MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

I am a personal 'User' I have cycled through many hours and days with support. No one knows what is going on. Most likely because I am never able to speak with someone that understands the Enterprise platform. I feel this is happening via my carrier- but Fraud sent me to Tech support. Tech support told me my phone is hacked and to file a police report.

In combination I suspect that MDM is a gateway for an external developer to access my phone via various methods: webkit, Xcode, Apple Store Connect, SDK

I am about 99.99% sure I know why, but that is something that I will not disclose because most likely all of my activity is monitored; despite the very strict privacy settings I try to maintain.


Symptoms:

  1. My apps will sometimes tell me they did not come from the App Store (Maps, FindMyiPhone, etc..)
  2. When I make an attempt to chat with Apple support I receive a message to Use Messages to Connect with Business. When I have my iPhone in LOCKDOWN mode I receive a message that I cannot use Messages for Business when my device is locked down.
  3. I only have one device. However, I am sharing across devices- many times or I have the option to. The choice is not grayed out.
  4. I am unable to perform an Emergency Reset because I am usually sharing something - Notes, Home, Health, Books....
  5. I do not use iCloud Drive due to multiple security concerns. Almost every time that I double check those settings apps show that they are using iCloud Drive. (Game Center, Health or Fitness, Notes, Books, Apple Support, Wallet) While clicking to turn OFF syncing I have had a battle with it changing right back before my eyes. (I have screen recordings)
  6. Game Center will come on even though I have strict Screen Time settings.
  7. I am generally either sharing, or my phone is gathering data from Health; even though that privacy option is supposed to keep that from happening.
  8. Sometimes I am unable to even sign out of my phone due to 'restrictions'.
  9. I have 'Share with Family' sometimes

*Those are only a few symptoms. That is minus the horror I see from the extraction of information I backed up into Kali Linux

As I have mentioned I have spent many many many hours with Support. One Senior Director did spend time Googling the services that show up in my Analytics. I have even uploaded screen shots and documents, but I never heard back.

I REALLY REALLY need help here.

I will add attachments. They won't be nearly the amount I have. I am begging!!!



iPhone 13, iOS 16

Posted on Apr 2, 2023 2:32 PM

Reply

Similar questions

160 replies

Aug 3, 2023 4:04 PM in response to T3ddy19

Ok, I was incorrect about the Wi-Fi and serial number being the same as a user pointed out. But the MDM uses the serial number and a beacon to find your device, and it scans your network using “geofencing” to detect any new devices. I’ve heard all the “impossible” comments as well, they have no clue! I’ve had my devices reformatted and bought new ones (new everything at one point), but since someone had one of my devices (now two since earlier last month) and was apparently using a MAC computer (required) to remotely install the MDM on my new devices, it didn’t help. And, it’s a free app. But there are other “entities” looking at the dangers of this program if in the wrong hands. You have to search a bit, but it’s out there. I’ve also seen GitHub and Python, along with many new scripts under shortcuts and programs the programs always get hidden after installation. I’ve wondered if there could be a tool or method to compromise the MDM on the dark web? I’d been in Information Security for about 30 years (CISSP, CISA, CISM) in one form or another, but I’ve never seen anything that compromises so quickly (3-5 minutes). If I still had the same job and title, I’m sure I’d be able to get it removed. But due to unfortunate ongoing surgeries, I’m no longer in security.


mine sends out fake emails as well, and automatically deletes needed ones. I likely mentioned this already, but go to a public network, your email account, and view source. I was surprised to see settings that created a fake page (JavaScript) and hide auto deletions and hidden folders. My banking page is also fake. I read on Apple documentation (I think that was the source), that the MDM does not use Safari, but instead it uses web clips to show pages. This allows considerable actions and views, like view source, tool bars, headers.


You mentioned FaceTime, FaceTime was used to contact Apple for over an hour using my phone number. Apple won’t accept FaceTime. So it was not actually FaceTime, but actually a “feature” under accessibility options that permits you to enter another phone number and impersonate the victim. There is usually a history, if not deleted. But check the numbers used if the access looks like a phone call. It also allows incoming calls, but they disable my phones when using this method. It seems like I saw something about beta somewhere, but don’t recall exactly where I saw it.


