The term "wtf" is putting my experience mildly. I've been in the "technology" industry for 24+ years. I've been dealing with an active breach at home since July 3rd; I've gone through 7 cell phones, 6 phone numbers, on 2 carriers and 2 modems.. not to mention every electronic in my house and an entire server room. I went into the store tonight to get new Sims for two of my phones. Guy in his 20s was working and asked why I wanted to swap my Sims. I told him I was having a security issue and I needed new ones but couldn't insert them at the store that I need to do it in a controlled environment. He told me I had to show him my hacked phones.. no problem, whipped 3 phones out. I showed him one, pointing out that the signing certificate and apk hashes do not match on all apps. I have screenshots of everything verified last night, I woke up this morning to them all failing. The only thing done to the phone was sign into Google play and download teams. "Sir this is a third party operating system, it's not the original Samsung android OS." Yeah, no sh*t.. I loaded a hardened copy of android. "Sir, what makes you think you're hacked." Um, because I say I am. This is literally my job. "Sir, to hack a phone like this you would need to be a world class hacker." Um, I assure you no you don't but as a matter of fact, I believe that's who's targeting me. "Unless you can show me on these other phones that have the original operating systems on them I'm not supposed to replace them." Ok bet, here you go. Brand new razr plus. I pulled up my endpoint and showed him it detected SSL stripping on WiFi and cellular. "Sir this is a third party app, you need to show me on the os." Omg man are you kidding me?! Ok here you go.. first do you know what a sym link is? "No" ok it's when a symbolic link is made between files or folders meaning the OS will look to it's folder but it's linked to another so it has no change on the OS side regarding programming. Google fi and Google talk is symbolically linked to my OS, there's a system_ext that has a copy of all the OS files but has additional files as well that are being called on in a whitelisted folder. "Sir your phone is on airplane mode" SMH. Deep breath. I know.. "sir I need proof like an alert popup from the OS" To give me new Sims? You need a popup? "I have to show that the phone is not working or has something wrong with it. You have your phones on airplane mode. If we take it off I'm sure they'll work." If you're reading this... It took everything in me not to smack you in the mouth. You're welcome.. I have them on airplane mode to possibly prevent you and the store from infection.. I only brought them incase they were needed. "Sir I'm going to need to turn them on.".... You know what nevermind. "SIM cards aren't capable of having viruses, getting new Sims won't help anyways.." (I'm dumbstruck on how much of a dbag this guy was) dude. I assure you I know more than you do about forensics and security.. "the best I can do is give you this number to call" who is this? "Att tech support" I'm good man. I spoke to them last week, the passed me to security which passed to a higher up security which moved me to att global security. After I told them I've had a lot of the same malware being used by the same threat actors hitting them but I had a copy of their initial payload unencrypted, they asked my contact info and then paused.. he said his system went down and it would be a minute. So I waited. He came back a few min later and told me his systems are not coming back up. So I asked to get passed to a coworker to give my info. "I'm sorry sir but all of our systems are down right now." Global security? "Yeah, please call back in about 30 min" that may just be a coincidence but hey at this point, never know... I've had the WORST experience with att. Internet gets it's updates over the air so I'm unable to reload the firmware, not allowed your own modem. I can literally stick the fiber connection into my firewall directly and could get it to work with a was110 sfp module, extracting the certs on the modem and cloning the mac but yet you can't make it easy by allowing a normal modem. The wireless... Where do I start. One, I bought 2 phones, had someone else purchase and ship them to someone's house. Activated when having my modem replaced. Hacked that night. I requested for WiFi not to be setup on the modem, came home and couldnt get internet. Logged into the modem and it had a hidden network called ghost set up. Wife's voicemail password was setup, our phones were routing through ATT4. Later that week.. guess what popped up on the threat map? ATT4. A week later I stopped in a store to get new phones with new numbers. Mind you at this point I'm already out 50-70k worth of equipment at my house.. I had to sign up for two more phone numbers to get new phones for as cheap as possible. (Come to find out I could have upgraded my original two phones and not paid for new ones) read more