Interview → iPhone software from the "employer" → you no longer have a smartphone 👋

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Interview → iPhone software from the “employer” → you no longer have a smartphone 👋
The old-new scheme for locking an iPhone via “Lost Mode” is back in circulation. Only now it has become more sophisticated: at the start of the post is a real-life example of a multi-step scheme, which we described in detail in an article on Habr.
There, too, are several more cases and a breakdown of the attacker’s actions: how he gains access, locks the device, and moves on to demanding a ransom. And most importantly — instructions on what to do if you are already in such a situation: which tools will help, where you should write, and whom it’s best not to contact so as not to make things worse.
😎 Bonus: we’ve prepared a clear visual guide to restoring access to an iPhone. It’s available as a PDF with clickable links — download it and save it to different devices (just in case).
#ios #dfir #mobile
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



