Persistent Ramsomware attack

I Believe Im being victm of ramsoware attack, all my devices, mobile, MacBook, and even VM on cloud are with much suspicious logs



MacBook Pro 14″, macOS 14.0

Posted on Aug 17, 2023 4:35 PM

Reply
6 replies

Aug 17, 2023 4:58 PM in response to OSSHatred

Theres something more weird, ive never installed Chrome, but have an com.apple.passwordmanager pointing to a google Chrome folder.

{

"name": "com.apple.passwordmanager",

"description": "PasswordManagerBrowserExtensionHelper",

"path": "/System/Cryptexes/App/System/Library/CoreServices/PasswordManagerBrowserExtensionHelper.app/Contents/MacOS/PasswordManagerBrowserExtensionHelper",

"type": "stdio",

"allowed_origins": [

"chrome-extension://pejdijmoenmkgeppbflobdenhhabjlaj/",

"chrome-extension://mfbcdcnpokpoajjciilocoachedjkima/"

]

And a los of attemptions to Lock or log in my Mac.


Aug 17, 2023 6:20 PM in response to OSSHatred

Reading system logs without a specific target in mind is the path to Madness.


There is so much junk in there, you could use those logs to prove ANYTHING, and also the prove the reverse of the previous assertion.


if you have Gross symptoms, please tell us about your symptoms.


MacOS now uses a separate locked, signed system volume that is un-writeable and crypto-locked. Any changes to it are detected within seconds. it is extremely difficult to hack. Applications are all signed and sand-boxed when they execute.


There is no threat from ordinary hackers, Unless you are an international activist, or major political figure. If you are, Nation-state level attacks cannot be ruled out.



Persistent Ramsomware attack

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.