{"id":10764,"date":"2022-06-09T22:41:01","date_gmt":"2022-06-09T19:41:01","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=10764"},"modified":"2022-06-09T22:41:01","modified_gmt":"2022-06-09T19:41:01","slug":"windealer-man-on-the-side","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/windealer-man-on-the-side\/10764\/","title":{"rendered":"WinDealer: S\u0131rad\u0131\u015f\u0131 bir \u015fekilde da\u011f\u0131t\u0131lan casus yaz\u0131l\u0131m"},"content":{"rendered":"<p>Kaspersky uzmanlar\u0131 LuoYu APT grubu taraf\u0131ndan yarat\u0131lan WinDealer k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n\u0131 <a href=\"https:\/\/securelist.com\/windealer-dealing-on-the-side\/105946\/\" target=\"_blank\" rel=\"noopener\">inceledi<\/a>. En ilgi \u00e7ekici bulgu, sald\u0131rganlar\u0131n man-on-the-side sald\u0131r\u0131 y\u00f6nteminde uzmanla\u015fm\u0131\u015f olmas\u0131 ve bunu hem k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 yaymak hem de vir\u00fcsl\u00fc bilgisayarlar\u0131 kontrol etmek i\u00e7in ba\u015far\u0131yla kullanmalar\u0131yd\u0131.<\/p>\n<h2>Man-on-the-side sald\u0131r\u0131s\u0131 nedir? WinDealer operat\u00f6rleri taraf\u0131ndan nas\u0131l kullan\u0131l\u0131r?<\/h2>\n<p>Man-on-the-side sald\u0131r\u0131s\u0131, sald\u0131rgan\u0131n bir \u015fekilde ileti\u015fim kanal\u0131n\u0131 kontrol etti\u011fi ve bu sayede trafi\u011fi okuyup normal veri al\u0131\u015fveri\u015finin aras\u0131na rastgele mesajlar ekleyebildi\u011fi anlam\u0131na gelir.<\/p>\n<p>Bir \u00f6rnek verelim: Sald\u0131rganlar tamamen me\u015fru bir yaz\u0131l\u0131m\u0131n g\u00fcncelleme talebine m\u00fcdahale ederek g\u00fcncelleme dosyas\u0131n\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 bir dosyayla de\u011fi\u015ftiriyor. G\u00f6r\u00fcn\u00fc\u015fe g\u00f6re WinDealer da bu \u015fekilde yay\u0131l\u0131yor.<\/p>\n<p>Sald\u0131rganlar benzer bir hileyle vir\u00fcsl\u00fc bilgisayardaki k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131ma komut g\u00f6nderiyor. K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, g\u00fcvenlik ara\u015ft\u0131rmac\u0131lar\u0131n\u0131n C&amp;C sunucusunu bulmas\u0131n\u0131 zorla\u015ft\u0131rmak i\u00e7in tam adresini i\u00e7ermiyor. Bunun yerine \u00f6nceden tan\u0131mlanm\u0131\u015f bir aral\u0131k i\u00e7inden rastgele bir IP adresine eri\u015fmeye \u00e7al\u0131\u015f\u0131yor. Ard\u0131ndan sald\u0131rganlar talebe m\u00fcdahale ediyor ve yan\u0131t veriyor. WinDealer bazen olmayan adreslere de eri\u015fmeye \u00e7al\u0131\u015f\u0131yor, fakat man-on-the-side y\u00f6ntemi sayesinde yine de bir yan\u0131t al\u0131yor.<\/p>\n<p>Uzmanlar\u0131m\u0131za g\u00f6re bu hileyi ba\u015far\u0131l\u0131 \u015fekilde kullanabilmek i\u00e7in sald\u0131rganlar\u0131n t\u00fcm alt a\u011f\u0131n y\u00f6nlendiricilerine s\u00fcrekli eri\u015fime ya da internet sa\u011flay\u0131c\u0131 d\u00fczeyinde baz\u0131 geli\u015fmi\u015f ara\u00e7lara ihtiyac\u0131 var.<\/p>\n<h2>WinDealer kimleri hedef al\u0131yor?<\/h2>\n<p>WinDealer\u2019\u0131n hedeflerinin b\u00fcy\u00fck \u00e7o\u011funlu\u011fu \u00c7in\u2019de bulunan yabanc\u0131 diplomasi kurulu\u015flar\u0131, akademi d\u00fcnyas\u0131n\u0131n \u00fcyeleri ya da savunma, lojistik ve telekom\u00fcnikasyon alanlar\u0131ndan \u015firketler. Ne var ki LuoYu APT grubu bazen Avusturya, \u00c7ek Cumhuriyeti, Almanya, Hindistan, Rusya ve ABD gibi ba\u015fka \u00fclkelerdeki hedeflere de sald\u0131r\u0131yor. Son zamanlarda di\u011fer Do\u011fu Asya \u00fclkeleriyle ve bunlar\u0131n \u00c7in\u2019deki ofisleriyle de daha fazla ilgilenmeye ba\u015flad\u0131lar.