{"id":10577,"date":"2022-03-29T11:00:09","date_gmt":"2022-03-29T08:00:09","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=10577"},"modified":"2022-03-29T11:00:09","modified_gmt":"2022-03-29T08:00:09","slug":"mobile-malware-2021","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/mobile-malware-2021\/10577\/","title":{"rendered":"Mobil tehditler: 2021&#8217;de kimler ak\u0131ll\u0131 telefonlar\u0131 hedef ald\u0131?"},"content":{"rendered":"<p>Sizi en \u00f6nemli trendler konusunda bilgilendirmek i\u00e7in s\u00fcrekli olarak mobil tehdit ortam\u0131n\u0131 izliyoruz. 2021\u2019de ak\u0131ll\u0131 telefon ve tablet sahiplerinin kar\u015f\u0131la\u015ft\u0131\u011f\u0131 tehditler hakk\u0131nda yay\u0131nlad\u0131\u011f\u0131m\u0131z <a href=\"https:\/\/securelist.com\/mobile-malware-evolution-2021\/105876\/\" target=\"_blank\" rel=\"noopener\">rapor<\/a>un \u00fczerinden \u00e7ok zaman ge\u00e7medi. \u0130lk olarak iyi haberi verelim: Dikkat \u00e7eken \u015fey, ge\u00e7en y\u0131l mobil tehdit eylemlerinde 2020\u2019ye k\u0131yasla \u00f6nemli bir d\u00fc\u015f\u00fc\u015f ya\u015fand\u0131\u011f\u0131n\u0131 g\u00f6rmemiz oldu. Ancak bununla birlikte bu konuda rahatlamak i\u00e7in \u00e7ok erken. \u00d6ncelikle, ak\u0131ll\u0131 telefon ve tabletlere yap\u0131lan sald\u0131r\u0131 say\u0131s\u0131 2019\u2019dakiyle ayn\u0131 seviyede, yaln\u0131zca 2020\u2019deki rekor seviyeye g\u00f6re d\u00fc\u015f\u00fc\u015f g\u00f6sterdi. Bununla birlikte siber su\u00e7lular her ge\u00e7en g\u00fcn daha yarat\u0131c\u0131 hale geliyor.<\/p>\n<h2>Reklam yaz\u0131l\u0131m\u0131 sald\u0131r\u0131lar\u0131<\/h2>\n<p>2021\u2019de s\u0131kl\u0131kla kullan\u0131lan trendlerden biri, bir\u00e7ok faydal\u0131 uygulama geli\u015ftiricisinin \u00e7al\u0131\u015fmalar\u0131ndan para kazanmak i\u00e7in \u00fc\u00e7\u00fcnc\u00fc taraf reklam mod\u00fcllerine k\u00f6t\u00fc ama\u00e7l\u0131 kodun eklenmesiydi. \u00d6rne\u011fin ge\u00e7ti\u011fimiz baharda siber su\u00e7lular, k\u00f6t\u00fc ama\u00e7l\u0131 bir reklam SDK\u2019s\u0131 kullanarak pop\u00fcler bir alternatif Android uygulama ma\u011fazas\u0131 olan APKPure\u2019a k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/infected-apkpure\/9515\/\" target=\"_blank\" rel=\"noopener\">bula\u015ft\u0131rd\u0131lar<\/a>. Neyse ki ma\u011fazan\u0131n geli\u015ftiricileri g\u00fcvenlik konusunu ciddiye al\u0131yorlard\u0131 ve kendileriyle ileti\u015fime ge\u00e7ildikten bir g\u00fcn sonra temiz bir s\u00fcr\u00fcm yay\u0131nlad\u0131lar.<\/p>\n<p>Benzer bir hikaye, pop\u00fcler WhatsApp modu FMWhatsApp\u2019da <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/fmwhatsapp-mod-downloads-malware\/9954\/\" target=\"_blank\" rel=\"noopener\">ya\u015fand\u0131<\/a>: Uygulaman\u0131n s\u00fcr\u00fcmlerinden birindeki bir reklam SDK\u2019s\u0131 i\u00e7inde <a href=\"https:\/\/www.kaspersky.com\/blog\/triada-trojan\/11481\/\" target=\"_blank\" rel=\"noopener nofollow\">Triada Truva At\u0131<\/a> bulunuyordu. Bu Truva At\u0131, bula\u015ft\u0131\u011f\u0131 cihazdan temizlenmesinin \u00e7ok zor olmas\u0131 nedeniyle k\u00f6t\u00fc bir \u00fcne sahip. Ayr\u0131ca, Triada nadiren tek ba\u015f\u0131na bula\u015f\u0131r, kendisiyle birlikte kurban\u0131n cihaz\u0131na \u00e7ok say\u0131da ba\u015fka k\u00f6t\u00fc ama\u00e7l\u0131 uygulamay\u0131 da indirme e\u011filimindedir.