Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Kickstand77

macrumors newbie
Original poster
I’m fighting an intruder who has been getting in my 5G network the last 23 months. I’m getting fairly close to kicking him out of my network & Apple devices, but he’s really good, or actually very evil. To help my struggle, I bought this 11-year old MacBook Pro i7 512GB 16GB-ram, considered one of the best Apple made, but you can’t sign into any of your Apple accounts. I got it for $125 on eBay. So, being I can’t afford a $2,400 laptop, I installed OpenCore Legacy Patcher & discovered a bunch of ways the hacker was accessing my Apple devices & network. He’s evil!!! Louisville police detective said to submit IC3 complaint at the FBI website & I submitted two. I had to go to the library cuz the hacker was preventing me from uploading the report. I’ve had to use library computers for several matters because the hacker seemed to interfere quite easily. I even mailed a 4-page Pages document to the local FBI office in Louisville, KY begging for help. Not a word from them. He’s still got my DNS messed up & there’s bunches of Netstat info showing hundreds of connections & so on. HELP, please. I could tell you stories that will blow your mind. OH, I tried posting in another forum & I beleive he took the post. SO, I’m trying again & I’ll copy it this time.

<netstat -R> Command revealed way too much info I’m concerned about.
50+ active kernel control sockets, 20 sctive kernel event sockets, 10 registered kernel control modules, 175 active LOCAL (UNIX) domain sockets, & 50 active internet connections.
Screen Shot 2026-08-22 at 10.18.59 PM.jpg


The following is my current network information using ifconfig in macOS Terminal
Screen Shot 2026-08-23 at 12.10.21 AM.jpg


This is my first post about anything i’ve experienced. The hacker even prevented me from participating in Verizon forums. So, I’m giving this forum a shot. Any help with this matter will be greatly appreciated. Thanks, Mike D. , aka “Kickstand77"
 
  • Haha
Reactions: startergo
At a glance there's nothing super glaringly bad here.

As I mentioned when you posted this before, your best bet is to find a cybersecurity expert and have them look into this in some detail.
 
I even mailed a 4-page Pages document to the local FBI office in Louisville, KY begging for help.
Law goes on facts, not pleading. They aren’t Batman.

You don’t provide any info or details about the attack vector. What 5G network? Are you talking about a 5G hotspot, the 5G band on your wifi? What network are they getting into is my first question.

Without knowing anything about your network, not much we can do.

Getting onto your wifi network still doesn’t give them access to your Apple services. One has nothing to do with the other. Just take a deep breath and give us info about your actual network set up. Then give us details about your iCloud account as well as what you mean by accessing your Apple devices. Like, do you see them move your files around or reading your emails? I suspect they likely just have your passwords and your wifi isn’t setup securely. Both are easily fixed. We just need to know the details.

You’re looking at sockets and whatnot but clearly have no idea what any of that means. Let’s roll it back to the basics.
 
You should try asking a friendly AI to explain these screenshots to you. (Unfortunately the forum rules forbid me to post their analysis here. But Google Gemini gave a very detailed breakdown.)

You are looking at normal Apple/macOS behaviour. From these screenshots, there is no evidence of you being hacked.
 
  • Like
Reactions: 4sallypat
You're tilting at windmills.

I'll assume you're a rational person who just has "enough knowledge to get themselves into trouble" and say you should do one of three things:
1. TRULY educate yourself on network security (i.e. take some classes - not "read Reddit")
2. Engage the services of a professional security consultant
3. Simply accept that Terminal and Console Viewer are "over your head" and stop looking at them.
 
Law goes on facts, not pleading. They aren’t Batman.

You don’t provide any info or details about the attack vector. What 5G network? Are you talking about a 5G hotspot, the 5G band on your wifi? What network are they getting into is my first question.

Without knowing anything about your network, not much we can do.