I have learned there is a history available that can tell you the location of access, although I’m not certain if it’s because they had my stolen devices? A subpoena would be needed. I did see an error in one log that was 313 (I think) and said something like “another person is using your ID or device”. There is so much.


A family members account was also recently put on the most recently taken iPad. Idk how they did that, unless it was from being at my house?


How did you discover your logins were going through APIs like GitHub, Google and so on? Is that info on a MAC computer?


BTW, you mentioned a web site, if you have a web site and company email, you could enroll in the MDM. I’d guess it would not overwrite the current one, but it’s free. You could buy a cheap device, keeping everything offsite with no iPhone, then install the MDM on it.


BTW, checkout LinkedIn and search on MDM with keywords malicious and such. There is more out there. This is not impossible and you are not going insane, unless from the constant bother. Also, check put .gov, MDM, parental, more interesting things.

Aug 9, 2023 3:00 PM in response to bct1

Did you have any luck with the sheriffs department? I’m not always 100% correct, but trying to help others and get help. I’ve found a MANAGED Wi-Fi hotspot that resolves to Apple based on IP, it seems to be running most of the time, but in particular when I do anything. I don’t have (or should say I never purchased a hotspot! Since it’s managed, I can’t delete it! Several other things pop up and say “you can’t do this on a managed device”. I read on Apple that the the hotspot is an additional “feature of the MDM. Also, per MDM Apple documentation, some options and things I’ve experienced are hidden headers and footers on Web Sites and email (you can’t see the actual sender of the email). Apparently, the MDM uses “web clips” to filter and prevent seeing this data. Try going to a public computer, sign into your email, then “view source”. Mine was redirected to a created page that appears to use JavaScript. Many features were hidden, like deletes of password resets to Apple and other accounts. Lots of hidden apps are downloaded, remote access, now more, about 4, 2 banking apps, one screen recorder and print screen capture, one complete control of your network and everything on it, many more apps. I was in IT Security for a long time, I’ve never seen anything like this before.


I had someone install an MDM before while I was in the hospital, I found the vender name using a Windows device, it was removed right away. But not this time. The MDM link even includes a “HIDE” option. Since it includes a Wi-Fi hotspot, firewall rules are bypassed. AT&T had an attack a while back where employees were installing “hotspots” on victims. I’ll see if I can find that article, can’t put links on here, but can provide search terms.


based on what I’ve experienced and read, it’s likely someone you know, they only need your PIN and hands on for a few minutes. Once it’s on one device, it can remotely installed to almost everything, all computer types, certain TVs and much more. I’ve attached 3 pics. So what to do? The only thing I can think of is to get a new device and install a similar MDM before you bring it home. I’ve not tried this yet, so I’d try it with something new. It gets on Android as well, so that won’t help. Or, get a subpoena and see if you can get a restraining order. Be careful when asking for data to make sure you get all recent connections to your network, device name, serial number, user name and Apple ID. I really wish Apple would help. I’ve read the Sheriffs Dept can issue a subpoena, but that’s based on state. I’m not 100% certain if it has to come from an attorney? I’d really rather not have to hire an attorney. I have 2 missing Apple devices, I know who had them, but they also use a Mac to go into the iCloud and download and share apps. They also use Family Sharing and Bluetooth. They connect via hotspot, then can connect up to 8 devices using Bluetooth. They also use the clipboard to collect data (under shortcuts and using scripts, mostly JavaScripts but other as well. Even when Wi-Fi shows as off on the first page, it’s still on. Once data is collected, I’ve seen it texted or emailed (using my address!), also under shortcuts and scripts. Anything I’ve tried to cut off Bluetooth or Wi-Fi hotspot works for a little while, then turns back on again. I have a Wi-Fi detector, but just keep it off most of the time due to constant beeping indicating Wi-Fi! The battery runs down quickly, and the cell signal drops from 4 bars to 2 bars. At one point, there were 87 scripts on my phone. I don’t have data on here, no fascinating life, and it keeps escalating. IC3 (gov) is very interested in this topic. I’ve yet to report the suspect, hoping they will stop, but it just gets worse.



