How do I stop a hacker from using acronyms and automations to label my files on my computer?

SSeriously, I have a hacker who is using acronymic letters to label certain things and files of posts and letters that I write and threatens DC with these letters. S/he has gone into the software of the computer and creates automations of files and labelings. It's like a bug in the predictability of words and file names. Another way for communicating with multiple persons reading an open thingy... or doc or words or file...


[Edited by Moderator]

Original Title: Questions on hackings

MacBook Air, macOS 26.6

Posted on Sep 2, 2026 10:18 PM

Reply
Question marked as Top-ranking reply

Posted on Sep 3, 2026 12:28 PM

69 replies

Sep 3, 2026 12:38 PM in response to bbyt

bbyt wrote:
Well, this requires me to post more screen shots of what was written and what was happening, that of lagged time and not what was happening exactly frame by frame during that exact moment.

None of which is going to get resolved around here.


Civil and criminal matters are for lawyers and police and courts.


Issues with or concerns about Write.as are for Write.as developers.


If you want to discuss macOS security, tell us first all of what you have done to address a reported compromise. This remediation would typically involve a complete reinstallation with no restore, new passwords and passcodes and passkeys everywhere, a Safety Check, and such. All of it. This for all gear Apple and otherwise, too.


And if after a complete reset, the Mac is then re-compromised, you’re past the sort of help that can be offered in this and other forums I’m aware of. Not without direct and personal discussions of your own personal risks, and your own personal requirements and exposures, and usually also with forensic access into your re-compromised Mac, and quite possibly also an examination of your local physical environment for related compromises. Cameras or trackers or alarm systems or networking hardware or whatnot. Which is all deeply personal, sensitive, very involved, and not appropriate for posting. Potentially all quite an expensive review, too.

Sep 3, 2026 1:20 AM in response to bbyt

The screenshot shows a macOS Save As window for a Write.as document. 


The filename displayed is “Editing 7t9s43yv8fq5b — Write.as”, with Downloads selected and HTML text (.html) as the format. 


The document also contains the labels #NSA, #CIA, #DC, and #DOD.


The screenshot alone does not show how those filename characters or labels were produced, or whether they are connected. 


It therefore is not enough to determine what process or person, if any, is responsible.


For a practical check of the Mac, EtreCheckPro would be useful because it can provide an overview of the hardware, operating system, installed software, startup items, background processes, and other configuration information. 


It should be treated as diagnostic information, not as proof that unauthorized access has occurred.


I would run EtreCheckPro and avoid deleting or changing anything it flags until the results have been reviewed. Apple's System Report can provide additional hardware and software information, and Login Items & Extensions can be checked for items that open automatically or run in the backgr


If you are investigating unexpected changes on the Mac, Apple provides Login Items & Extensions under System Settings >> General, where you can review items that open automatically and apps permitted to run in the background. (Apple Support


Apple also documents how macOS controls applications' access to files and its Automation permissions. (Apple Support)


Apple: Login Items & Extensions


Apple: Controlling app access to files in macOS


Apple: Shortcuts privacy settings on Mac

Sep 3, 2026 9:08 AM in response to bbyt

Are you looking for assistance and support for the Write.as tools and website, potentially including security questions? It appears that service has a forum at https://discuss.write.as/latest, and it further appears someone has already posted a similar “acronymic hacker” question over there: https://discuss.write.as/t/acronymic-hacker-labeled-my-writing-posts-and-is-potentially-even-threatening-dc/20934


Write.as can be tied into the Fediverse social network, which means there can potentially be all sorts of replies. Replies which can include #hashtags, whether algorithmic, and otherwise. This if whatever you are writing is set to be published, and which appears possible here. And there are many bots active in the Fediverse.


Based on that forum posting and what’s been posted here in this thread, this issue looks unrelated to macOS, though.


Given the sexual abuse allegations and geolocation allegations referenced over in the forum posting, this would seem to be a legal matter, or possibly proximate to one.


As for somebody creating macOS automations, hashtags either from What.as itself or from Fediverse replies seems more likely than somebody creating macOS automations. Or maybe problems with macOS autocorrupt. The Apple autocorrect and autocomplete mechanisms have been a flaming mess (for me) lately, and I’ve shut off parts of that locally.

Sep 2, 2026 10:21 PM in response to bbyt

Hi - I can see this has been really stressful for you, and I'm sorry you're dealing with it. :(


If you're worried about actual account security:


  1. Change your Apple ID password: Settings → [your name] → Sign-In & Security → Change Password.
  2. Turn on Two-Factor Authentication if it isn't already on.
  3. Check Settings → [your name] → Sign-In & Security → "Devices" to see exactly which devices are signed into your Apple ID, and remove any you don't recognize.
  4. Check System Settings → General → Login Items & Extensions for anything unfamiliar running in the background.


On the blog posts and file names: those look like normal system-generated names (like "7t9s43yv8fq5b") that apps such as Write.as create automatically when you start a new draft - they're not secret codes or messages from someone else, just random IDs the software assigns.


Hope this helps. :)

Sep 4, 2026 10:06 AM in response to weeklycod

weeklycod wrote:
Everything is alright as per the Etrecheck app. Then what did the author install?