Getting onto your wifi network still doesn’t give them access to your Apple services. One has nothing to do with the other. Just take a deep breath and give us info about your actual network set up. Then give us details about your iCloud account as well as what you mean by accessing your Apple devices. Like, do you see them move your files around or reading your emails? I suspect they likely just have your passwords and your wifi isn’t setup securely. Both are easily fixed. We just need to know the details.

You’re looking at sockets and whatnot but clearly have no idea what any of that means. Let’s roll it back to the basics.
Gosh, I probably change passwords once or twice a week. I keep everything on index cards now cuz in the beginning, he setup a shared passwords folder in my Passwords app. When it all started 23 months ago on Labor Day, he got in my Verizon 5G network then eBay & bought a 99 cent toy soldier & charged $500 shipping & $30 tax for $531. I had a bank credit on file. 5/3 Bank did two investigations & refused to refund me the money. That's when I wrote a detailed two page letter with attached evidence & mailed it to 5/3 corporate. The next day I got a call from the presidents office &I was finallynrefunded the money plus interest. It took nearly five months. That's just the tip of the iceberg. He intercepted two Cash App transactions for $50 & $30. Cash App wouldn't refund. DON'T USE CASH APP!!! I finally got the MacBook Pro & that's when I figured out lots of methods he was using. Two months in a row he racked up 800GB & 700GB passing anonymous data through my network. I still to this day discover Google warnings about violating their terms of conduct & my behavior is resembling bots, server is malformed, ........ I attached one of them. I exported the email as a pdf file to my documents folder. I've got tons of evidence saved on USB devices. I still believe he's got my DNS hijacked sometimes. I gotta go into Terminal & run bunches of commands involving mDNSResponder, SNTP time, mdutil to index my files, networksetuputil to set DNS servers, dscacheutil to flush the cache, & others just so I can get my resolver back. Also, I've been suspecting he's got some kinda custom domain to possibly get my emails like MITM. I did another factory restore on my iPhone 17 last night using the MacBook. It's a daily battle against him & I can't have any streaming services anymore. He's takes them sometimes or latches on somehow. He had four devices hooked to my AppleTV in the cloud, a dozen people connected to my Prime Video, & 125 devices had connected to my Google. I finally had to get rid of it. An Apple tier two supervisor told me Google is the easiest to hack. Apple finally admitted it was a device issue. I finally was able to show them actual evidence & issues they couldn't fix. In the Samsung TV logs, there's IP/network config entries with dates in 1974 & 2106. It's not hacked now cuz I don't use Wi-Fi anymore & I only have two Ethernet ports. Been looking on eBay for a Cisco or Linksys managed gigabit 8-port PoE Ethernet switch. He'll eventually go away I think but he hasn't. I've managed to lessen the data each month to around 200-300GB. Again, Ive only mentioned a few things he's done. OH, Ive seen him take my whole inbox of emails right in front of my eyeballs while on phone with Verizon, TWICE! I'd love to see him get arrested & computers taken away. I pretty knew where he was but I think he's been evicted from the 21-story apartment building downtown. OK, I'll wrap it up for now. Thanks for the ear.
 

Attachments

At a glance there's nothing super glaringly bad here.

As I mentioned when you posted this before, your best bet is to find a cybersecurity expert and have them look into this in some detail.
Howard, Im a poor retired disabled 64 year old from a motorcycle crash 9 years ago so you can imagine my income dropped considerably with SSDI. I get by fine but there's no way I could afford their services. I did call around town & I couldn't find anybody that made service calls to residential & Louisville Police can't do anything, said complete IC3 complaints at FBI site, I did, & wrote a detailed 4-page Pages letter to the local Louisville FBI office. I did another factory restore on my iPhone 17 last night using the MacBook. I'm exhausted after fighting this hacker for 23 months.
 
  • Like
Reactions: Howard2k
Thanks for sharing all those details and screenshots. It’s clear you’ve put a massive amount of time into tracking these system behaviors. Regardless of the technical side, what you’re describing - feeling stalked for 23 months and dealing with bypasses on your personal devices - sounds incredibly exhausting and isolating.