Oct 31, 2023 1:53 PM in response to AgentDragonfly

I have some information that might be helpful. After years of looking for answers and getting none I discovered this sys diagnostic test.


https://support.umbrella.com/hc/en-us/articles/4406646902420-How-to-capture-a-sys-diagnose-from-an-iOS-device


I think you’ll be surprised with what it can reveal.


I am having the same problems and more…connected to cameras, speakers, amps, I could go on. Intelligence platforms are running in my analytics. Mobile Obliteration, Pegasus, shim remotes.

I tried to post some pictures here but it’s blocking me. I’ve been making all the same calls to tech supports. No real answers other than yes my device is being remotely accessed. I’ve had a dozen new phones since this began. Everyone of them have the same problems. I have managed to do a couple resets but it was compromised again within a hour. I’m still looking for answers like you.

Do you know of any websites with specific information? I’ve googled many platforms listed in my analytics so I know who it is. Any suggestions for a way to get it confirmed?


Nov 3, 2023 3:28 PM in response to Watchlistvictim

The stacks log is packed with useful data


example:


This is logged from my “CloudConfigurationDetails”


bplist00Ö

\AllowPairing_ConfigurationWasApplied_CloudConfigurationUIComplete_ConfigurationSource_PostSetupProfileWasInstalled\IsSupervised "<[qžŸ ¢£

¤


this is from a stack labeled MCMeta


bplist00Ô_LastMDMMigratedBuild_LastMigratedBuild_&StopFilteringGrandfatheredRestrictions_ AllowedGrandfatheredRestrictionsU20F75Ñ ^restrictedBool£

[allowiTunes_allowAddingGameCenterFriends_allowAppRemoval(<eˆŽ’¡¥±Ð

â


payload manifest - bplist00Ò_OrderedProfiles^HiddenProfiles ¡_=secure-wifi.spectrum.net.8DE2356F-F195-444A-B534-6E67170C4E73

./1q


I could go on for days about this lol


I think what they do is they partition your operating system into multiple operating systems that synch between each other. So while you’re on one partition. They are on another loading remote content and once you put your device down they synchronize back to their partition that is virtually identical but different logs home screens etc


May 25, 2023 7:39 AM in response to AgentDragonfly

Wow! This sounds so much like mine! Either can’t turn off games, or if I turn off, they come right back. There were 87 JavaScripts under shortcuts. There is also “clips” under privacy and security, microphone. Sound became very quiet, have to use speaker, that was the first symptom. Lots of redirect scripts with email to a fake or created site. Email is often deleted, some from 2 more fraudulent sites downloaded and hidden (like the MDM app), 2 banking apps, screen recorder, more! I had 87 scripts under shortcuts! I’d never even looked before. It also turns on family sharing, that permits it to download on one device and then spread to others, including Windows/Android and Roku, Smart TVs. My data is also moved to the iCloud, then transferred from there to another cloud service. If you have a windows device, search on *mdm*.*, make sure “hidden” is checked under view. My iCloud sign on page is also redirected. There is an Apple page where you can see hidden purchases, but it only goes a few months back!


When I deleted 2 accounts and created another, it was gone for about 7 hours, no grayed out options, “clips” or games. But then it visibly showed under purchases and was installed. It gets much worse, identify theft, credit card fraud beyond App purchases (the one on Apple. Alarm system hacking and entering my home. Deleting password reset messages, using my phone number to call Apple, using an Apple feature. It will not go away with a reformat. For the first install, physical access is required (I think). I was in the hospital for about a month when this started, but it could have been sooner. Based on what I’ve read, you should reformat it (unshare) or delete problem apps, several things have to be turned off. Delete your account! You have to set up a new account that does not have your name and address on it! It goes by name and serial number. I’ve not found any solution at all other than what I mentioned. Keep in mind, smart devices, IoT may also be compromised, smart light bulbs (I found one in my house using a detector) and what appears to be NFCs. It also picks up a lot of DECT, smart fridge, Wi-Fi cameras, alarm

system (if Wi-Fi), some TVs, I guess my printer is infected as well.


