Ransomware Kalunga Russia iCloud Hack

My iCloud account was hacked by source supposedly from Kalunga Russia. My MacBook Pro and iMac desktop both show a lockout screen on start up and ask for a four digit PIN on my MacBook and a six digit PIN on my iMac Desktop. It says to email apple.device@gmx.com


There are reported fixes on REDDIT stating that resetting the PRAM / NVRAM by rebooting three times with the OPTION COMMAND P R keyboard combination will unlock the computer. I tried this and it does to work.


macosx - MacOS Ransomware with EFI Lock - Information Security Stack Exchange


Obviously someone has figured out how to hack into iCloud accounts bypassing two factor identification. This is a serious problem and Apple seems to be ignoring it as there is no information form Apple as to how to fix the problem or prevent icon accounts from being hacked. I assume Apple does not want to admit to security weaknesses.


If anyone has any information about this please post.


Message was edited by: mirvine1

MacBook, Mac OS X (10.5.4), MacBook / Powerbok G4 / iBook / iMac G3's / Airport Express / As

Posted on Aug 5, 2017 8:12 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 20, 2017 7:26 AM

It's a firmware lock..Apple will not provide a solution. Due to the fact that it is suppost to work like this. They can't get to your data. The only thing is you can't either due to the firmware lock.


The only thing you can do is bring the original reciept and go to an Apple store. They will get a new firmware code and this will unlock your device.

53 replies

Aug 11, 2017 8:03 AM in response to mirvine1

if you are using the same user pass for your Apple ID as you are using for any other service and that service gets hacked then you gave a hacker an opportunity to simply try those same credentials at Apple.


If you arrange with Apple beforehand an Apple Store may be able to remove the firmware lock. It's possible that the data is still available to you, if not hopefully you have a backup.

1-800-MY-APPLE

apple.com/contact

Aug 11, 2017 8:48 AM in response to Winston Churchill

As I stated in my original post. I received a message from Apple stating that someone was trying to access my iCloud from Kalunga Russia. I denied that access. i did not receive any two factor ID request at that time. Immediately after that my Laptop went into lockout mode. I was able to access my iCloud form another computer at a different location and my laptop and desktop, which was never turned on during this episode, were both listed in iCloud as locked out. I changed my password immediately but my laptop and desktop remain locked out even though they no longer show as locked on iCloud. I use different id's and passwords for every online account I have.


.

Aug 12, 2017 11:19 AM in response to mirvine1

So it was a hack as I do not give out this information.


But yet they had it. Call it what you want. Use whatever phrase makes you happy.


This locking of your device can't happen without your Apple ID *AND* current password.


but how did they do this unless they hacked my MacBook or iCloud, the only two places I store this information ?

You are not locked out of your iCloud account are you? Why hack it and not take it over?

Aug 13, 2017 10:23 AM in response to LACAllen

No you miss understand what I'm getting at. What my point is as long as you still have the password to Apple ID you can just log into iCloud.com and turn off 'Lost Mode'. You don't need the passcode created with 'Lost Mode'. It stated in the article that was linked.

Aug 13, 2017 6:14 PM in response to Miamoo0110

What happens when you enter your known passcode on the device itself?


If you have removed the passcode via iTunes, you may have removed the only way to resolve this. Now you must know your Apple ID and password, but not until your device is online.


until my phone connects to the internet-which i cannot do because my phone is locked-any assistance anyone can offer?

This should not prevent your phone from using cellular data or connecting to a previous wifi network. Is the SIM card not in it?


What can't you sign in to iCloud.com with your Apple ID and password?

Aug 15, 2017 8:17 AM in response to mirvine1

Same thing happened at my office. We saw someone trying to remote in from kalunga russia on a co-workers laptop while in a meeting and she hit deny access. her computer immediately restarted and the locked page showed up on both her computer and phone. she had 2step activated and it was the only place she used the password. she has never given her password to anyone because she has Icloud password login enabled. watching it happen i have to agree and say somehow hackers found a vulnerability very recently because while researching this most of the kalunga hacks started in July.

Aug 16, 2017 5:43 AM in response to lilacien

lilacien wrote:


Well time will tell as more people "suddenly" don't know how to protect their devices.

Sorry, that's just more nonsense.


If you set a strong password, don't use it for anything else and don't disclose it, you are really pretty much secure.


However, having done so, if you want to protect against the unlikely scenario of someone being able to guess your password and lock your device, just ensure you've already set a lock, so the lock that gets applied to your device is one you already know. Admittedly setting a firmware lock on a Mac is a little more complicated than setting a screen-lock on a phone, but it still only takes a few minutes.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Ransomware Kalunga Russia iCloud Hack

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.