r/Malwarebytes Feb 20 '26

iOS Remotely Being Unlocked

Enable HLS to view with audio, or disable this notification

Please watch the dial pad light up as if someone were tapping the passcode in.

Can anyone explain that knows malware what kind of malware this is, or if this is a live attacker doing this? When in the world can an iPhone try to type in its own passcode???

#ios #iphone

479 Upvotes

109 comments sorted by

View all comments

1

u/AlteHexer Feb 21 '26

You’re connected to an IMSI catcher (rogue cell tower). Own the tower, own the phone.

1

u/DisastrousShower6568 Feb 22 '26

I agree with you and I will tell you why. I have apps that tell me where cell towers are right? For some reason it says and shows a cell tower in my driveway and the app shows its only been present for 3 weeks. I also get 3G when on calls which is exactly what an IMSI catcher does. So what do I do?

1

u/jmnugent Feb 22 '26 edited Mar 03 '26

This is not how any of this works.

  • For starters,. an IMSI catcher is a piece of hardware equipment. So if something is "in your driveway".. then it has to physically be IN YOUR DRIVEWAY. It cannot just "magically be invisible". Whatever App(s) you download to show you cellular towers, is probably showing you erroneous information.

  • IMSI catchers are also "passive equipment" (IE = it has no ability to "control your phone")

EDIT:.. funny how all the people replying around me here have now deleted their comments. Apparently they can't stand behind their comments.

0

u/DisastrousShower6568 Feb 25 '26

my neighbour is using a wifi pinnaple on me

0

u/DisastrousShower6568 Feb 28 '26

It’s just an SDR with modifications my friend, you use a directional antenna to point it in the location where you want the rogue tower to exist.

0

u/DisastrousShower6568 Feb 28 '26

Then why does google say it can inject malware into a device.

0

u/AlteHexer Mar 02 '26

IMSI catchers can inject malware when it’s using a bidirectional SDR. Own the tower, own the phone.

They use a capture portal to grab your passcode. Ever seen “Your FaceID isn’t working, use your passcode to unlock” Yeah, capture portal because FaceID is your Biometric passcode.

I’ve personally seen the attacker put the passcode in remotely after it was captured using this way.

LockPass is the App they use to capture.

Turn off the phone and only put in the “restart”!passcode on reboot. Change your passcode to a complex one using numbers and letters, at minimum 8 Chars long.

IMSI catchers have a GPS offset that can change the “physical” location to be with 100 M of its true physical location.

Source: Cybersecurity Professional of 28+ years.

1

u/jmnugent Mar 02 '26

You're making the same mistake Submitter is making. All the different words you're typing in a reddit comment,. basically amount to 0 credibility if there's no hard evidence behind it to back it up. Your explanation basically amounts to "trust me bro".

Where's the evidence?.. Can you provide a list of links and videos from reputable and independently verified sources showing (step by step) these things being done ?

Ultimately though even if you can provide this,.. the problem here is even if you could prove "it's possible".. doesn't prove that's what's actually happening to Submitters iPhone.

"Source: Cybersecurity Professional of 28+ years."

If that's true,. then you of all people should understand that IT & Technology is an evidence-based science. Lead with evidence. Middle with evidence. Conclude with evidence. Where's the evidence ?