a lot of things get transferred in the background, like the router IP, although the MDM has options to scan for new devices, phones, PCs and much more. This started Dec 2021 or earlier. I was a former Global IT Security Manager, but I’ve found no way to remove this! It also modifies the router and has a beacon, it appears to allow more hackers? And there is more dangerous activity going on that you can’t see.


they also downloaded Xcode, then hid, and of course JavaScript can be used under shortcuts, they use commands that I’m not able to use? Everything is compromised. I’d like to speak with you to compare notes, although phone, text and even this chat is transcribed. Most security emails are blocked (all read). Text usually makes it but not always. I have about 7 IOS devices, will have to get rid of all of them. Android and Windows get quickly

compromised, MDM and parental controls. Attacker has used Unix and MAC. BTW, the DOJ has the MDM under investigation, it said antitrust as they also used it for parental controls, and said it’s a safety concern! This account will likely be gone soon. Oh, when I bought new devices but didn’t set them up, they were compromised around the time they came in the house! I’ve even unplugged the router, but activity continues.


I never thought I’d end up with a fraudulent malicious app(s) that they won’t remove! I actually got an MDM app before, around 2015 (in the hospital again). It had the venders name on it, I called them and they removed it while I was on the phone! Now, 1.5 years, disabled, trying everything, but no help. As a security manager what a horror it would be in an 8,000 user environment, but they likely get help.

Jun 1, 2023 12:59 AM in response to AgentDragonfly

Girl I have been living this nightmare for nearly four years. I hear you loud and clear. Absolutely NO help and lie after lie. Try this MITRE ATT&CK® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. Very accurate and give you insight to how the attacks are happening.


Mine is through direct access remotely. Abuse of administration privileges from a prior Global admin, azure and google workspace. I have been documenting this from day one. Binders full of evidence, fraud, spoofing, malware, spyware and everything in between.

There is very little oversight to these web developers and MDM companies. The Big Tech Co’s sell your info to the highest bidder. Watch Social Dilemma. Very disturbing. Unfortunately, the criminal is protected and the victim pays dearly and suffers the consequences. If someone has access to your Apple ID which is Very easy to get nowadays it can be devastating to individuals.


I’m literally sick of the stress it brings on, the Mind F*** and the financial loss. It is a vicious circle and a living nightmare. Check your Apple App report and Apple analytics. Also check your VPN again. It will not be visible you have to click and click again to find it. Check IPsec see if you see a Cisco VPN.

Best of luck to you.


[Personal Information Edited by Moderator]




Jun 27, 2023 12:31 AM in response to gravityfed

Wow! I am glad I came across this tonight. I have been dealing with this since March ‘23. My windows, Mac and Linux PCs are infected. My iPhone 13 Pro (typing on) , Google Pixel 6 pro and Samsung A13 android all infected. Every day I get more and more information. I signed up as an apple dev so I could install iOS 17 on here. The analytics data has been great. It is causing a lot of the processes to break and automatically create bug reports. That’s what I am out researching tonight. I have created new iCloud accounts, google accounts and stopped using WiFi / Bluetooth and it doesn’t matter. They even were able to take control of my Infotainment / GPS system in my 21 Audi via Bluetooth. That was witnessed by the sheriffs department. I have been compiling Ip addresses and tons of documents and giving to the cyber unit of the local FBI office as well. The only thing that helps pause the flow of data and monitoring is by disabling the SIM card temporarily(which I have also went through multiple sims).


