Ransomware Kalunga Russia iCloud Hack

My iCloud account was hacked by source supposedly from Kalunga Russia. My MacBook Pro and iMac desktop both show a lockout screen on start up and ask for a four digit PIN on my MacBook and a six digit PIN on my iMac Desktop. It says to email apple.device@gmx.com


There are reported fixes on REDDIT stating that resetting the PRAM / NVRAM by rebooting three times with the OPTION COMMAND P R keyboard combination will unlock the computer. I tried this and it does to work.


macosx - MacOS Ransomware with EFI Lock - Information Security Stack Exchange


Obviously someone has figured out how to hack into iCloud accounts bypassing two factor identification. This is a serious problem and Apple seems to be ignoring it as there is no information form Apple as to how to fix the problem or prevent icon accounts from being hacked. I assume Apple does not want to admit to security weaknesses.


If anyone has any information about this please post.


Message was edited by: mirvine1

MacBook, Mac OS X (10.5.4), MacBook / Powerbok G4 / iBook / iMac G3's / Airport Express / As

Posted on Aug 5, 2017 8:12 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 20, 2017 7:26 AM

It's a firmware lock..Apple will not provide a solution. Due to the fact that it is suppost to work like this. They can't get to your data. The only thing is you can't either due to the firmware lock.


The only thing you can do is bring the original reciept and go to an Apple store. They will get a new firmware code and this will unlock your device.

53 replies
Question marked as Top-ranking reply

Sep 20, 2017 7:26 AM in response to Ammmpt

It's a firmware lock..Apple will not provide a solution. Due to the fact that it is suppost to work like this. They can't get to your data. The only thing is you can't either due to the firmware lock.


The only thing you can do is bring the original reciept and go to an Apple store. They will get a new firmware code and this will unlock your device.

Sep 21, 2017 6:21 PM in response to asdfasfwefwef

I find it very improbable that the hackers "guessed" my password or phished it from me... this has to be either an Apple authentication weakness or they somehow are intercepting login details from the official Apple sites/server.


But yet that is the only way this could have happened to you.


They *had* your Apple ID AND password. Signing in to iCloud.com, as described by be earlier in this conversation, with screenshots, on a 2FA enabled Apple ID allows one to bypass the verification code filed and get to Find My device. There, you can place a firmware lock on a Mac, or enable Lost Mode on an iOS device.


I find it importable that you are the first victim of an Apple account server hack as you suggest. I would think a hack of Apple IDs and passwords, a la Equifax, Yahoo etc. would have been in the papers.


The prevention of this is to not enable Find My Mac if you don't also have a firmware password in place. If there is one present, this "hack" can't be utilized.

Sep 21, 2017 2:23 PM in response to mirvine1

Same happened to me. Received a notification on my iPad that someone from Kaluga, Russia was attempting to access my iCloud and I hit "deny"... A few minutes after that my iMac powered down and came up with a lock screen asking for a 6 digit PIN, and displaying an official-looking but fake email address to contact. I had two-factor authentication enabled, that's how I knew the attempt took place from Kaluga, Russia because the two-factor authentication popup on my iPad showed it to me on a map and I pushed "deny" but they have evidently found a way past it. I created this iCloud account just a couple weeks ago, used a secure password with random letters and numbers, and have not entered my iCloud password anywhere except the official Apple website and in iTunes and on my iPad. I find it very improbable that the hackers "guessed" my password or phished it from me... this has to be either an Apple authentication weakness or they somehow are intercepting login details from the official Apple sites/server.

Sep 13, 2017 12:40 PM in response to mirvine1

This exact thing has happened to me as well on my Mac at home. I also have the 2 Factor authentication. I have been on the phone with Apple technical support multiple times. They have turned it over to their engineering department as highest priority, as it does seem to be a new hack through iCloud. There is no longer a button in my iCloud to unlock or do anything to my Mac other than play a sound to locate or remove from account.

Sep 21, 2017 2:20 PM in response to mirvine1

Same happened to me. Received a notification on my iPad that someone from Kaluga, Russia was attempting to access my iCloud and I hit "deny"... A few minutes after that my iMac powered down and came up with a lock screen asking for a 6 digit PIN, and displaying an official-looking but fake email address to contact. I had two-factor authentication enabled, that's how I knew the attempt took place from Kaluga, Russia because the two-factor authentication popup on my iPad showed it to me on a map and I pushed "deny" but they have evidently found a way past it. I created this iCloud account just a couple weeks ago, used a secure password with random letters and numbers, and have not entered my iCloud password anywhere except the official Apple website and in iTunes and on my iPad. I find it very improbable that the hackers "guessed" my password or phished it from me... this has to be either an Apple authentication weakness or they somehow are intercepting login details from iTunes/iCloud or the Apple website.

