{"id":10642,"date":"2022-04-21T12:47:02","date_gmt":"2022-04-21T09:47:02","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=10642"},"modified":"2022-04-21T12:47:02","modified_gmt":"2022-04-21T09:47:02","slug":"qbot-emotet-spam-mailing","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/qbot-emotet-spam-mailing\/10642\/","title":{"rendered":"E-postalar\u0131 hedef alan k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m y\u00fckseli\u015fte"},"content":{"rendered":"<p>Uzmanlar\u0131m\u0131z, \u00e7e\u015fitli \u00fclkelerdeki i\u015fletmeleri hedef alan karma\u015f\u0131k k\u00f6t\u00fc ama\u00e7l\u0131 spam e-postalarda \u00f6nemli bir art\u0131\u015f tespit etti. Bu k\u00f6t\u00fc ama\u00e7l\u0131 e-postalar\u0131n say\u0131s\u0131 \u015eubat 2022\u2019de 3000 civar\u0131ndayken, bu say\u0131 Mart\u2019ta yakla\u015f\u0131k 30.000\u2019e y\u00fckseldi. \u015eimdiye kadar teknolojilerimiz \u0130ngilizce, Frans\u0131zca, Macarca, \u0130talyanca, Norve\u00e7\u00e7e, Leh\u00e7e, Rus\u00e7a, Slovence ve \u0130spanyolca dillerinde yaz\u0131lm\u0131\u015f k\u00f6t\u00fc ama\u00e7l\u0131 e-postalar tespit etti.<\/p>\n<h2>Siber su\u00e7lular kurban\u0131n cihazlar\u0131na nas\u0131l bula\u015f\u0131r?<\/h2>\n<p>Siber su\u00e7lular\u0131n, ticari konulardaki aktif e-posta konu\u015fmalar\u0131n\u0131 engelledi\u011fi ve al\u0131c\u0131 cihazlar\u0131na bankac\u0131l\u0131k truva at\u0131 bula\u015ft\u0131rmak i\u00e7in k\u00f6t\u00fc ama\u00e7l\u0131 bir dosya veya ba\u011flant\u0131 i\u00e7eren bir e-posta g\u00f6nderdi\u011fi iddia ediliyor. Bu t\u00fcr bir sald\u0131r\u0131, bu mesajlar\u0131n tespitini zorla\u015ft\u0131r\u0131r ve al\u0131c\u0131n\u0131n oyuna gelmesini kolayla\u015ft\u0131r\u0131r.<\/p>\n<p>Siber su\u00e7lular\u0131n al\u0131c\u0131lara g\u00f6nderdi\u011fi baz\u0131 e-postalar, k\u00f6t\u00fc ama\u00e7l\u0131 bir ek i\u00e7eriyor. Di\u011fer durumlarda, bilinen bir bulut bar\u0131nd\u0131rma hizmetinde bulunan bir dosyaya y\u00f6nlendiren bir ba\u011flant\u0131ya sahip. K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, genellikle e-posta metninde belirtilen parola ile \u015fifrelenmi\u015f bir ar\u015fivde yer al\u0131r. Sald\u0131rganlar, kullan\u0131c\u0131lar\u0131 eki a\u00e7maya veya ba\u011flant\u0131 arac\u0131l\u0131\u011f\u0131yla dosyay\u0131 indirmeye ikna etmek i\u00e7in genellikle bunun ticari bir teklif gibi baz\u0131 \u00f6nemli bilgiler i\u00e7erdi\u011fini belirtir.<\/p>\n<p>Uzmanlar\u0131m\u0131z, bu e-postalar\u0131n, bankac\u0131l\u0131k Truva atlar\u0131n\u0131 yaymay\u0131 ama\u00e7layan koordineli bir kampanyan\u0131n par\u00e7as\u0131 olarak g\u00f6nderildi\u011fi sonucuna vard\u0131.<\/p>\n<h2>Sald\u0131rganlar hangi k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 kullan\u0131yor ve bunlar ne kadar tehlikeli?<\/h2>\n<p>\u00c7o\u011fu durumda, kurbanlar k\u00f6t\u00fc ama\u00e7l\u0131 bir belge a\u00e7t\u0131\u011f\u0131nda, <a href=\"https:\/\/securelist.com\/qakbot-technical-analysis\/103931\/\" target=\"_blank\" rel=\"noopener\">Qbot<\/a> k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n\u0131 indirir ve ba\u015flat\u0131r, ancak uzmanlar\u0131m\u0131z bu belgelerden baz\u0131lar\u0131n\u0131n <a href=\"https:\/\/securelist.com\/emotet-modules-and-recent-attacks\/106290\/\" target=\"_blank\" rel=\"noopener\">Emotet\u2019i<\/a> indirdi\u011fini de g\u00f6zlemledi. Her iki k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m t\u00fcr\u00fc de, kullan\u0131c\u0131lar\u0131n verilerini \u00e7alma, vir\u00fcsl\u00fc bir \u015firket a\u011f\u0131ndaki verileri toplama, a\u011fda daha fazla yay\u0131lma ve di\u011fer a\u011f cihazlar\u0131na fidye yaz\u0131l\u0131mlar\u0131 veya di\u011fer Truva atlar\u0131 y\u00fckleme yetene\u011fine sahip. Ayr\u0131ca, Qbot e-postalara eri\u015febilir ve bunlar\u0131 \u00e7alabilir.<\/p>\n<h2>Kendinizi koruman\u0131n yollar\u0131<\/h2>\n<p>Qbot ve Emotet sald\u0131r\u0131lar\u0131ndan (veya e-posta yoluyla yay\u0131lan di\u011fer k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlardan) korunmak i\u00e7in a\u015fa\u011f\u0131dakileri \u00f6neriyoruz:<\/p>\n<ul>\n<li>Posta a\u011f ge\u00e7idi d\u00fczeyinde <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security\/mail-security-appliance?