Some of the common recurring exploits I have noticed on my devices:


iPhone / Mac:

  • iokit exploits
  • mdm policies
  • proxies and tunnels (hidden)
  • . Look for cloudflare tunnels
  • firebase app attacks
  • socket streaming
  • hidden apps


Android:

  • device policy (mdm)
  • VPN hijacking
  • DNS hijacking
  • Google Play Framework / Services Malware
  • Very high data usage ( almost 200gb / month) when before it was maybe 10-15
  • Remote Config and “Google/Samsung ” system apps that are forgeries (Due to leaked App signing keys. Google search it)
  • nearby device sharing and uwb


Linux:

  • pam elevated permissions exploits
  • pipewire, alsa and avahi exploits
  • Firmware / Bios malware injection
  • dbus socket exploits
  • dns highjacking
  • wifi bt control with overlays to hide connection


Windows:

  • Lsass elevated exploits (Microsoft finally released a security update to address it with 22H2
  • group policy and domain join enforcement (personal computer)
  • Bios / efi exploits. Microsoft just released a partial security update but you have to activate it manually
  • sfc /scannow is your friend from a admin cmd prompt
  • nearby device sharing
  • print server exploit


The iPhone and Samsung have never been rooted yet they have root cmd line access.


The bad thing with all these devices is as soon as you factory reset or wipe (even complete reinstall) the first thing all these devices want to do and do is turn on your radios(WiFi bt nfc) and search for nearby devices. Someone previously in the thread mentioned infected Roku printer and other iot devices spreading it. I can confirm that is what has happened to me after resets many times.


Sorry for the dump of info (even non Apple related) but this is obviously a bigger problem than companies are willing to admit right now. They are all interrelated though based on WiFi, BT NFC and the radios that our devices have, as well as, device sharing, sync and backup. Something needs to change. I mentally can’t keep living this nightmare and second guessing my sanity.


I applaud apple on making their own chip though because they didn’t (yet maybe) have the Exonos exploit from a couple months ago that allowed full device control with someone just having your phone number if you had WiFi calling enabled. It didn’t even make the news. Samsung still hasn’t released the fix for my a13 months later

Jul 24, 2023 12:35 PM in response to AgentDragonfly

Ok, part 4, if I’m allowed 4 posts.


This is about 1%. Do a wildcard search on you Linux box using MDM, both in files and in root. I know nothing about Linux, but on windows the search would be *MDM*.* then the same for system or root files, but use the % in place of the * then note the location. Other files will likely be listed under the same location. Many may be cab (or cabinet files), most are encrypted.


ok, I’ll try to summarize again:

collect data from all sources. Create a one page summary by category, email, rogue emails (my Facebook account was removed after my address was used to send links to my no longer available contacts, a virus?). Also, look for emails that you did not send, and settings changes on device vs on public. System changes, harder to document, you could use a video. Deleted or offloaded data (check for added cloud services other than iCloud). Look at FaceTime history, I deleted FaceTime and it came back. Rogue hotspots, scan house for Wi-Fi, NFC, Bluetooth, RF and such. Avoid paying large sums to “pros” for scanning. Look at internal images of smart bulbs online. Look at YouTube to see how Wi-Fi can be added to almost anything! Document and provide images for the things you listed above, reference page numbers in summary. Include recent attacks, they are difficult to find, but they are out there. The Attorney General in NYC got a lot of press on his find with Apple Phones. There was another article on YouTube also WSJ and iPhone attacks, but I don’t recall the details. I think if you can provide proof and get authorities interested in what it could do for them it might help, plus, it’s all (mostly) new, except Pegasus which they keep announcing as new but it’s been around since 2015. They will also ask why you think you are a target, implying you are a nobody, why would anyone be interested in your information. There are articles on why ppl are cyberstalkers, look this up to provide an answer. My work history has including a couple of high target risks (such as banking Information Security) which has made me a target in the past, or it could be an X BF or GF. Provide info on why.


I think everything has to go. Unless you are able to get it removed by installer and you trust that it’s really gone. I hate to say that! And I don’t know what “everything” includes! In my case, alarm system, Rokus, PCs, IOS, Samsung TV (research vulnerable TVs). Firewall (id replaced my router/firewall about 6 times hoping to block it before I knew what it was. Avoid using credit cards online, buy gift certificates specifically for Amazon, or other accounts. Watch closely charges on credit cards. Get a list of hidden apps asap, they don’t keep that info for long. It’s also good to keep dates of things happening, but that’s so much!


