or I have the option to. The choice is not grayed out.
  4. I am unable to perform an Emergency Reset because I am usually sharing something - Notes, Home, Health, Books....
  5. I do not use iCloud Drive due to multiple security concerns. Almost every time that I double check those settings apps show that they are using iCloud Drive. (Game Center, Health or Fitness, Notes, Books, Apple Support, Wallet) While clicking to turn OFF syncing I have had a battle with it changing right back before my eyes. (I have screen recordings)
  6. Game Center will come on even though I have strict Screen Time settings.
  7. I am generally either sharing, or my phone is gathering data from Health; even though that privacy option is supposed to keep that from happening.
  8. Sometimes I am unable to even sign out of my phone due to 'restrictions'.
  9. I have 'Share with Family' sometimes

*Those are only a few symptoms. That is minus the horror I see from the extraction of information I backed up into Kali Linux

As I have mentioned I have spent many many many hours with Support. One Senior Director did spend time Googling the services that show up in my Analytics. I have even uploaded screen shots and documents, but I never heard back.

I REALLY REALLY need help here.

I will add attachments. They won't be nearly the amount I have. I am begging!!!



iPhone 13, iOS 16

Posted on Apr 2, 2023 2:32 PM

Reply

Similar questions

82 replies

May 25, 2023 7:58 AM in response to pia157

Question, can you see JavaScript and Xcode on a Mac? The MDM spread to Windows with the fraudulent remote access apps, I could see that, but permissions are changed always, MDM on, parental controls on. Another question, I unplugged my router 8 weeks ago, but they are still accessing devices, I’ve seen ppl parked at end of driveway a couple of times when several devices were active but not every time. I’ve seen a lot of data transfers on Roku )not to movie or Roku). I did a scan for active BT, one Roku showed up (I’ve seen many users on there as well), and data transfers from the former Alarm. Idk if Roku is connecting to neighbor? Lots of settings and downloads are put in iCloud with synch to all, but a user can’t do that, unless it’s a MAC option. I’ve had tons of scripts, not always visible on iPad (unless under shortcuts), but visible on a Windows PC (although 7 PCs are compromised). I know the MDM will have to be blocked before entering my house!

May 30, 2023 1:27 PM in response to T3ddy19

Have you checked on apple beta to see if your user name is there? I have to keep unenrolling mine. There are no other signs that I am in the beta program . Apparently, if you are enrolled, the " developers" have permission to do whatever they want with your devices. Also check your cell service beta programs as well as any other accounts... for instance my sons Xbox has beta rights. To confirm, we didn't authorize it nor can we find emails acknowledging it but it is worth looking into.

Jun 1, 2023 12:59 AM in response to AgentDragonfly

Girl I have been living this nightmare for nearly four years. I hear you loud and clear. Absolutely NO help and lie after lie. Try this MITRE ATT&CK® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. Very accurate and give you insight to how the attacks are happening.


Mine is through direct access remotely. Abuse of administration privileges from a prior Global admin, azure and google workspace. I have been documenting this from day one. Binders full of evidence, fraud, spoofing, malware, spyware and everything in between.

There is very little oversight to these web developers and MDM companies. The Big Tech Co’s sell your info to the highest bidder. Watch Social Dilemma. Very disturbing. Unfortunately, the criminal is protected and the victim pays dearly and suffers the consequences. If someone has access to your Apple ID which is Very easy to get nowadays it can be devastating to individuals.


I’m literally sick of the stress it brings on, the Mind F*** and the financial loss. It is a vicious circle and a living nightmare. Check your Apple App report and Apple analytics. Also check your VPN again. It will not be visible you have to click and click again to find it. Check IPsec see if you see a Cisco VPN.

Best of luck to you.


