{"id":10466,"date":"2022-01-20T15:02:56","date_gmt":"2022-01-20T12:02:56","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=10466"},"modified":"2022-01-20T15:02:56","modified_gmt":"2022-01-20T12:02:56","slug":"snatchcrypto-bluenoroff","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/snatchcrypto-bluenoroff\/10466\/","title":{"rendered":"BlueNoroff&#8217;un kripto para aray\u0131\u015f\u0131"},"content":{"rendered":"<p>Uzmanlar\u0131m\u0131z kripto para birimleri, ak\u0131ll\u0131 s\u00f6zle\u015fmeler, merkezi olmayan finans ve blok zinciri teknolojisi ile u\u011fra\u015fan \u015firketleri hedef alan k\u00f6t\u00fc ama\u00e7l\u0131 bir giri\u015fimi inceliyor. Sald\u0131rganlar genel olarak fintech ile ilgileniyor. SnatchCrypto adl\u0131 giri\u015fim, Banglade\u015f merkez bankas\u0131na yap\u0131lan 2016 sald\u0131r\u0131s\u0131yla ba\u011flant\u0131s\u0131 oldu\u011fu bilinen BlueNoroff APT grubuyla ili\u015fkilendiriliyor.<\/p>\n<h2>SnatchCrypto hedefleri<\/h2>\n<p>Bu giri\u015fimin arkas\u0131ndaki siber su\u00e7lular\u0131n iki amac\u0131 var: Bilgi toplamak ve kripto para \u00e7almak. \u0130lk \u00f6nce kullan\u0131c\u0131 hesaplar\u0131, IP adresleri ve oturum bilgileri hakk\u0131nda veri toplamakla ilgileniyorlar. Do\u011frudan kripto para birimiyle \u00e7al\u0131\u015fan ve hesaplar hakk\u0131nda kimlik bilgileri ve ba\u015fka bilgiler i\u00e7erme olas\u0131l\u0131\u011f\u0131 olan programlardan yap\u0131land\u0131rma dosyalar\u0131n\u0131 \u00e7al\u0131yorlar. Sald\u0131rganlar, potansiyel kurbanlar\u0131 dikkatle inceliyor; bazen aylarca etkinliklerini izliyorlar.<\/p>\n<p>Y\u00f6ntemlerinden biri, kripto c\u00fczdanlar\u0131 y\u00f6netmek i\u00e7in kullan\u0131lan pop\u00fcler taray\u0131c\u0131 uzant\u0131lar\u0131yla ger\u00e7ekle\u015ftirdikleri baz\u0131 manip\u00fclasyonlar. \u00d6rne\u011fin, taray\u0131c\u0131 ayarlar\u0131nda bir uzant\u0131n\u0131n kayna\u011f\u0131n\u0131, resmi internet ma\u011fazas\u0131 yerine yerel depolamadan (yani de\u011fi\u015ftirilmi\u015f bir s\u00fcr\u00fcmden) kurulacak \u015fekilde de\u011fi\u015ftirebiliyorlar. Ayr\u0131ca, i\u015flem mant\u0131\u011f\u0131n\u0131 de\u011fi\u015ftirmek amac\u0131yla Chrome i\u00e7in de\u011fi\u015ftirilmi\u015f Metamask uzant\u0131s\u0131 kullanarak kripto para transferlerini imzalamak i\u00e7in donan\u0131m cihazlar\u0131n\u0131 kullananlardan bile para \u00e7alabiliyorlar.<\/p>\n<h2>BlueNoroff\u2019un istila y\u00f6ntemleri<\/h2>\n<p>Sald\u0131rganlar kurbanlar\u0131n\u0131 dikkatle inceliyor ve edindikleri bilgileri sosyal m\u00fchendislik sald\u0131r\u0131lar\u0131 uygulamak i\u00e7in kullan\u0131yorlar. Genellikle mevcut giri\u015fim \u015firketlerinden geliyormu\u015f gibi g\u00f6r\u00fcnen, ancak ekinde makro etkinle\u015ftirilmi\u015f bir belge bulunan e-postalar olu\u015fturuyorlar. Bu belge a\u00e7\u0131ld\u0131\u011f\u0131nda, eninde sonunda bir arka kap\u0131 indiriliyor. Sald\u0131r\u0131 ve sald\u0131rganlar\u0131n y\u00f6ntemleri hakk\u0131nda ayr\u0131nt\u0131l\u0131 teknik bilgi i\u00e7in <a href=\"https:\/\/securelist.com\/the-bluenoroff-cryptocurrency-hunt-is-still-on\/105488\/\" target=\"_blank\" rel=\"noopener\">Securelist\u2019in \u201cThe BlueNoroff kripto para av\u0131 hala s\u00fcr\u00fcyor\u201d ba\u015fl\u0131kl\u0131 raporuna<\/a> g\u00f6z at\u0131n.<\/p>\n<h2>\u015eirketinizi SnatchCrypto sald\u0131r\u0131lar\u0131ndan nas\u0131l koruyabilirsiniz?<\/h2>\n<p>SnatchCrypto etkinli\u011finin a\u00e7\u0131k i\u015faretlerinden biri, de\u011fi\u015ftirilmi\u015f bir Metamask uzant\u0131s\u0131d\u0131r. Sald\u0131rganlar\u0131n bunu kullanabilmek i\u00e7in taray\u0131c\u0131y\u0131 geli\u015ftirici moduna ge\u00e7irmesi ve Metamask uzant\u0131s\u0131n\u0131 yerel bir dizinden y\u00fcklemesi gerekir. Bunu kolayca kontrol edebilirsiniz: Taray\u0131c\u0131 modu izniniz olmadan de\u011fi\u015ftirildiyse ve uzant\u0131 yerel bir dizinden y\u00fcklendiyse cihaz\u0131n\u0131z muhtemelen tehlikeye girmi\u015ftir.