I think my best friend has hacked me!!! Please help

Joined
Mar 18, 2022
Messages
1
Reaction score
0
Points
1
Hello Mac Forum,
Please bear with me during this story,
I have a best friend who is a genius software developer and me myself I am Mechanical engineer with ok Background in IT and tech but not for sure near as good as him. Two weeks ago, he asked me and sent me the links on FB messenger to download Xcode and Cordova on my Macbook [cuz he doesn't own one] and so he can run his iOS code and get his application uploaded on Apple store. Me of course I agreed, then it took me a few days to update my software, download Xcode and then Cordova which made him wait longer but he didn't show any annoying reaction but I know he was annoyed somehow...

a few days later, When all apps were ready to run and download, I asked him to send me the code which he ignored completely, I asked again and then he ignored me too and changed the subject by sending memes we laugh about. A week later, which is today, I checked my desktop by coincidence and ....

I see a folder I never installed or download, What was crazy is that folder name was named after my friend name. and inside there is a bunch of other sub folder and one xcode file named after my friend name as well. This has shocked me to levels I can't describe....

I immediately contact Apple support and a senior security manager called me and we found out that the firewall was turned off and the dates of the folder creation matches the same date my friend sent me the links, She asked me to install Malwarebytes, We have scanned the device and run the scan and nothing was detected so far.

I then personally installed Knock Knock, Block Block, Task Explorer and Reikey from Objective-see

I really need your help guys, I feel like I am attacked and shocked.
1- What can I do to make sure my macbook is safe now and I am not tracked or followed by anyone?
2- What can I do to check how this folder was installed?
3- Can I check if there is any keyloggers installed on my macbook or not?


Thanks for reading my post! I really really appreciate your help

Regards,
 

Raz0rEdge

Well-known member
Staff member
Moderator
Joined
Jul 17, 2009
Messages
15,771
Reaction score
2,111
Points
113
Location
MA
Your Mac's Specs
2022 Mac Studio M1 Max, 2023 M2 MBA
First, if your friend is intending to create Apps for Apple devices, they should get their own machine since this is not a one time thing, but rather an ongoing thing. Additionally, you'd hardly be pushing the app up for them.

Anyway, the thing you should do is obviously ask them about the folder and what the files they sent you to see if they have a clear explanation.

Finally, once you have you important data backed up, you can just do a clean re-install of your Macbook and don't install any of the stuff your friend provided if you want to clear all of your concerns.
 
Joined
Jul 24, 2013
Messages
5,075
Reaction score
764
Points
113
Location
Ohio (USA)
Your Mac's Specs
2023-14" M3max MBPro, 64GB/1TB, iPhone 15 Pro, Watch Ultra
And in additions to Raz0rEdge's fine advice, are you sure it was your friend who sent the link on FB? I have had several FB contacts from "friends" who were bogus. They had set up fake FB pages and set them to look like one of my friends. It happens.

Lisa
 

Rod


Joined
Jun 12, 2011
Messages
9,707
Reaction score
1,893
Points
113
Location
Melbourne, Australia and Ubud, Bali, Indonesia
Your Mac's Specs
2021 M1 MacBook Pro 14" macOS 14.4.1, Mid 2010MacBook 13" iPhone 13 Pro max, iPad 6, Apple Watch SE.
Hopefully you already have a full backup of your device, Time machine or other. If so don't update it for now especially if it dates back to before the current changes. Certainly get an explanation from your "friend" about what's going on and if it cannot be resolved then yes, you could erase your HD and re instal your data from backup.
 
Joined
Sep 30, 2007
Messages
9,962
Reaction score
1,235
Points
113
Location
The Republic of Neptune
Your Mac's Specs
2019 iMac 27"; 2020 M1 MacBook Air; macOS up-to-date... always.
First off, the firewall being off isn't unusual. Normally it is off, but scammers prey on unsuspecting people who don't know better and claim they've been hacked by walking them through to that setting on the phone. My ex's mother got hit by that.

Secondly, "if" that copy of Xcode was legit, as was Cordova, then simply installing those would not have given your friend access to your system. Of course, those are big "ifs". Where exactly did you download those from? Xcode should ONLY be downloaded from Apple, either via the App Store or their developer portal, which you'd have to log into first to get it. If the URL is NOT an Apple.com link, then it was phony. Cordova comes from apache.org, so again, if you got that from anywhere else, it's phony. So take a look at those links you used.

If the links ARE legit, then something is amiss here. Your friend MUST have access to your Mac if they were to use Xcode on your Mac in the first place. Do you have any VNC software installed, or have screen sharing turned on? Any other user accounts on that Mac?

I would change your Apple ID password and your user login password for the Mac just for starters.
 
Joined
Sep 30, 2007
Messages
9,962
Reaction score
1,235
Points
113
Location
The Republic of Neptune
Your Mac's Specs
2019 iMac 27"; 2020 M1 MacBook Air; macOS up-to-date... always.
BTW, you said you contacted Apple and they called you back. Where did you get the number from to call Apple? If that number was NOT 800–275–2273 or 800-692-7753, then you may have been conned. And by that, I don't mean the number they called you from (scammers will spoof those numbers), but the number you personally dialed.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top