[Personal Information Edited by Moderator]




Jun 3, 2023 7:11 PM in response to AgentDragonfly

I’m a former Global Info Sec Manager, certified. I can’t get my hand on the needed tools to even get a peek inside, but I have many of the same symptoms. Check out “shortcuts”, there should only be a couple. If you click on the eclipse, you should be able to see actions, I had 87 at one point. Some brought back pics of the hacker, obviously to bother me, although back doors were opened, fraud, including fraud downloads from App Store that were hidden, an Apple feature. There is a site where you can see hidden purchases, and Apple provides info on how to view them, 2 banking apps, 2 remote control apps, 2 email “management” that deleted all of my email from 1 account that I’d had since the inception of email, more. All completely hidden. The download for the MDM showed up again, I attempted to download, but it said I needed Admin access. And when clicking on the MDM icon, it had an option to hide! There is a lot of JavaScript included. Like you, I also see regular activity to Game Center, Health or Fitness, Notes, Books and calendar along with many other settings that turn back on right after turned off. Mine are all personal devices, never Corp owned. You must have a Mac to install, at least for the 20 free licenses. And sharing turns on as well, this allows any device on your network to share certain apps, and it spreads software to Windows (including MDM) if you have windows, do a search on *mdm*.*, there will be over 1,000 files if it’s on there. If you have anything you want to keep, back it up on a usb drive, Amazon has a photo stick that will allow you to copy pics. There is an app that will create a zip file of contacts, but my email auto deletes a lot of email, even Apple Email. Search on DOJ MDM and antitrust, they mention the MDM on parental controls, but also other devices and it’s deemed a huge security risk. Report it on IC3.org, if it will allow you, it blocks me. Check out your scripts, see if it’s collecting recent data, such as calls, websites. At the bottom, it says something like search for apps, type either ssh, JavaScript or Script in there, see what results you get. It’s most likely someone you know that has a MAC computer and has access to your devices. I can collect data, and see what’s going on, but I can’t stop it. Oh, my router and firewall are unplugged, but it is still getting in, verified cell data, and it’s not there. It’s using a remote access tool, and has the “root” password? It is showing an internal IP address, not cell phone. But many ppl have the same internal IP addresses. But Bluetooth will turn itself on, on the first page of settings, or says Wi-Fi off, but when you select Wi-Fi, it’s on and green. It shows that it’s scanning the network for devices, indicating I have 22 and 22 were expected. It shows much more. But since it scans everything, you can’t add anything new without it taking over. I bought a small Amazon fire to avoid the high cost of another IOS device (I’m disabled and on fixed income. But it installed parental controls before I could set it up! Most security programs require Corps only. But I’m not a Corp, and someone downloaded it! I have a couple things in the works. If I could have a Windows PC, and a simple phone (at this point), I’d be OK, but the hacker will not permit it! 1.6 years to date. BTW, depending on where you live, you might be able to get a private eye or attorney then get a subpoena. Apple told me they have “real” user info, even if they obfuscate it. Then you could get a restraining order (or sue depending on what you find). It’s hard to track phone activity (they have spoofed my phone even to call Apple and reset passwords on everything. When you looked at Analytics, did you see scanning and counting? I’m not sure, but think it occurs when you reboot, I’d just reformatted again, a few differences, but it was on Wi-Fi right away. And 22 devices? Nothing is turned on or plugged in, I had to remove the Roku devices as well!

Jun 3, 2023 7:48 PM in response to Livingmare

What does the Cisco VPN tell/provide? I was in Security for decades until 25 surgeries took me out, but we had nothing like this. Look under shortcuts and check out you JavaScripts as well, I had 87. My email

on my devices is redirected to a fake site, but if I go to a different computer not near my home I can see real data that included auto deletion of email. All accounts compromised, Fraud, cyber stalking, equipment destruction, cancellation of need grocery delivery, froze all accounts. Many fraudulent apps downloaded and hidden, but if you go to the Apple site, they will let you see hidden apps for a few months back. It accessed my unplugged router/firewall! Using SSH, port 22, something like WRT? And it says root and password (hidden). They hacked my home alarm with a stolen device then came in my home per alarm report, and location services are in and won’t allow cutting them off. I’ve tried a few VPNs, but they get bricked. I also noticed my internal IP addresses show up as external addresses? Except when running JavaScript, which I know very little in this area. It’s all over the device, in the browser, likely turning off options (if not MDM), or maybe you need a Mac to see it? You must have a Mac to install and control other devices. And they say a FQDN and business email. So if you bought a Mac, and provided a domain, could we replace the MDM? BTW, when I went offsite to view real email, the pages I was viewing were copied to my phone? This stuff is so different, and I’m so slow these days. Last surgery for cancer, doc said there was a 50% chance of return in 3 years, everyone knows stress causes cancer. It’s been 1.5 years, and for a long time I was extremely stressed, until I realized this hateful person was intentionally out to hurt me. It’s not easier knowing that, but it’s obvious. I have no data, pictures, contacts, social network to keep in touch with ppl out of country. Yet multiple cloud services are added. I never kept data in the cloud before this started, now it’s all over. I read on one page that 90-95% of people that do this cyber stalking are extremely mentally ill. Why else would someone do this? If I come up with something, I’ll let you know. I know what does not work, reformatting, new accounts, new devices, different devices like Windows or android, upgraded firewall, Antivirus or even a VPN. Or, and begging, calling Apple. They know (some of them) much more than they are allowed to say. I don’t know how many ppl have the same issue, but they are huge. I guess they don’t care about a few terrorized people. They make so much money, they can afford to do without many customers vs the effort required to research and fix things. Maybe the DOJ will help with the antitrust issues with MDM.

