Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Fourteen_Endpoints — Shell Companies Inside Apple's Privacy Relay | Kitploit
Tools/GitHubGitHub/jgoyd/fourteen_endpoints
OSINT (Open Source Intelligence)ReconnaissanceNetwork ForensicsForensicsInformation GatheringNetwork SecurityDigital ForensicsPrivacyThreat IntelligenceIncident ResponseDNS Analysis
51255 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
jgoyd/fourteen_endpoints

Fourteen_Endpoints

Shell Companies Inside Apple's Privacy Relay

View Repository

The Middlemen

Shell Companies Inside Apple's Privacy Relay

An anonymous Delaware LLC publishes a Bible prayer app, a daily journal, and a caller ID tool on the App Store. That entity operates encrypted relay infrastructure inside Apple's privacy network. That relay terminates at Taiwan Mobile Co., Ltd.

You can confirm it's live right now. Three commands.


In 2024, Apple introduced Oblivious HTTP for Live Caller ID Lookup. Your phone asks who's calling. Apple's relay strips your identity from the question. A third-party provider answers without ever knowing who asked. The relay sees your IP but not your question. The provider sees your question but not your IP. Nobody sees both.

To participate, providers register endpoints and receive Apple's approval. Their infrastructure then sits inside the relay — encrypted, anonymized, trusted.

What follows is a documented record of what was found inside that relay on ordinary production iPhones.


The Bible App That Runs Relay Infrastructure

StopScam LLC is a Delaware limited liability company registered at 254 Chapman Rd, Suite 208 #20663, Newark, DE 19702. That's a registered agent service. There is no office. There are no named officers. There are no named humans anywhere in the public record.

StopScam LLC publishes three apps on the App Store:

  1. StopScam: Scam Detector Pro (ID 6741771102) — a caller ID app
  2. Pray Bible: Daily Prayer — a Bible prayer app
  3. Evaari: Daily Journal — a journaling app

Apple approved this entity — Developer ID 1795482410 — to operate pir.stopscam.ai and ohttp.stopscam.ai inside its OHTTP relay. Certificate Transparency logs show 76 certificates issued for stopscam.ai subdomains since November 2024. Including n8n.stopscam.ai — an open-source workflow automation platform. A caller ID service doesn't need workflow automation. A data processing pipeline does.

StopScam is not alone.


The Other Providers

kaylees.site — Wipr Content Blocker

Public records show kaylees.site belongs to an independent iOS developer known for Wipr 2 — a Safari content blocker with over a decade on the App Store. Wipr 2 includes a feature called Filtr that uses Apple's iOS 26 URL Filters API to block content at the network level across all apps. That API uses the same OHTTP/PIR infrastructure, which explains why pir.kaylees.site appears in the relay as an ObliviousHopFallback endpoint.

Unlike StopScam LLC, this is a publicly identifiable developer with a documented product history. The presence of kaylees.site in the relay is consistent with legitimate URL Filter provider enrollment. What remains unclear is whether the traffic observed on this channel is solely Filtr content blocking or whether something else is riding a legitimate provider's relay presence.

Pepper AI / Aura (pepperai.aurasvc.io)

Aura is a major US consumer security company — parent of Hotspot Shield, Identity Guard, and Betternet. Their urlfilter.pepperai.aurasvc.io endpoint appears in the relay in the same ObliviousHopFallback chain as the other providers. The urlfilter prefix suggests content filtering — a function that requires inspecting data passing through the relay. Present in 5 of 15 Persist files.

AutoSec / Uney GmbH (issuer.autosec.com)

AutoSec is published by developer Hieu Van (App Store Developer ID 1876492156) under copyright of Uney GmbH — a company registered at Baarerstrasse 25, 6300 Zug, Switzerland, with additional offices on Sheikh Zayed Road in Dubai and operations in Ho Chi Minh City, Vietnam. Uney also produces ShieldNet 360 (enterprise cybersecurity) and SkyTrack (autonomous vehicle mission platform).