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic-2\">\n<h2>Google Play\u2019de K\u00f6t\u00fc Ama\u00e7l\u0131 Yaz\u0131l\u0131m<\/h2>\n<p>Yaz\u0131lar\u0131m\u0131zda bir\u00e7ok kez <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/google-play-malware\/6434\/\" target=\"_blank\" rel=\"noopener\">k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n gizlice resmi uygulama ma\u011fazalar\u0131na girebilece\u011finden<\/a> bahsettik. Siber su\u00e7lular, t\u00fcm kontrolleri ge\u00e7ip kullan\u0131c\u0131lara ula\u015fmak i\u00e7in onaylanm\u0131\u015f bir programa k\u00f6t\u00fc ama\u00e7l\u0131 kod y\u00fcklemek amac\u0131yla bir g\u00fcncelleme gibi g\u00f6r\u00fcnmek de dahil her t\u00fcrl\u00fc hileyi kullan\u0131rlar. 2021\u2019de, Google Play\u2019deki uygulamalarda Joker ve Facestealer k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 da dahil bir\u00e7ok <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/banker-trojan-banker\/\" target=\"_blank\" rel=\"noopener\">Truva at\u0131<\/a> y\u00fckleyicisi tespit edildi. Joker gizlice kullan\u0131c\u0131y\u0131 \u00fccretli servislere abone yaparken, Facestealer ad\u0131ndan da anla\u015f\u0131laca\u011f\u0131 \u00fczere Facebook kimlik bilgilerini \u00e7alma konusunda uzmanla\u015fm\u0131\u015ft\u0131.<\/p>\n<p>\u00c7o\u011fu durumda siber su\u00e7lular, yaratt\u0131klar\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 Google Play \u00fczerinden yaymak i\u00e7in, halihaz\u0131rda ma\u011faza taraf\u0131ndan onaylanm\u0131\u015f, zarars\u0131z uygulamalara k\u00fc\u00e7\u00fck k\u00f6t\u00fc ama\u00e7l\u0131 kod yerle\u015ftirirler. \u00d6rne\u011fin, Joker Truva At\u0131\u2019n\u0131n yazarlar\u0131, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 tematik duvar ka\u011f\u0131tlar\u0131 sunan bir uygulamada gizlemek i\u00e7in Kore TV dizisi <em>&lt;em&gt;Squid Game&lt;\/em&gt;<\/em>\u2018in pop\u00fclaritesinden yararland\u0131. Joker ke\u015ffedildi\u011finde, Google Play\u2019de diziyle ilgili 200\u2019den fazla uygulama bulunuyordu ve bir\u00e7o\u011fu birbirinin \u00f6zelliklerini kullan\u0131yordu. Ma\u011faza moderat\u00f6rlerinin bu t\u00fcr programlar\u0131 tararken, k\u00f6t\u00fc niyetli bir \u201cy\u00fckseltme\u201dnin gizlice ge\u00e7mesine izin vermesi \u00e7ok da \u015fa\u015f\u0131rt\u0131c\u0131 bir durum de\u011fil. Siber su\u00e7lular\u0131n s\u00fcrekli olarak istismar etmeye \u00e7al\u0131\u015ft\u0131\u011f\u0131 k\u00fc\u00e7\u00fck boyuttaki k\u00f6t\u00fc ama\u00e7l\u0131 kod yerle\u015ftirmelerinin denetim s\u0131ras\u0131nda tespit edilmesi zordur.<\/p>\n<div id=\"attachment_10579\" style=\"width: 910px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-10579\" class=\"wp-image-10579 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/03\/29105334\/mobile-malware-2021-joker.jpg\" alt=\"\" width=\"900\" height=\"900\"><p id=\"caption-attachment-10579\" class=\"wp-caption-text\">Google Play\u2019de Joker Truva At\u0131 i\u00e7eren uygulamalardan biri<\/p><\/div>\n<p>\u00a0<\/p>\n<h2>Bankac\u0131l\u0131k Truva Atlar\u0131 \u2014 Yarat\u0131c\u0131 h\u0131rs\u0131zl\u0131k<\/h2>\n<p>Birka\u00e7 y\u0131ld\u0131r bankac\u0131l\u0131k Truva Atlar\u0131 yaln\u0131zca banka hesaplar\u0131 i\u00e7in de\u011fil, ayn\u0131 zamanda internet ma\u011fazalar\u0131 ve di\u011fer dijital hizmetlerdeki hesaplar i\u00e7in