Some apps seemed to have opened a back door to other attacks, but that’s difficult to determine. If you find a smart bulb or other such device, you might want to call authorities to remove it, if they are willing. Some newer devices will unscrew, but one had a big visible green circuit board and emitted a loud Wi-Fi signal.


Check out devices on you router/Firewall, try to identify unknown devices (if you can access the firewall. Note they may change the name of your Linux box to something else, so get MAC addresses if possible. And, look for NFC, they look like little circles if paper! Lookup online, scanners will pick them up.


I’ve tried everything I can, contacted venders, replaced equipment, bought software, scanned, recorded on cameras. But I’ve not yet completed a report to IC3 dot gov, or finished report to local authorities. 1st, it’s all been very difficult and excessive, second, not wanting to cause harm. But it gets worse, not better at least so far. Also, like others, when I try to get help from various sources, something worse happens again! I wish we could speak in person. Good luck, let me know if you are able to remove this mess. PS, the DOJ and FBI are all over this MDM because it over rides all security and it’s very dangerous. That’s why you must report to IC3!

Jul 24, 2023 12:48 PM in response to AgentDragonfly

Under your services, the calendar configuration relates to the MDM per Apple. Search on first line under Apple or search on Apple MDM with the exact calendar words. Have you looked up each service with MDM and Apple added?


Calendar declarative configuration for Apple devices

Use the Calendar configuration to provide account settings for connecting to a CalDAV-compliant server. These accounts are added to an iPhone, iPad, or Mac enrolled in a mobile device management (MDM) solution.

Jul 25, 2023 2:57 PM in response to GSS_544

Check out “hidden apps” I didn’t know you could hide them! I’ve also seen GitHub and Python (likely the hacked version). Many purchased and “free”‘apps were downloaded. And there is one that provides SSH and other programming capabilities (it’s not the dictionary). I was surprised seeing SSH under Apple Shortcuts used to hack my network using port 22. The network is disconnected, so now (or before?) I have a somewhat hidden managed hotspot with no ability to remove it. I can’t use it, it connects to me. I have a Wi-Fi detector, it’s going off as we speak. It connects via Wi-Fi then connects to multiple devices using Bluetooth. And even if you think you have cut Wi-Fi or Bluetooth, it’s still running. Also, look under shortcuts (don’t run anything as they often reference more dangerous things but the source code is on the web). But previously used scripts, such as SSH will show, I’ll include the pic if the computer God or Devil will permit. There is also a scanning list that shows up sometimes. If I can locate it I’ll post as well. The MDM can compromise just about anything, I tried Android as well.

Aug 9, 2023 3:06 PM in response to -Hey-You13-

MDM is the starting point of the hack, it takes complete control of devices within the geofenced area, for me; downloads hidden apps and hides them, screen recorders, remote access, banking apps, spyware, and much more. replaces web sites with fake ones, collects data, often sent to another cloud service. Runs malicious JavaScripts and other programming tools under “shortcuts”, hides headers on web pages and hides email headers as it impersonates you email account,

Oct 12, 2023 3:56 PM in response to T3ddy19

i have been researching and digging for almost 3 years on my own. no one believed me and after proving it they just did not want to hear about it. i know this is apple site but this is my 7th phone but first iphone the other 6 were android. the common factor is root installed and radio access tech or RAT which is also remote access and that is used too. next is api restful api to be more precise which can come from multiple areas. i have matched api, root access, mdm, iot, bluetooth, to every device. microsoft azure, visual studio, googleapis, enterprise, yahoo, facebook, and many more. facebook is the most seen on phone but my desktop is all microsoft. i have used windstream and spectrum and both routers were taken over as well.

get a network analyzer app and you will literally feel your mouth fall open at what you find. im on a loopback completely separate from every other device. i have dns that make no sense.

we need to get together and fight this!

Dec 2, 2023 1:40 PM in response to AgentDragonfly

Hello.