<\/p>\n<p>Ek olarak, a\u015fa\u011f\u0131daki standart koruyucu \u00f6nlemleri alman\u0131z\u0131 \u00f6neriyoruz:<\/p>\n<ul>\n<li>Periyodik olarak \u00e7al\u0131\u015fanlar\u0131n <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">siber g\u00fcvenlik bilincini<\/a> artt\u0131r\u0131n;<\/li>\n<li>Kritik uygulamalar\u0131 (i\u015fletim sistemi ve ofis paketleri dahil) hemen g\u00fcncelleyin;<\/li>\n<li>\u0130nternet eri\u015fimi olan her <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">bilgisayar\u0131 g\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> ile donat\u0131n;<\/li>\n<li>Karma\u015f\u0131k tehditleri tespit etmenize ve zaman\u0131nda yan\u0131t vermenize yard\u0131mc\u0131 olan bir <a href=\"https:\/\/www.kaspersky.com.tr\/enterprise-security\/endpoint-detection-response-edr?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">EDR \u00e7\u00f6z\u00fcm\u00fc<\/a> kullan\u0131n (altyap\u0131n\u0131za uygunsa).<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-b2b\">\n","protected":false},"excerpt":{"rendered":"<p>Uzmanlar\u0131m\u0131z, finans teknolojisi \u015firketlerini hedef alan k\u00f6t\u00fc ama\u00e7l\u0131 bir giri\u015fim ke\u015ffetti.<\/p>\n","protected":false},"author":2581,"featured_media":10467,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194,1727],"tags":[493,1544],"class_list":{"0":"post-10466","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"category-smb","10":"tag-apt","11":"tag-kripto-para"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/snatchcrypto-bluenoroff\/10466\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/snatchcrypto-bluenoroff\/23845\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/snatchcrypto-bluenoroff\/19342\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/snatchcrypto-bluenoroff\/9701\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/snatchcrypto-bluenoroff\/26081\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/snatchcrypto-bluenoroff\/24050\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/snatchcrypto-bluenoroff\/23785\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/snatchcrypto-bluenoroff\/26744\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/snatchcrypto-bluenoroff\/26339\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/snatchcrypto-bluenoroff\/32229\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/snatchcrypto-bluenoroff\/43412\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/snatchcrypto-bluenoroff\/18452\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/snatchcrypto-bluenoroff\/18850\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/snatchcrypto-bluenoroff\/15719\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/snatchcrypto-bluenoroff\/28006\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/snatchcrypto-bluenoroff\/32329\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/snatchcrypto-bluenoroff\/28041\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/snatchcrypto-bluenoroff\/24790\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/snatchcrypto-bluenoroff\/30191\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/snatchcrypto-bluenoroff\/29980\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/apt\/","name":"APT"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=10466"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10466\/revisions"}],"predecessor-version":[{"id":10468,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10466\/revisions\/10468"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/10467"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=10466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=10466"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=10466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}