de kullan\u0131l\u0131yor. Sald\u0131rganlar\u0131n 2021\u2019de ilgi alanlar\u0131 daha da geni\u015fledi: Uzmanlar\u0131m\u0131z, <em>PlayerUnknown\u2019s Battlegrounds<\/em> (PUBG) oyununun mobil s\u00fcr\u00fcm\u00fc i\u00e7in giri\u015f verilerini \u00e7alan <a href=\"https:\/\/securelist.com\/it-threat-evolution-q1-2021-mobile-statistics\/102547\/\" target=\"_blank\" rel=\"noopener\">Gamethief<\/a> k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n\u0131 ke\u015ffettiler. Bu, oyun hesaplar\u0131n\u0131 \u00e7alma konusunda uzmanla\u015fm\u0131\u015f ilk <em>mobil<\/em> Truva at\u0131d\u0131r \u2014 Birka\u00e7 y\u0131l \u00f6ncesine kadar bu t\u00fcr k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar yaln\u0131zca masa\u00fcst\u00fc bilgisayarlara \u00f6zeldi.<\/p>\n<p>Siber su\u00e7lular, yaratt\u0131klar\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n i\u015flevselli\u011fini de geli\u015ftirdiler. \u00d6rne\u011fin, Fakecalls bankac\u0131l\u0131k Truva At\u0131, kullan\u0131c\u0131, bankas\u0131yla ileti\u015fim kurmaya \u00e7al\u0131\u015ft\u0131\u011f\u0131nda aramay\u0131 durduruyor ve \u00e7a\u011fr\u0131y\u0131 sahte bir banka temsilcisinin \u00f6nceden kaydedilmi\u015f yan\u0131t\u0131yla de\u011fi\u015ftirebiliyor. Bu y\u00f6ntemle k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, kurban\u0131n\u0131n, \u00e7a\u011fr\u0131y\u0131 yan\u0131tlayan ki\u015finin bir banka \u00e7al\u0131\u015fan\u0131 oldu\u011funu d\u00fc\u015f\u00fcnmesini sa\u011fl\u0131yor.<\/p>\n<h2>Ak\u0131ll\u0131 telefonunuzu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlardan nas\u0131l korursunuz?<\/h2>\n<p>Siber su\u00e7lular olduk\u00e7a yeteneklidir ve mobil cihaz kullan\u0131c\u0131lar\u0131n\u0131 tuzaklar\u0131na d\u00fc\u015f\u00fcrmek i\u00e7in her f\u0131rsat\u0131 de\u011ferlendirirler. Bu nedenle aktivite seviyeniz ne olursa olsun, dikkatli olmakta fayda var.<\/p>\n<ul>\n<li>Uygulamalar\u0131 yaln\u0131zca resmi kaynaklardan indirin. Bu %100 g\u00fcvenlik sa\u011flamaz ancak resmi ma\u011fazalarda \u00e7ok daha az k\u00f6t\u00fc ama\u00e7l\u0131 program bulunur ve k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m denetimden ge\u00e7se bile genellikle g\u00f6rece olarak daha h\u0131zl\u0131 bir \u015fekilde ma\u011fazadan kald\u0131r\u0131l\u0131r.<\/li>\n<li>K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlarla kar\u015f\u0131la\u015fma olas\u0131l\u0131\u011f\u0131n\u0131 en aza indirmek i\u00e7in, m\u00fcmk\u00fcnse iyi bilinen, g\u00fcvenilir geli\u015ftiricilerin uygulamalar\u0131n\u0131 kullan\u0131n.<\/li>\n<li>Hi\u00e7 duymad\u0131\u011f\u0131n\u0131z \u00f6demeler veya a\u015f\u0131r\u0131 c\u00f6mert hediyeler vaat eden uygulamalara itibar etmeyin. Hemen hemen hepsi doland\u0131r\u0131c\u0131l\u0131kla sonu\u00e7lan\u0131r.<\/li>\n<li>Uygulamalara, \u00e7al\u0131\u015fmas\u0131 i\u00e7in ihtiya\u00e7 duymad\u0131\u011f\u0131 izinleri vermeyin. K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n \u00e7o\u011fu, \u00f6rne\u011fin Eri\u015filebilirlik \u00f6zelliklerine eri\u015fim, k\u0131sa mesajlara eri\u015fim ve <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/unknown-apps-android\/10015\/\" target=\"_blank\" rel=\"noopener\">bilinmeyen uygulamalar\u0131n y\u00fcklenmesi<\/a> gibi potansiyel <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/five-permissions-android-games-do-not-need\/8662\/\" target=\"_blank\" rel=\"noopener\">tehlikeli izinler<\/a> olmadan tam olarak da\u011f\u0131t\u0131lamaz.