FYI, the EtreCheck posted may not be complete. However, as @MrHoffman was written in the following post earlier in this thread:

@MrHoffman's analysis - Apple Community


The OP appears to be only having issues while using the "write.as" website which apparently can be linked with some social media sites (seems like a huge issue to me, but I also have no idea what this "write.as" website is or does). It appears to be a "write.as" website issue and/or usage issue with that web site. I'm thinking the OP is utilizing the wrong tools here and/or does not understand how that website works. Sounds like the simplest fix is to not use that particular website.


Otherwise as @MrHoffman has mentioned, the OP won't be able to get much assistance on this forum (or any other) so I would highly recommend the OP hires a local professional security specialist consultant to help them through these issues & their security concerns. Once the OP has resolved their security concerns, getting assistance from a local macOS specialist may also be useful to better understand how to utilize & configure their Mac. Some things just needs a physical hands on approach. The OP has too much going on here that cannot be solved remotely via the forums.

Sep 3, 2026 12:56 PM in response to bbyt

bbyt wrote:
This is just to inform Apple…

"Apple" is not here. This is a user forum. If you want to inform Apple, you can use the product feedback link or contact Apple Support.


Feedback - macOS - Apple


Official Apple Support


Regarding EtreCheck, snippets are not helpful. Post the full report using the Additional Text button. No personal information is revealed. 



For the most part, this exercise should just serve to inform Apple of how things could get into its apps.

Nothing is 'getting into Apple's apps', macOS and most of the native apps are installed on a sealed, read-only volume on your Mac that only macOS can write to.


Meanwhile, as you head to school you can just say out loud, "Hey Mr. Ternus," and proceed to verbally describe your issues. That will 'inform Apple' just as effectively as posting those issues here. Think about that for a moment, if necessary.

Sep 4, 2026 5:50 AM in response to bbyt

See, just with a blank screen we cannot do anything. Go and click the share button in the app etrecheck after the report is created. Copy the report and paste it in additional text option in reply.

Do all these in safe mode.

Do one more thing too: go to settings and privacy and security and go to accessibility (this setting allows the application to run the computer without the users' interference. ) Deselect all the options, then go to general. Login extension, then deselect all the apps starting. This might stop the application which is creating this fuss

Sep 3, 2026 9:23 AM in response to bbyt

The Background Etrecheck Application 


At one time there was an  Etrecheck Application available on the Apple Apps Store.


Due to certain constrains place upon the Developer by APPLE, the developer chose to remove it from the Store and make is available Directly from them.


This specific application is well known,  on these Forums,  as a Go To for trouble shooting and avoiding a game of 20 questions.


It is also known and reported by Reliable Sources that,  sometimes APPLE SUPPORT has invoked using this same Developer Distributed Version of Etrecheck application to trouble shot computer issues 


Lastly - should you decide to use and post the Report now or at a later time, someone may or may not be willing to have a very close look and offer some insights 

Sep 3, 2026 9:51 AM in response to bbyt

bbyt wrote:
Yeah, I've already tried to talk to the police about the matter. I've even submitted evidence. They've been very quiet, and haven't responded back to me. Even though it's been years.

IT security issues ongoing for years are not going to get resolved around here, or in most any other forum.


Getting profoundly new suggestions — suggestions you have not previously received and considered and implemented as appropriate — is exceedingly unlikely.


Issues including allegations of crimes are not going to get resolved around here.


Whatever is happening here is not clear from what was posted, either. What was meant by “acronymic hacker” and “acronymic letters to label certain things and files of posts and letters” and such” — if not strings generated for content tracking or related uniqueness, or social media #hashtags — is also unclear.

Sep 3, 2026 1:27 PM in response to bbyt

With no disrespect toward the EtreCheck app intended, the chances of malware showing up in a report is somewhere between slim and none.


Same for backdoors.


Adware and browser hijacks and related junk, sure. That’ll often show in a report.


Exploits and remote access showing in a report? Not so likely.


EtreCheck just isn’t meant to look for exploits, or for these reported “acronymic” hacker artifacts.


Artifacts which look like #hashtags from Write.as or hashtags in replies from the Fediverse social network.

Sep 4, 2026 10:58 AM in response to weeklycod

weeklycod wrote:
Everything is alright as per the Etrecheck app. Then what did the author install?

That would be exactly the question here, yes.


If anything was installed here.


The early part of this thread was seemingly involving a browser-based writing and social-media app.


Tooling that all runs out of a web browser, without installing apps locally.


And again, whatever EtreCheck might find here would be limited, at best. Assuming there is anything installed here. (This intending absolutely no shade toward EtreCheck too, as detecting malware simply isn’t its focus. It is a configuration and software inventory tool, and most malware would probably prefer to avoid being included in one of the most commonly-used inventory tools.) And backdoors are a whole ‘nother discussion. Are all the login accounts real, or did something add one?


I am aware of folks targeted by mercenary tooling too, but those cases are rare based on available reporting, and they’re (still) not going to get resolved around here. And in this case, it’s unclear to me whether this “acronymic” issue involves any exploits or compromises or backdoors. Or behaviors of the website, and of other people and other bots potentially reading and responding via its available social media linkages.

How do I stop a hacker from using acronyms and automations to label my files on my computer?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.