Jun 3, 2023 7:56 PM in response to AgentDragonfly

I know a lot of what is happening and have documentation, read through my posts. But the knowledge does not help to remove the MDM. I wish I could help you. I have decades of security experience (now disabled). But even with Corp Security tools, I still could not remove this. I can’t even delete games. And ppl that say you are crazy just don’t understand the complex technology. The MDM tool does not appear to be complicated, but it causes a lot of damage. Please do write to IC3.org, it might help with the antitrust issue with MDM that the DOJ considers to be a high security risk!

Jun 25, 2023 8:51 PM in response to T3ddy19

Thanks for all the information. I've been calling apple

support for more than 40 days now.

i "repaired" everything to be able

and work, brought all my family's devices back and took 10 minutes

to start the nightmare again. Apple says I'm a paranoid, but losing my job, plus stolen money, is no joke.

Jun 26, 2023 4:47 AM in response to Community User

This is getting really bad. Why Apple and Google won’t address the elephant in the room is just so wrong.


I am seeing everything you guys are, the wifi is hacked, iOS iPhone and iPads, macOS MacBook Pro and Mac mini, Chromebook ChromeOS, Android phone.


I’ve been calling it InvisibleBeta and StealthyDeveloper because we can’t see it but they are there!

Jun 27, 2023 12:31 AM in response to gravityfed

Wow! I am glad I came across this tonight. I have been dealing with this since March ‘23. My windows, Mac and Linux PCs are infected. My iPhone 13 Pro (typing on) , Google Pixel 6 pro and Samsung A13 android all infected. Every day I get more and more information. I signed up as an apple dev so I could install iOS 17 on here. The analytics data has been great. It is causing a lot of the processes to break and automatically create bug reports. That’s what I am out researching tonight. I have created new iCloud accounts, google accounts and stopped using WiFi / Bluetooth and it doesn’t matter. They even were able to take control of my Infotainment / GPS system in my 21 Audi via Bluetooth. That was witnessed by the sheriffs department. I have been compiling Ip addresses and tons of documents and giving to the cyber unit of the local FBI office as well. The only thing that helps pause the flow of data and monitoring is by disabling the SIM card temporarily(which I have also went through multiple sims).


Some of the common recurring exploits I have noticed on my devices:


iPhone / Mac:

  • iokit exploits
  • mdm policies
  • proxies and tunnels (hidden)
  • . Look for cloudflare tunnels
  • firebase app attacks
  • socket streaming
  • hidden apps


Android:

  • device policy (mdm)
  • VPN hijacking
  • DNS hijacking
  • Google Play Framework / Services Malware
  • Very high data usage ( almost 200gb / month) when before it was maybe 10-15
  • Remote Config and “Google/Samsung ” system apps that are forgeries (Due to leaked App signing keys. Google search it)
  • nearby device sharing and uwb


Linux:

  • pam elevated permissions exploits
  • pipewire, alsa and avahi exploits
  • Firmware / Bios malware injection
  • dbus socket exploits
  • dns highjacking
  • wifi bt control with overlays to hide connection


Windows:

  • Lsass elevated exploits (Microsoft finally released a security update to address it with 22H2
  • group policy and domain join enforcement (personal computer)
  • Bios / efi exploits. Microsoft just released a partial security update but you have to activate it manually
  • sfc /scannow is your friend from a admin cmd prompt
  • nearby device sharing
  • print server exploit


The iPhone and Samsung have never been rooted yet they have root cmd line access.


