Support needed to certify, unbelievably, of possible exploit of mighty iOS. (Im the lucky loser, possibly)

This is an addended post referring to me getting bounced from Bank of America and account shut down and forced to firmware wipe etc my devices due to ‘account takeover’ from ‘malware’ as their crowdstrike or whatever prob read api or ip irregularity? They wouldn’t say, bye this happened to 4 other similar accounts in 6 months. I don’t use proxy or remote etc but the log below apparently reveals some kind of strange activity- I’m not smart enough to put it all together, much appreciated folks!!!

terminusd-471.140.5 pid 674 built on Jun 29 2024 06:58:06, iphoneOS 21G80 "iPhone", packet logging disabled Companion link is currently enabled on this device 23:35:36.2420 : time of this status dump --------- NRD Local Device Database Status (0 devices) --------- --------- Director status --------- Name: Link Director Enabled: YES Fixed Interface mode: NO Thermal watcher registered: NO Thermal Pressure: Nominal SOCKS port: 62742 SOCKS server: (null) FD Usage: { NETPOLICY = 2; Total = 6; VNODE = 4; } Unlocked data protection: ClassA --------- Manager status --------- Name: Policy Session Manager Policy Session: { priority = control1 policies = {} } Installed policies: { "NRLinkDirector-Drop" = ( 1 ); } Name: Link Manager - Bluetooth LinkManager type: Bluetooth State: Ready [] Links: {( )} Pipes: {( )}

Peripherals: (null) connectPeripheral invoked: (null) CentralMgr: (null) PeripheralMgr: (null) currentAdvertisementState: Idle currentAdvertisementRate: Default BT connection state: (null) Name: Link Manager - WiFi LinkManager type: WiFi State: Ready Links: {( )} WiFi Interface: en0 (index 22) AWDL Interface: (null) (index 0) WiFi Available: NO WiFi WoW Enabled: NO WiFi Client Type: 0 Local WiFi Endpoint: (null) Local WiFi Signature: (null) Remote WiFi Endpoints: { } Remote WiFi Signature: (null) Remote AWDL EndpointDict: { } Available IPv4 addresses: ( ) Available IPv6 addresses: ( ) Available AWDL addresses: ( ) Prefer WiFi asserts: 0 Cleared Prefer WiFi asserts: 0 ---- NRIKEv2Listener ---- IKEv2 Listener: (null) Registered links: (null) Orphaned Device Monitor Connections: {( )} Orphaned Device Preferences Connections: {(

)} Ephemeral Device Connections: {( Sent from my iPhone

Answered by endecotp in 801356022

the log below apparently reveals some kind of strange activity

What makes you believe that?

I don't know what the log means, but I have a suspicion that this is some sort of scam where you are contacted by a fake "technical support" person who says "look in blah blah blah, does it say 'fjnjurhtghj', if it does your device is hacked". Then you worry, and they say "don't worry, the hackers have got your Bank of Foo password, but if you quickly transfer all your money to Bank of Scam then they won't be able to steal it. Look, I've made an account for you, just click here and ignore all the warnings".

Do you understand what I'm saying? Back to the original question, what makes you believe there is something wrong in that log file?

Accepted Answer

the log below apparently reveals some kind of strange activity

What makes you believe that?

I don't know what the log means, but I have a suspicion that this is some sort of scam where you are contacted by a fake "technical support" person who says "look in blah blah blah, does it say 'fjnjurhtghj', if it does your device is hacked". Then you worry, and they say "don't worry, the hackers have got your Bank of Foo password, but if you quickly transfer all your money to Bank of Scam then they won't be able to steal it. Look, I've made an account for you, just click here and ignore all the warnings".

Do you understand what I'm saying? Back to the original question, what makes you believe there is something wrong in that log file?

Sorry to be blunt, OP, but neither of your posts have anything to do with us here on the Developer Forums.

We're just developers writing apps. We aren't Apple employees. These forums are not the place for posts like yours.

If you have some concerns about your device, wipe it and start from scratch. Don't restore from a backup unless doing so would mean you lose something you really don't want to lose.

Importantly, read what @endecotp wrote. It's highly likely that you're being scammed, so don't speak to anyone who calls you or messages you saying your device is hacked etc. It's a load of nonsense.