<\/li>\n<li>Telefonunuza girmeye \u00e7al\u0131\u015fan k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 tespit edip, engelleyecek g\u00fcvenilir bir\u00a0<a href=\"https:\/\/www.kaspersky.com.tr\/mobile-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____c8090141bf3f79f6\" target=\"_blank\" rel=\"noopener\">mobil antivir\u00fcs<\/a> kullan\u0131n.<\/li>\n<\/ul>\n<p><strong><input type=\"hidden\" class=\"category_for_banner\" value=\"android-malware\"><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>2020&#8217;ye k\u0131yasla 2021&#8217;de ak\u0131ll\u0131 telefon ve tabletlere daha az sald\u0131r\u0131 ger\u00e7ekle\u015ftirildi. Ancak bu rahatlamak i\u00e7in yeterli de\u011fil; nedenini yaz\u0131m\u0131zda a\u00e7\u0131kl\u0131yoruz.<\/p>\n","protected":false},"author":2477,"featured_media":10578,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[105,183,728,2401,1986],"class_list":{"0":"post-10577","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-android","9":"tag-google-play","10":"tag-kotu-amacli-yazilim","11":"tag-triada","12":"tag-truva-atlari"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/mobile-malware-2021\/10577\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/mobile-malware-2021\/23989\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/mobile-malware-2021\/19476\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/mobile-malware-2021\/9828\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/mobile-malware-2021\/26294\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/mobile-malware-2021\/24252\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/mobile-malware-2021\/27018\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/mobile-malware-2021\/26563\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/mobile-malware-2021\/32991\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/mobile-malware-2021\/43996\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/mobile-malware-2021\/18667\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/mobile-malware-2021\/19221\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/mobile-malware-2021\/15877\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/mobile-malware-2021\/28366\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/mobile-malware-2021\/28170\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/mobile-malware-2021\/24898\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/mobile-malware-2021\/30334\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/mobile-malware-2021\/30106\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/android\/","name":"android"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2477"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=10577"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10577\/revisions"}],"predecessor-version":[{"id":10580,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10577\/revisions\/10580"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/10578"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=10577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=10577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=10577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}