Anyone still enduring EFI Rootkit madness?

ive been following several users nightmares of the EFI Rootkit nuisances that people have been enduring ever since mine started around 5 odd months ago.

Now I’m not going to go into any detail just yet, since for the most part - it’s a looooong piece of text to write, just to be shutdown, disbelieved and end up generally unhelped from many people at all…so i won’t waste my time just yet, im really just wondering if any of the poor that also have/had or still do have this maddening, expensive saga bestowed upon them - have had any luck ridding themselves of the filth?


Im attaching some images for the sceptics and the ones who claim all the picture/screenshot evidence thus far as ‘normal’


i managed to get in pretty deep into the system files to screenshot or copy of photograph a bunch of evil stuff that I haven’t seen the others post up, so enjoy it, it’s pretty wild stuff.


But seriously any help would be appreciated - for the most part, I’ve learned just to live with it.

Only real way out I see is to replace ALL devices at once….modems, routers, mice, pc/Mac, phones, new phone number, smart tv, portable tv boxes, usb drives of any description, leave behind all email address, order new bank cards and literally throw all those old into the bin or burn them and start from scratch. I’ll be moving house in the near future so that is my plan… and it’s only one I have.


[Edited by Moderator]

iPhone 8 Plus, iOS 16

Posted on Oct 8, 2023 02:50 AM

Reply

Similar questions

6 replies

Jan 26, 2024 06:59 AM in response to lyndsayyy

Hey mate

I got a secondhand HP mini pc and was just using internet hooked up through my phone and not using the broadband at the house and alll was good for a few weeks and I don’t remember the exact point when I noticed… I think I might’ve logged into an old email account or something and came back it probably worse than ever now. I’ve got features and extensions loaddd into my CPU settings.. it’s overclocked… managed servers everywhere, blah blah blah it goes and on… you know exactly what I mean

You say you’ve had it for years

Do you just try to forget about it and live with it? Have they touched your bank accounts? Me, no. Seems like they’re only interested in the crypto mining on my devices.

I still spend waaaaay too much time trying to beat this thing. It can’t be. There is contingencies for every single app and situation you can try to throw at it..

Have you at all worked out how to wipe a hard drive fullly without the hidden undeletable partitions?? That’d be a good starting point.

Jan 26, 2024 05:23 PM in response to HappyCamper007

Howdy


No I can’t delete those partitions either. I had some limited success using disk utility “Open image” and renaming various file names whilst in the open dialogue file browser window which broke some of the links. I have over 500 processes running in recovery and they just respawn immediately. Trustd and launchd and the kernel etc wont stop no mater what.. Plus terminal has been messed with so commands that should work dont.


We (think) we got rid of it once using a sparse image but invariably once online it comes back via wifi or iPhone hot spot or Bluetooth. It’s always merging my iCloud accounts and changing my avatars. Locking me out of after one try even though it’s telling me it’s my third. My 2 factor text messages arrive from bogus phone numbers, they arrive irregularly and are intercepted. Emails addressed to me directly go to my trash so I miss stuff regularly for example the Australian federal police inviting me to be a witness for the mining case.


linux kinda worked but the partition map won’t be erased completely l. I removed the labels and flags but as soon as the GPT and APFS is selected they are still there hiding!


I found a folder in my EFI called CAFEBEEF. Apple haven’t told me if that’s supposed to be there. I also found ramdisks called sunburst and golden gate.


I also have their server outgoing ports that I got before they hid themselves and purged the logs . It’s sophisticated.


some info that may help you:


when you install the OS and it does its restart for the final installation part, I did a hard shutdown then command R and went to recovery and some new stuff was mounted that seems to get purged once it runs for the first time. It mounts 9 volumes with some folders the most interesting one is called restore. I think it comes down via the preboot server. Perhaps this temporary window may hold the key to removing it.


the latest Sonoma update helped a lot but the virus is back today. I saw it enter via an opendirectory pid in my recovery/installation log. I got excited when I saw the WebKit bundles that had been deleted/repaired.


But of course that’s only part of the beast and they indeed have a response for absolutely everything. I’ve had it since early 2020. Been through a lot of devices in that time.


I would love to give up. But I don’t have any choice. I can’t afford forensics /monitored security.


it gets me down but u can’t live in perpetual depression fear and frustration for ever so invariably you become desensitised to it all. Sadly.


it just sucks up so much of my time. It’s incredible. Thousands and thousands of hours.


do u think u got it via the net? I’m not sure what to think or who to trust these days! Seems pretty severe for a remote intrusion. It’s good to talk to you.


It feels like no one understands what we are going through..


I’m sure there’s lots of typos. Apologies as im typing on my phone (MacBook needs to be restored again)



Jan 26, 2024 05:31 PM in response to HappyCamper007

aleo Some of those folders that are mounted (mobile activation and the boot stuff logs caches and efires can be cleared via random disk then you can easeDisk then eject. But not all.


you would think it would be possible to force overwrite it but not seeming to be possible. Even Apple returns the devices to me with the problems stil present.


crazy times. Seems to be a problem that’s growing quickly. A lot more evidence of people having it now than there was in 2020.


I am mostly worried because I can’t safely buy or hold digital currency with this in my devices. So what happens if/when they change over. What willl we do?



This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Anyone still enduring EFI Rootkit madness?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.