Hey thanks for responding!!! of all the log files I have those are not the most concerning (Although I know my place well enough not to make any kind of meaningful Inferences or speculation unless you’re a developer, in which case, golf clap for you……. I actually did lose my bank account, someone tried to open in my name. I found a Keylogger on my iPhone permissioned and attached to my AURA app- its a developer keyboard, and It’s just sitting there one hop from settings/aura and it’s 3 permissions- location, local network, then something called ’kids’. I’ve never seen a keyboard attached to any app before and figured that was cute of the company, they are giving kids the chance to appreciate and learn digital hygeine and identity management at early age. But a click further asks full access and iOS bubble alerting this Developer keyboard can store your data and Stores any information inputted into keyboard. hmm. ive had it out with aura, no joke a kind of juiced up lifelock, monitoring and storing, laughingly, bank and credit account and routing info, SS, passport #, DL, credit bureau info, property and titling info, and the same thing keeps happening that happened with the bank- a personal emaI I lost admin access to despite passing 2+3 factor, my passport, my selfie- someone else’s number then appeared in the recovery options and i failed identity verification to re acct 4 times in a row- kept showing up as my primary anchor for alerts and even overtook my cell phone in priority/privelege DESPITE repeatedly having To go into a BOA branch with 2 forms of identification in order to remove it due to fraud on account/suspicion. It reappeared 4 times with BOA after I kept going in and telling them this story, wash rinse repeat with Amazon.com, Gmail, and just today Venmo and bitdefender are telling me new email AND new devices wholly different in user agent and brand and device type (freebsd On desktop with a modem/ethernet link, while I’m not only on iPhone 15 but my device is linked direclty to these apps and accounts and Ive seen in each one’s logins them correctly identify my user agent and tls fingerprint before. Then either another device logs in a minute or 2, always after me, showing different signature, but what’s galling is their API reader or whatever after correctly reading me right for 50 logins suddenly forgets my device is registered in that app with a nickname attached and now getting alerts new and unknown device attempting login followed a min later. worse, today, no joke produced a darkweb hit of my gateway IP for air with att and it leaked a month ago from a site called mspy which is de-facto stalkerware and spyware. My iPhone continues to dent my password askint for the password to my other iPhone. Hidden profiles/ after last firmware reboot I got blocked from login to my Apple ID with the error either my Apple ID or my device is managed and I have restrictions. dunno Akamai peering shows up in trace, my ports 21,22,1723, 8443 are open reading only my devices on my cellular network. I’m won’t get into my work and so forth but anyone who’s very high in corporate cyber has told me they believe originated with cloud and key_sync something and I have all the indications of an enterprise Managed device/profile. I trust Apple would defeat most any malware or virus- whatever happened to me seems low tech and crude but I was so tech ignorant up until literally the last month or two it’s shameful to share how bad my hygiene was. I was oblivious to this entire universe for 40 years and happy that way. This came out of nowhere with an initial DOS router and brute force hack ID’d and explained like a child to me what this log insicates etc. escalated from there. Anyhow this is a Hail Mary man. someone Tried open a bank account this week in my name and I got scolded by a top level BOA security guy whos only Concern wasn’t me but the liability my devices posed to their architecture or whatever. Blew my mind. litetally a department in BOA named account takeover I had to deal with. Scolded me for not addressinf it sooner. Wtf. I’m not a cyber tech. Anyhow I’m Out. Be good.

I’ll go ahead and close this thread. Discovering a ‘kids’ keyboard (keylogger) permissioned and tied to my life’s vault (SS, DL/PSPORT/TITLES/BANKING/CREDIT/ etc. was shocking to say the least. After rebooting my device at apple as the ATO exec at my bank mandated in order to open a new account, and regain permission to use online banking, i was restricted/locked out of logging into my apple id. The genius bar tech was confused and said he hadnt seen it before (he could have been new) but the iPhone screen was dark black sand in lighter greyish type it said: Your account is restricted. Either your APPLE ID, or you device are Managed’. I thought it strange that somehow you could restrict one and not the other? Maybe it was a fake or phishing prompt, but I called apple tech in austin and he confirmed it. this is why when i found these cruising around my analytics for ‘details’ of this, finding this was weird:

Payload manifest: bplist00)OrderedProfiles^HiddenProfiles i_8com.apple.ATT_NR_US.f7eb2f44-daOe-11eb-8349-f45c89abb0d9 mc meta: bplist00Ô_LastMDMMigratedBuild_LastMigratedBuild&StopFilteringGrandfatheredRestrictions_ AllowedGrandfatheredRestrictionsU21G93Ñ

  • who knows. Life goes on. I’ll shut this down, thanks to anyone who took the time review or respond. Many thanks, and please be good to yourselves.
Support needed to certify, unbelievably, of possible exploit of mighty iOS. (Im the lucky loser, possibly)
 
 
Q