Sep 22, 2017 2:51 PM in response to mirvine1

I just experienced the same thing with my husbands iPhone. My daughter was on her iPad which is on the same account as my husbands and it popped up someone in Russia was trying to use it and he pushed not allowed. Then his phone was put into lost mode along with my other daughters iPad with a passcode. It was weird that the iPad my daughter was on wasn't put into lost mode. All 3 devices are on the same account. We couldn't get into his iCloud at first the password was changed then after we finally did and turned off lost mode and had to erase it to get the passcode off. After we did that to the phone the passcode disappeared on the iPad without erasing it. Then we went to restore the phone after we did we noticed everything was gone from his iCloud. They erased it and all the backups were gone and there is nothing on his iTunes. I was not happy when I came home to find out it happened and he emailed the people that did it from my computer. I hope there is nothing on it and he used an my e-mail that I only use for a few specific important things. So I didn't pay attention to who sent the e-mail to me and opened it on my phone.

Oct 4, 2017 2:05 PM in response to mirvine1

Something similar happened to me October 2. My iphone alarm to wake me up didn't go off so I checked my iphone and the first display on the screen was that it was put into lost mode. The message said to contact an email, which was made to look like an Apple email but it wasn't, it ended with @post.com. I cancelled that and entered my iphone PIN and then a notification screen appeared requesting access to my Apple ID/icloud account for use in Russia (not where i was). I clicked don't allow. I use two factor authentication for account security. I also had 2 emails from FMiP saying my iphone was put into lost mode and then it was found, both sent at the same time stamp after i was sleeping. I had 1 email saying my Apple ID was used to sign into icloud via a web browser, same time stamp as the 2 FMiP emails.



I contacted Apple today to verify account security and they said my account was not breached and was secure. I'm calling BS on that as my iphone was put into lost mode and email was sent saying my icloud was accessed after i was sleeping.


How was that possible since I had 2 factor authentication enabled?

Aug 5, 2017 12:44 PM in response to mirvine1

If this happened to you, they knew both your Apple ID and password. No other way for it to happen. It is/was not a hack of iCloud.


If you go to icloud.com and use your Apple ID AND your current password for a 2FA enabled account, the prompt for the verification code will pop up. You will also see an icon for Find My Device, which can be used without the verification code.


This allows users to place their devices in Lost Mode or for a Mac, add a firmware password, without the verification code. Just click the Find My ... icon.


User uploaded file


This is not a hack. You can't do this without the password.



This is a firmware password that was placed on your Macs. You should have received an email when it happened and your Macs rebooted spontaneously.


User uploaded file

There is no workaround. You must present your Macs at an AASP or ARS with your proof of ownership and they will unlock them.

User uploaded file


Use a firmware password on your Mac - Apple Support


There are reported fixes on REDDIT stating that resetting the PRAM / NVRAM by rebooting three times with the OPTION COMMAND P R keyboard combination will unlock the computer. I tried this and it does to work.

Not any more. In previous, less secure versions of OSX, this was possible.

Aug 12, 2017 3:46 AM in response to Winston Churchill

I had the exact same hack done to me last night. Same thing, saw a weird trying to access my iCloud. Say don't allow, reset my password, didn't think anything else of it. In the morning my work iMac was locked, @GMX email address there. And my older laptop was also locked. (Going to try the PR Ram reset as it's a older laptop (2009)). Took my work iMac into apple care to get unlocked.


I've since set up 2FA, it wasn't set up last night, but I don't use my iCloud password on any other devices and I'm pretty vigilant for phishing scams.


This is happening to other people right now as well.


Locked Macbook and Hacked appleID

Aug 13, 2017 9:50 AM in response to LACAllen

To expand on this answer. What @LACAllen is trying to get across is with only your password someone can login into iCloud.com website and turn on 'Lost Mode'. You can turn it off as long as you still have the correct password. To see how to turn it off look at Find My iPhone: Use Lost Mode see 'Turn off Lost Mode...'.



On another note please see If you think your Apple ID has been compromised - Apple Support as it states 'Your device was locked or placed in Lost Mode by someone other than you.'

Aug 11, 2017 7:03 AM in response to Winston Churchill

Sorry but you are wrong. I have two factor ID enabled. They hackers were able to access my iCloud and bypass the two factor ID process, i.e. I did not reply to a six digit code being sent to my iPhone.


Furthermore the only way they could have iCloud user name and password was to have hacked my Macbook iCloud while I was on the internet and fished it out of my Contacts. I have never downloaded anything from bit torrent.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Ransomware Kalunga Russia iCloud Hack

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.