Reading this thread has been helpful, we all know whqt its like when you think your going crazy and no one believes you, then you question your own sanity until the tell tail signs appear again.


its been about 3 years this has been happening to me, ive done a lot of reading and calling but now i dont care, as much as i used to anyways - this will never end im sure. But, when bordom strikes its sometime to occupy the mind.


Before coming across this post i actually narrowed it down that it had to be an installed profle, now reading this im certian. Also, i went through my analytics data and found a report that had converted all my apps to a different form of app or to a different storage location on my phone. Today, i went to sign into iCloud online and a redirect thing appeared (attched) i googled what the link was for and it was to 'sign out' of a 'CWA' which got my curious because ot wanted ro open the app store, i clicked it opened and app store and there was app updates in there from days ago, i only updates my apps an hour before hand, fishy .. my apps are not ny apps and havent been since i seen that analysis data.


I download an app called TulaByte which loggs all connections to your device (attched) i googled some of the stuff and its apprantly the icloud Private Relay service which you have to pay for, i havent .. theres a separate profles on a different storage file on my phone i think which is why is connecting to my device since i dont have that .. the mind boggles!


Anyways, on wards and up wards - another day on the calendar and still no closer on how to remove it.


Now i can't upload pictures when i try, typical!


I wish you all the best of luck of this journey, your not carzy! They are!


J.

Feb 23, 2024 12:54 AM in response to AgentDragonfly

You guys are describing, almost exactly, my life for the last two years. I am not in IT but have worked with computers for my career as an artist and let’s just say I’ve been on a Mac since the the first Macs were out and I drove my Mac IIci to college and I’ve bricked and rebuilt more OS’s than I can remember. I have so many screen shots almost identical to the above and the settings toggling back in front of your eyes! Ha! People do call you crazy. I’ve wiped these machines and bought new ones. I’ve been told “it’s not possible” and then had Apple days later push major OS updates (remember the huge Webkit update!) I also have theories as to why money has not been taken, although it’s possible there hasn’t been the opportunity to steal a large enough sum. But moreover I feel it’s probably tactical or botnet.


Thanks for the tips. I would add that I can reiterate that I’ve found that our printer has always been implicit whenever we get it back online. Fancy new routers have not changed the situation. Samsung smart TV browser catch will always fill back up and eventually CPU will fill up. Apple senior advisors have told me that they can only help me with as much as they are trained in doing. I have escalated to engineers but it was beyond me which are the correct logs that are the “smoking guns” and furthermore I started to feel like they string me along as their research animal. (Free Apple bounty?) Now I can also vouch for above mentioning of IOkit, SDK, WebKit, AppStore Connect, use of Game Center and Health/Apple Watch, etc, But there have been at the point of all new Apple ID’s, unfortunately I have one member of my family who needs to have their computer reset by a corporate entity each time so the method above seems unattainable if everything needs to happen in lockstep. We had come very close to resetting every device all at once a year+ ago, but not to the DFU level and not to mention firmware of every other mfr.


also want to note that to me (very abstractly) basically all XCode dev stuff all goes back to IOkit stuff (Spotlite helperUtility is the real brains) , and it’s in the CFBundle (your lovely bad Certificates that allow you to let the floodgates open in any web browser- it doesn’t matter as far as I can tell, and also WindowManager because like DarkAqua and FauxDark Aqua, we know you’re supposed to be there but you are complicit right, parent proces - ???). Watch the SQLite databases for everything. I wish I could read it all and figure it out. (although it’s very MDM to slow updates… regardless) there is a propensity to keep everything legacy or roll a few things backwards, like having to manually update every app and OS, (sort of a version of classic ‘slowly gaining permissions’). I’ve found old modern scripts (sometimes supposed to be there) but then seeming active and logs of ACP (affordable cable-my address is not enrolled), and old firmware on our devices and Mac address changes on our LAN, and really the craziest things.


Anyways thanks for the validation. I’m coming close to the full DFU resets and new Apple Id’s. IDK if it was mentioned, but there is a good help page on Addigy’s website about briefly disabling SIP (system integrity) and the correct terminal commands to wipe any previously existing MDM programming before reenabling it. It might be a good step before the DFU reset or (in my case) between DFU resets!

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.