AI-Assisted Cyber Attack Investigation & Prevention
Budget: $1,500 – $3,000 USD
I am making investigation about fraud and in order to stop me cybercriminals continuously attack all my devices. Or when I am analysing files with new device using AI, among the files there are some malicious files which pretend to be jpg / PNG / pdf / xlsx but in fact there is bad malicious code hidden which exploits the device and AI.
High skilled hackers are working against me and they use following instruments:
- registering my devices apple under hidden mdm which is not shown in settings in VPN
- hacking my apple IDs even new and making me child in my own profile
- changing the apps (in logs I see that no check was done when downloading this app, certificate was not used) to looking same but malicious / modified probably using firebase iOS config (because network logs show that)
- MITM attack. All my AI (both through browser and installed as apps) are providing wrongs answers denying facts and telling lies instead of true
- it happened 2 times that password from my phone to unlock screen were changed (that only can be done by MDM/dep/enrolled/managed device)
- apple classroom were used by attackers to get access to my screen without any notifications making me student and attacker teacher (found plist files where unpromptedacesstoscreen was true and mobileconfig files, also found that in 1 week 14 times mobile operator configuration was installed and uninstalled)
- also I documented facts of using IMSI catcher (which how I found out very easy to create and very cheap to buy in any country just need raspberry pie + antenna + simcard slot) which pretends to be a real cellular station while in fact it's fake and it intercepts connection, stealing sms, uploads malicious certificates and making MITM attack, changing the answers of AI to wrong)
- more than 10 devices (iphone,Samsung,MacBook,windows laptops,google pixels, raspberry pie, Huawei) were hacked and spoiled using mentioned above methods
- when try to erase / clean it finds out that malicious things are interpreted like system files or/and locked or changed directory and after erase problem doesn't disappear
- for understanding the problem please refer to Marcel Molnar and YouTube video from conference Black Hat named "Impostor Syndrome" where he find out that's it is enough just to know serial number of apple device which is not hidden and printed even on the box to enroll device in MDM. Also he tells about registering rogue devices - I see same in my data (I see 2 devices in logs while in fact should be one and in settings it is shown as 1)
My goal is
- to prepare documented evidence of the fact that my devices were under heavy continuous cyber attack (would be great if possible to prepare document which can be used in court internationally, for that there is should be organization with licence)
- to clean device/devices
- to make them resistable in future for these kind of attacks mentioned above
- to upload/reupload clean real version of Graphene OS to Google Pixels devices
Some more details:
The way to solve part of problems mentioned above connected to MacBooks and iphones is to make wifi hotspot with proxy which belongs to us and controlled by us which will tell devices that they are not enrolled or registered in MDM after erase and activation of devices (this can be done using raspberry pie as hotspot and using Adguard home or pi hole to block addresses refers to dep/mdm/enrollment/configuration/setup). I am not IT specialist but the decision for some of the problems connected to macs and iphone is approximately like this.
High skilled hackers are working against me and they use following instruments:
- registering my devices apple under hidden mdm which is not shown in settings in VPN
- hacking my apple IDs even new and making me child in my own profile
- changing the apps (in logs I see that no check was done when downloading this app, certificate was not used) to looking same but malicious / modified probably using firebase iOS config (because network logs show that)
- MITM attack. All my AI (both through browser and installed as apps) are providing wrongs answers denying facts and telling lies instead of true
- it happened 2 times that password from my phone to unlock screen were changed (that only can be done by MDM/dep/enrolled/managed device)
- apple classroom were used by attackers to get access to my screen without any notifications making me student and attacker teacher (found plist files where unpromptedacesstoscreen was true and mobileconfig files, also found that in 1 week 14 times mobile operator configuration was installed and uninstalled)
- also I documented facts of using IMSI catcher (which how I found out very easy to create and very cheap to buy in any country just need raspberry pie + antenna + simcard slot) which pretends to be a real cellular station while in fact it's fake and it intercepts connection, stealing sms, uploads malicious certificates and making MITM attack, changing the answers of AI to wrong)
- more than 10 devices (iphone,Samsung,MacBook,windows laptops,google pixels, raspberry pie, Huawei) were hacked and spoiled using mentioned above methods
- when try to erase / clean it finds out that malicious things are interpreted like system files or/and locked or changed directory and after erase problem doesn't disappear
- for understanding the problem please refer to Marcel Molnar and YouTube video from conference Black Hat named "Impostor Syndrome" where he find out that's it is enough just to know serial number of apple device which is not hidden and printed even on the box to enroll device in MDM. Also he tells about registering rogue devices - I see same in my data (I see 2 devices in logs while in fact should be one and in settings it is shown as 1)
My goal is
- to prepare documented evidence of the fact that my devices were under heavy continuous cyber attack (would be great if possible to prepare document which can be used in court internationally, for that there is should be organization with licence)
- to clean device/devices
- to make them resistable in future for these kind of attacks mentioned above
- to upload/reupload clean real version of Graphene OS to Google Pixels devices
Some more details:
The way to solve part of problems mentioned above connected to MacBooks and iphones is to make wifi hotspot with proxy which belongs to us and controlled by us which will tell devices that they are not enrolled or registered in MDM after erase and activation of devices (this can be done using raspberry pie as hotspot and using Adguard home or pi hole to block addresses refers to dep/mdm/enrollment/configuration/setup). I am not IT specialist but the decision for some of the problems connected to macs and iphone is approximately like this.