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">g\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> \u00e7\u00f6z\u00fcm\u00fc y\u00fcklemek \u2014 spam ve k\u00f6t\u00fc ama\u00e7l\u0131 iletileri, son kullan\u0131c\u0131lar bir hata yapma \u015fans\u0131 bile bulamadan otomatik olarak filtreleyecek.<\/li>\n<li>\u00c7al\u0131\u015fanlara <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">temel siber g\u00fcvenlik hijyeni e\u011fitimi<\/a> vermek \u2014 onlara siber su\u00e7lu davran\u0131\u015flar\u0131n\u0131 tespit etmeyi \u00f6\u011fretebilir (\u00f6rne\u011fin, \u015fifrelenmi\u015f ar\u015fivle ayn\u0131 e-postada bulunan parolay\u0131 bilmek yaln\u0131zca bir amaca hizmet edebilir: k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mdan koruma teknolojilerini aldatmak).<\/li>\n<li>\u00c7al\u0131\u015fanlar\u0131n\u0131z\u0131n kimlik av\u0131 ve k\u00f6t\u00fc ama\u00e7l\u0131 e-postalar\u0131, ger\u00e7ek olanlardan ay\u0131rt etmelerini sa\u011flamak i\u00e7in sim\u00fcle edilmi\u015f sald\u0131r\u0131lar y\u00fcr\u00fctmek.<\/li>\n<li>\u0130nternete ba\u011fl\u0131 her u\u00e7 noktada <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> kullanmak. B\u00f6ylece \u00e7al\u0131\u015fanlar\u0131n\u0131z bir sald\u0131r\u0131ya maruz kal\u0131rsa bir dosyan\u0131n a\u00e7\u0131lmas\u0131n\u0131 veya k\u00f6t\u00fc ama\u00e7l\u0131 bir ba\u011flant\u0131n\u0131n \u00e7al\u0131\u015fmas\u0131n\u0131 engelleyebilir.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial-leadgen\">\n","protected":false},"excerpt":{"rendered":"<p>\u0130\u015fletmeleri hedefleyen k\u00f6t\u00fc ama\u00e7l\u0131 spam kampanyas\u0131 ayda 10 kat b\u00fcy\u00fcyor, Qbot ve Emotet k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n\u0131 yay\u0131yor.<\/p>\n","protected":false},"author":2704,"featured_media":10643,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194,1351],"tags":[1921,728,240],"class_list":{"0":"post-10642","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"category-threats","10":"tag-e-posta","11":"tag-kotu-amacli-yazilim","12":"tag-spam"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/qbot-emotet-spam-mailing\/10642\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/qbot-emotet-spam-mailing\/24063\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/qbot-emotet-spam-mailing\/19549\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/qbot-emotet-spam-mailing\/26390\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/qbot-emotet-spam-mailing\/24337\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/qbot-emotet-spam-mailing\/27100\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/qbot-emotet-spam-mailing\/33112\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/qbot-emotet-spam-mailing\/44144\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/qbot-emotet-spam-mailing\/18798\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/qbot-emotet-spam-mailing\/19331\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/qbot-emotet-spam-mailing\/15935\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/qbot-emotet-spam-mailing\/28493\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/qbot-emotet-spam-mailing\/24964\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/qbot-emotet-spam-mailing\/30414\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/qbot-emotet-spam-mailing\/30182\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/e-posta\/","name":"e-posta"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10642","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2704"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=10642"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10642\/revisions"}],"predecessor-version":[{"id":10644,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10642\/revisions\/10644"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/10643"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=10642"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=10642"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=10642"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}