AutoSec's own privacy policy states the app is operated by "The Legal Entity to be Confirmed." It collects device identifiers, location data, IP addresses, call/message metadata, contact lists, and browsing behavior. Data is shared with "third party clients, agencies and networks" and transferred to countries "including but not limited to India." Both primary and fallback OHTTP hop entries appear in the relay.

Carrément (antispam.carrement.ai)

Carrément is a small company at 18 Rue Bailey, 14000 Caen, France. Its public-facing product is DialogPro (dialogpro.ai) — an "intelligent answering service." No named team members. Minimal web presence. Hosted on AWS Canada. The antispam subdomain is consistent with call-handling or spam-filtering services. Single appearance in the relay.

Yandex (ios-service.cid.yandex.net)

Yandex — Russia's largest search engine and technology company — operates a caller ID service for iOS. Both primary (ObliviousHop) and fallback (ObliviousHopFallback) entries appear in the relay with two distinct UUIDs and session keys. Yandex is subject to Russian Federation data access laws.

Taiwan Mobile (osbstage.twmsolution)

Taiwan Mobile Co., Ltd. — one of Taiwan's three major telecommunications carriers. The terminal node. UUID C56B1AED-20FE-4B7D-B1EA-D791DA57A549 is persistent across captures. The osbstage prefix suggests a staging backend (Oracle Service Bus or similar). Present in 4 of 15 Persist files and identical between March 19 and March 21 captures.


The Invisible Cloud

Here's what Apple's privacy architecture promises:

  Your iPhone ──> Apple Relay ──> Caller ID Provider
                  (sees IP,       (sees query,
                   not query)      not IP)

              Nobody sees both. Privacy preserved.

Here's what's actually inside that relay:

                  Apple Relay
                      │
     ┌────────┬───────┼───────┬────────┐
     v        v       v       v        v
  kaylees  StopScam  Pepper  Yandex  AutoSec
  .site    .ai       AI      (Russia) (Zug/
  (Wipr)   (Bible    (Aura)           Dubai/
            app)                      Vietnam)
     │        │       │       │        │
     └────────┴───────┼───────┴────────┘
                      v
               Taiwan Mobile
               Co., Ltd.

Fourteen endpoints. Six countries. An indie content blocker, an anonymous Delaware LLC, consumer security brands, a Russian search engine, a Swiss-Dubai-Vietnam cybersecurity firm, Google API endpoints, and a Taiwanese state telecom — all operating as approved providers inside Apple's privacy layer.

This matters because Apple's OHTTP relay is shared infrastructure. Every iPhone using Live Caller ID Lookup connects through the same relay to the same approved providers. The question isn't whether this affected one phone. It's how many.

#NodeEntityCountry
1osbstage.twmsolutionTaiwan Mobile Co., Ltd.Taiwan
2kaylees.siteKaylee Calderolla (Wipr / Filtr)Italy/Intl
3stopscam.aiStopScam LLC (anon Delaware)USA (on paper)
4pepperai.aurasvc.ioAura (Hotspot Shield, Identity Guard)USA
5-6ios-service.cid.yandex.netYandexRussia
7-8issuer.autosec.comUney GmbH (Zug/Dubai/HCMC)Switzerland
9-11*.googleapis.comGoogle (Safe Browsing, Gemini, AI Platform)USA
12privacy-pass-issuer-eu.truecaller.comTruecallerSweden
13antispam.carrement.aiCarrément (Caen, France)France
14caller-id-issuer.nordvpn.comNordVPNPanama/Lithuania

What Your Phone Shows vs What's Happening

Your phone says everything is fine. Settings looks normal. Battery is normal. No alerts, no prompts, no notifications.

Behind that, Apple's relay daemon — networkserviceproxy — is running 98 scheduled background tasks over the capture period. Every 12 hours, it wakes up, allocates 5,120 bytes of network, and executes. Zero CPU. Zero user interaction. Unique task ID every time.

Caller ID lookups happen when someone calls you. They don't run on a 12-hour timer at 2 AM with fixed allocations and no human involvement.

Download Tool