You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

I am a personal 'User' I have cycled through many hours and days with support. No one knows what is going on. Most likely because I am never able to speak with someone that understands the Enterprise platform. I feel this is happening via my carrier- but Fraud sent me to Tech support. Tech support told me my phone is hacked and to file a police report.

In combination I suspect that MDM is a gateway for an external developer to access my phone via various methods: webkit, Xcode, Apple Store Connect, SDK

I am about 99.99% sure I know why, but that is something that I will not disclose because most likely all of my activity is monitored; despite the very strict privacy settings I try to maintain.


Symptoms:

  1. My apps will sometimes tell me they did not come from the App Store (Maps, FindMyiPhone, etc..)
  2. When I make an attempt to chat with Apple support I receive a message to Use Messages to Connect with Business. When I have my iPhone in LOCKDOWN mode I receive a message that I cannot use Messages for Business when my device is locked down.
  3. I only have one device. However, I am sharing across devices- many times or I have the option to. The choice is not grayed out.
  4. I am unable to perform an Emergency Reset because I am usually sharing something - Notes, Home, Health, Books....
  5. I do not use iCloud Drive due to multiple security concerns. Almost every time that I double check those settings apps show that they are using iCloud Drive. (Game Center, Health or Fitness, Notes, Books, Apple Support, Wallet) While clicking to turn OFF syncing I have had a battle with it changing right back before my eyes. (I have screen recordings)
  6. Game Center will come on even though I have strict Screen Time settings.
  7. I am generally either sharing, or my phone is gathering data from Health; even though that privacy option is supposed to keep that from happening.
  8. Sometimes I am unable to even sign out of my phone due to 'restrictions'.
  9. I have 'Share with Family' sometimes

*Those are only a few symptoms. That is minus the horror I see from the extraction of information I backed up into Kali Linux

As I have mentioned I have spent many many many hours with Support. One Senior Director did spend time Googling the services that show up in my Analytics. I have even uploaded screen shots and documents, but I never heard back.

I REALLY REALLY need help here.

I will add attachments. They won't be nearly the amount I have. I am begging!!!



iPhone 13, iOS 16

Posted on Apr 2, 2023 2:32 PM

Reply
Question marked as Top-ranking reply

Posted on Apr 3, 2023 6:45 AM

Sadly, there doesn't seem to be any help and the ones that will respond, will tell you you are either crazy or you can't be hacked unless you have your device to someone.


For what it is worth I have been dealing with this and here is what I have learned; you need to delete your old apple id's and confirm that they are deleted. You may not be logged in to any (neither was I) but it has something programmed into the IOKIT boot so you cannot reset the NVRAM properly, leaving find my process to look as if the activation lock is on.


Make appointments for each apple product to have a firmware/software update through DFU mode and make sure it is DFU because a factory restore will not remove the cache that is lingering in the files. This should all be done at the same time otherwise it will talk to the other device and reestablish itself.


The factor reset you are doing doesn't work because it does not empty the trash and it seemingly blocks any terminal command to do so as well.


Before you boot up your computer(s) & phone(s) delete and confirm you have deleted all of your previous apple id's. Write down the code it provided to delete the id because chances are you will have to call to

confirm its deletion.


If you have a google ID, check to see if you are enrolled in any trial based workspace or fire base programs. Workspace allows device control as well.


I have changed our TV's and printers but it still seems to latch on to any printer so now we do not print. Debilitating to say the least.


I believe that there are enough of us out there to confirm that this problem exists but apple will not respond until they have fixed it. I know it sucks. Two factor everything and I wouldn't suggest any external usb or thunderbolt security keys.


I also would not suggest any products other than apple. That will only make your situation worse.. even the keyboards because it will load a generic driver onto your device. Only use apple wires as well. I am definitely not an apple advocate, only sharing what I have come to accept and learn.