The bad thing with all these devices is as soon as you factory reset or wipe (even complete reinstall) the first thing all these devices want to do and do is turn on your radios(WiFi bt nfc) and search for nearby devices. Someone previously in the thread mentioned infected Roku printer and other iot devices spreading it. I can confirm that is what has happened to me after resets many times.


Sorry for the dump of info (even non Apple related) but this is obviously a bigger problem than companies are willing to admit right now. They are all interrelated though based on WiFi, BT NFC and the radios that our devices have, as well as, device sharing, sync and backup. Something needs to change. I mentally can’t keep living this nightmare and second guessing my sanity.


I applaud apple on making their own chip though because they didn’t (yet maybe) have the Exonos exploit from a couple months ago that allowed full device control with someone just having your phone number if you had WiFi calling enabled. It didn’t even make the news. Samsung still hasn’t released the fix for my a13 months later

Jun 30, 2023 10:06 AM in response to pia157

To Pia, I received info in my inbox sent by you, but attempting to use the link to your post was blocked, it included the wording “can lshow you a screen shot where the Mac “. I’d read that you must have a Mac to install this, I have no MAC. But I’ve received attacks and such from a MAC, web iCloud access with a Mac and more. I’ve lost a lot of $ due to equipment destruction, hiring ppl, software and much more, a lot of fraud, including Apple apps that were purchased then hidden. I also read that purchases only show on the device used to purchase, but sometimes I see these purchases, and some are free. When I searched on your name, only the above post showed up. I should mention the app is hidden. At one point, I decided to download the App, it was the only app I’ve seen to date that included a hide or hidden button on the shortcut. When I downloaded, it said I had to contact the administrator [of the Apple Configurator or MDM] to view anything. I have the usual symptoms of MDM plus many more at this point, lots of JavaScript on websites, 87 JS under shortcuts in one day. Getting new everything has not helped. I completely disconnected my Internet weeks ago, but they are using a rogue Wi-Fi router. I’ve found 3 other routers, but not this one. It turns on Bluetooth then the router, all devices have been compromised. Resetting network made no difference. Turning off settings, no difference as they get turned back on. Only my iPhones have connectivity. A lot of data transfers in the background, and my devices had data offloaded to a cloud service, about 9 were installed. Simple settings, like only use the current number for messages does not work, they are broadcast across devices. Also, I recently found out that ppl were coming in my home when I’m not here. Ok, I don’t recall the last time I went to iTunes, I used to avoid all apps on phones, at least no third party apps. The other thing, the beta site, I’ll have to try to find that. But there is no MDM under VPN settings, there is a link to work or school but the Apple ID does not work there. Must you have a Mac to view this information? It’s been a long time since I’ve used one. And I don’t recall, but it seems like you can’t search MDM on IOS, found many entries on Windows PCs, 1,000+. Then strangely enough, if I start out with a new PC or reformatted device, settings are changed within 3 minutes, permissions, accounts deleted, restricted to C drive, restricted on everything I look at! All with no Wi-Fi network (except the rogue). Same thing happens in router/firewall. When I reset, or buy another they jump in, change admin password and throw me out. This app is one of many that were installed and hidden, like 2 remote access apps, a screen recorder (which I can view but without any controls), it even created and mailed a link of the recording to me and company (someone else?).


I”m certain I’ll have to get rid of all equipment again, but the MDM scans for all devices, phones, PCs, iPads, IoT, everything.


ok, did your actions get rid of this? Must I get a MAC computer? There have been many attacks on Apple lately, one called VastFlux and it used JavaScript, 11 million phones! Plus, 1,700 apps on the App Store were infected, even viewing the ad for these apps caused infection, dubbed the largest attack in history. More on Human Security, point is, I think the flood gate is open. Antivirus has been no help on the iPhones.


I have to remove the MDM, I even asked if I could install it on a new set of devices, but was told “NO” because I’m not a company! This is not a third party app, it indicates it was developed by Apple.


so, would getting a MAC work or help? Are the MAC devices able to be protected with AV? Can you see installed files? I’m seeing something new now, attempts to install a “WebKit” which some sites indicate has been compromised, but this activity is not very visible. Could I use an iPad to view anything? We have public places where you can go and use computers, but no MACs, and you can’t install anything. I’m going to look for the beta site. Thanks so much for your info. This has been going on for 2 years now.



MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.