To be honest, it sounds like you’re under a huge amount of pressure right now. Dealing with this level of constant surveillance and technical interference would put anyone’s nervous system into overdrive. It makes sense that you feel like you can't trust the platforms you're using.

Have you considered talking to a doctor or a professional about the stress this is causing you? Even if just to help manage the anxiety that comes with being targeted like this? Sometimes when we are in a high-stress "battle" for this long, our bodies and minds need a safe space to decompress so we can think clearly about the next steps.

It might be worth a check-in with someone neutral just to make sure you’re looking after yourself while you deal with all of this.

Take care of yourself.
 
Howard, Im a poor retired disabled 64 year old from a motorcycle crash 9 years ago so you can imagine my income dropped considerably with SSDI. I get by fine but there's no way I could afford their services. I did call around town & I couldn't find anybody that made service calls to residential & Louisville Police can't do anything, said complete IC3 complaints at FBI site, I did, & wrote a detailed 4-page Pages letter to the local Louisville FBI office. I did another factory restore on my iPhone 17 last night using the MacBook. I'm exhausted after fighting this hacker for 23 months.

Sorry to hear about your motorcycle accident!
There's no indication visible here that there is someone inside your systems.

Totally grasping at straws but have you replaced your home networking equipment? Is it possible that you home router has been compromised via backdoor or firmware?

Regardless, before anything else at all, I would secure my Apple, Google, and Microsoft accounts, along with your primary email to an external passkey pair (or triple) like Yubikey.

The outcome of this is that nobody can sign into those accounts without having your physical yubikey (or your recovery keys, which you would print but not save on your computer). You need to set this up from a computer you know is not compromised. Ideally, find a friend who has a MacBook and use their MacBook to enroll your keys.

Apple:
You need to ensure that all your devices support passkeys. Your MacBook Pro in particular is a concern, so check if the MacOS you're running on that is supported.

Once your Yubikeys are enrolled, check Find My and ensure that any foreign devices are evicted. They will need the yubikey to come back in.

Again, the outcome you need is that nobody can sign in without your yubikey. You need to test this and can do so from a friend's PC, or from a private browser session on a browser that cannot access your passkeys.

You also, for convenience, can place your Apple passkey into iCloud, but you don't want to do this until you've got a better handle on things.

We can't post AI stuff here, but you can google "walk me through setting up my appleID to use ONLY Yubikey passkey for authentication"

Google:
Form your Google account you can also add your physical yubikeys. Same thing - you want to ensure that nobody cans sign into google without your physical keys. You can add a device bound or iCloud passkey later for convenience once things are locked down and tested and you're feeling safer.


Microsoft:
They actually are pushing to delete passwords altogether. Do that, and enroll your passkeys. Again, add device bound or cloud passkey once you're certain everything is clean, not too early.

Primary email: If it's google, apple, or Microsoft, you're already done. If not, try to set up your primary email to bind it to your yubikey. This is for protection in MFA scenarios.

Amazon also supports passkeys.


this is the key that I would be using (two or more):

It supports passkey credentials but also TOTP.

And again, check your hardware firmware is up to date, search for vulnerabilities tied to that specific model or even brand. And consider replacing with a more reputable brand, or at least a different brand.

Once your primary accounts are secure and tied to yubikey exclusively for login, and you've removed questionable devices from Find My and signed out other Google accounts, you can protect yourself against people using those vectors to come in.

Again, not to beat a dead horse, but you need to ensure and test that the physical passkey is required. You don't want Yubikey to be an "option" to sign in, you want it to be the ONLY way to sign in. Sign in with the passkey, or sign in with the passkey and password, but not sign in with just a password.

Again, again, don't do this on a computer that might be compromised. If you do, then your recovery codes could be exploited.

Incidentally, this forum supports passkeys too.

There's a slight learning curve, and the inconvenience at the outset of setting up all three keys, and then testing. But even if it takes you half a day it's crucial, IMO.
 
As an Amazon Associate, MacRumors earns a commission from qualifying purchases made through links in this post.
  • Like
Reactions: tonmischa
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.