You may have to go line by line in settings on your iPhone to turn off everything that you do not use and if there is an arrow on it, click to make sure there is not an opportunity to bypass your defaults. The Mac computer is the same and there are probably about 100 Plists that will try to alter your default settings so do not take anything for granted until you have clicked through it all. Plists are just preference and apple will tell you that it does not mean that they are being used. That is absolutely correct but the Plists I have seen start with NVRAM and a fmm (find my

mac activation) which is huge problem.


for whatever reason it uses nfc and mdm BUT mdm does get removed later on during the process. It keeps respawning. So it isn't necessarily MDM as much as it is trying to be so I presume that there is some detail in the MDM program that helps it get what it needs.


The shared cache you are seeing is at best guess, all of the info it has collected on you and will keep looping together. This is just a guess but I have been watching it on mine as well. I could 100 percent be wrong but I believe the cache is what keeps this process communicating between devices.


There are enough of us out there with this problem. I am sure that we have a common thread but I have no idea what it could be. I just know that no one is going to help me or my family and I am just going to have to do my best to keep my kids safe.


I could bring a new computer into this house and within ten minutes watch it try to harvest my old apple ids, while Bluetooth sniffing and try to connect to something nonstop. Eventually, it gets back in and the new id becomes corrupt, I delete it and start again hoping the last apple update resolved this issue. Two years later and I am headed back to the Apple Store today to pick up a couple of devices.


I wish someone had better news for the both of us but this is the best advice I can give you.

Similar questions

160 replies

Jul 25, 2023 2:57 PM in response to GSS_544

Check out “hidden apps” I didn’t know you could hide them! I’ve also seen GitHub and Python (likely the hacked version). Many purchased and “free”‘apps were downloaded. And there is one that provides SSH and other programming capabilities (it’s not the dictionary). I was surprised seeing SSH under Apple Shortcuts used to hack my network using port 22. The network is disconnected, so now (or before?) I have a somewhat hidden managed hotspot with no ability to remove it. I can’t use it, it connects to me. I have a Wi-Fi detector, it’s going off as we speak. It connects via Wi-Fi then connects to multiple devices using Bluetooth. And even if you think you have cut Wi-Fi or Bluetooth, it’s still running. Also, look under shortcuts (don’t run anything as they often reference more dangerous things but the source code is on the web). But previously used scripts, such as SSH will show, I’ll include the pic if the computer God or Devil will permit. There is also a scanning list that shows up sometimes. If I can locate it I’ll post as well. The MDM can compromise just about anything, I tried Android as well.

Feb 21, 2024 8:45 AM in response to Katefromouterspace

You might want to run a System-diagnostic check on your device. If you google “how to do sys-diagnostic test on iPhone with touch assis.” It catches “leaks” on some of the processes running and you’ll see it’s easy to do and well worth what you’ll find running on your device. This can help you decide what kind of services you’ll want to look for. You could be right that part of the security intrusion has to do with your location. This diagnostic check revealed an unbelievable amount of security breaches and surveillance activity. A stingray device collecting and filtering all my communications. I would be interested to see what others find hidden in their devices and networks with this check.


May 14, 2023 7:30 AM in response to AgentDragonfly

I would imagine if you went to the apple beta website and tried to sign in, you would find you have an account... check all of your id's. If you have a family of devices, check all of the id's. Experiencing the same problems and have been trying to get Apples help but they just keep resetting. I have been seeing DTD plists for over two years, plists to processing like sharing and safari that I have zero control over. I removed my ID from the beta site and miraculously, the next day, was logged back in. It resets itself so check and check again. If you delete your Apple ID, it may revive itself as well so take note of the code apple provides for deleting your account so when it does revive, you can call.



May 14, 2023 2:24 PM in response to AgentDragonfly

Same thing is happening to me. While I was in the hospital, a mini 2 was stolen. I kept old ones for fear of data compromise, now, everything is compromised. Tried reformatting, buying new, paid professions, Apple support. Just deleted account with special permissions, but before I received notification (email likely deleted), 2 devices rebooted and had been reformatted. Apple Configurator (MDM) showed up in purchases (although it’s free) tried to delete, no luck.


Once this is on one device, it spreads to everything, Windows, Android, and it can control other devices, like IoT. Many devices destroyed.


I downloaded it on one device, tried to execute, and it said @administrator permission is required”. When I touched the icon, it had an option to hide the application. Several other apps were purchased and hidden. Apple has a page where you can see these apps, but only a few months back.


but I’ve tried everything to show app icons on desktop (I found about 6 ways), nothing works. The NDM is supposed to be “vetted” by Apple, with a fully qualified domain name. But I found a site that will provide this for scammers. Family sharing is enabled to allow it to spread. Location services is always turned on, after my home alarm was compromised, they entered my home and left 15 minutes before I returned per alarm log. Apple developed it, so contacting developer does not help.


This has enabled fraud, theft, identity theft, stalking, lost accounts, lost $20k+ in damaged equipment (old and new). The MDM creates a “geofence” which is the area around your home, when a new device is discovered, it adds the MDM. I can’t see Apple files, but on Windows, it shows over 1,000 files! If you have a Windows device that still works, go to file explorer, search on *mdm*.*, and for root, search on %mdm%. It transfers data on a regular basis, I think using telemetry. Also, look under windows update schedules, you will see the transmission data there.


I would think the first install has to get physical access, but I’m not certain. But after the first one, it’s all over. They have complete control. Other devices impacted included my Roku, router, and home Alarm system. Any IoT device could be impacted as many have no security, it trusts anything inside the network.


All attempts to get help have been blocked, email, online forms blocked, phones compromised using “assessibilty” options which permits using your phone number for password resets!


Also, look at shortcuts, I had 87 in mine, plus in the same area, recorded chats, web sites and more. Don’t attempt to execute any. I hope Apple fixes this major flaw, look in App Store for Apple Configurator, it clearly states this app is vetted before allowing installation! If you find anything, like how to unhide device, or delete, let me know. But it’s designed not to allow an uninstall. When I changed my account name, and reformatted everything, back to factory, it was gone for a few hours, but quickly returned, even with network unplugged.


My guess would be it’s someone you know. It’s fairly easy to copy a phone or iPad within minutes. The first device is reformatted to “transfer to new owner”, then placed beside your device. Once you do that, it all ask if you want to transfer data to the “new device”. If they know the PIN, they enter that number and it only takes minutes. If you have saved passwords, they are in clear text.


Good luck! Check out your purchase history. I understand Apple keeps data for 3 years, and it includes the actual IP. A subpoena is needed to get that data. Once you identify the hacker, you could get a restraining order. But they are expensive. I found a DIY subpoena, but I don’t feel confident with my disabilities standing before a judge. And another warning, it has “beacons” that advertise your address and back door. Now it appears other hackers are getting in. Even with network unplugged. This part I don’t understand (on other devices), uss they use cell phone data or are parked at driveway.

May 25, 2023 7:58 AM in response to Community User

Question, can you see JavaScript and Xcode on a Mac? The MDM spread to Windows with the fraudulent remote access apps, I could see that, but permissions are changed always, MDM on, parental controls on. Another question, I unplugged my router 8 weeks ago, but they are still accessing devices, I’ve seen ppl parked at end of driveway a couple of times when several devices were active but not every time. I’ve seen a lot of data transfers on Roku )not to movie or Roku). I did a scan for active BT, one Roku showed up (I’ve seen many users on there as well), and data transfers from the former Alarm. Idk if Roku is connecting to neighbor? Lots of settings and downloads are put in iCloud with synch to all, but a user can’t do that, unless it’s a MAC option. I’ve had tons of scripts, not always visible on iPad (unless under shortcuts), but visible on a Windows PC (although 7 PCs are compromised). I know the MDM will have to be blocked before entering my house!

May 30, 2023 1:27 PM in response to T3ddy19

Have you checked on apple beta to see if your user name is there? I have to keep unenrolling mine. There are no other signs that I am in the beta program . Apparently, if you are enrolled, the " developers" have permission to do whatever they want with your devices. Also check your cell service beta programs as well as any other accounts... for instance my sons Xbox has beta rights. To confirm, we didn't authorize it nor can we find emails acknowledging it but it is worth looking into.

MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.