<\/p>\n<h2>WinDealer neler yapabilir?<\/h2>\n<p>Hem k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n hem de da\u011f\u0131t\u0131m mekanizmas\u0131n\u0131n ayr\u0131nt\u0131l\u0131 teknik analizini <a href=\"https:\/\/securelist.com\/windealer-dealing-on-the-side\/105946\/\" target=\"_blank\" rel=\"noopener\">Securelist blogundaki yaz\u0131da<\/a> bulabilirsiniz. \u00d6zetlemek gerekirse WinDealer modern bir casus yaz\u0131l\u0131m\u0131n i\u015flevlerine sahip. \u015eunlar\u0131 yapabiliyor:<\/p>\n<ul>\n<li>Dosyalar\u0131 ve dosya sistemlerini manip\u00fcle edebiliyor (dosyalar\u0131 a\u00e7abiliyor, yazabiliyor ve silebiliyor, dizinler ve diskler hakk\u0131nda veri toplayabiliyor);<\/li>\n<li>Donan\u0131m, a\u011f yap\u0131land\u0131rmas\u0131, i\u015flemler, klavye d\u00fczeni ve y\u00fckl\u00fc uygulamalar hakk\u0131nda bilgi toplayabiliyor;<\/li>\n<li>Rastgele dosya indirip y\u00fckleyebiliyor;<\/li>\n<li>Rastgele komut y\u00fcr\u00fctebiliyor;<\/li>\n<li>Metin dosyalar\u0131 ve MS Office belgeleri i\u00e7inde arama yapabiliyor;<\/li>\n<li>Ekran g\u00f6r\u00fcnt\u00fcs\u00fc alabiliyor;<\/li>\n<li>Yerel a\u011f\u0131 tarayabiliyor;<\/li>\n<li>Arka kap\u0131 fonksiyonunu destekliyor;<\/li>\n<li>Uygun Wi-Fi a\u011flar\u0131 hakk\u0131nda veri toplayabiliyor (uzmanlar\u0131m\u0131z\u0131n buldu\u011fu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m s\u00fcr\u00fcmlerinden en az biri bunu yapabiliyor).<\/li>\n<\/ul>\n<h2>Kendinizi koruman\u0131n yollar\u0131<\/h2>\n<p>Ne yaz\u0131k ki man-on-the-side sald\u0131r\u0131lar\u0131na kar\u015f\u0131 a\u011f d\u00fczeyinde korunmak \u00e7ok zor. Teorik olarak s\u00fcrekli bir VPN ba\u011flant\u0131s\u0131n\u0131n yard\u0131m\u0131 olabiliyor, fakat bu her zaman m\u00fcmk\u00fcn olmuyor. Bu y\u00fczden casus yaz\u0131l\u0131m bula\u015fma riskini ortadan kald\u0131rmak i\u00e7in internet eri\u015fimi olan t\u00fcm cihazlarda <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">g\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> olmas\u0131 gerekiyor. Buna ek olarak, <a href=\"https:\/\/www.kaspersky.com.tr\/enterprise-security\/endpoint-detection-response-edr?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">EDR s\u0131n\u0131f\u0131 \u00e7\u00f6z\u00fcmler<\/a> de anormalliklerin tespit edilmesine ve sald\u0131r\u0131lar\u0131n erken a\u015famalarda durdurulmas\u0131na yard\u0131mc\u0131 olabiliyor.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial-leadgen\">\n","protected":false},"excerpt":{"rendered":"<p>Uzmanlar\u0131m\u0131z LuoYu APT grubu taraf\u0131ndan yarat\u0131lan WinDealer k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n\u0131 inceledi.<\/p>\n","protected":false},"author":2581,"featured_media":10765,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[493,2556,2555],"class_list":{"0":"post-10764","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-apt","10":"tag-casus-yazilimlar","11":"tag-man-on-the-side"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/windealer-man-on-the-side\/10764\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/windealer-man-on-the-side\/24255\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/windealer-man-on-the-side\/19738\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/windealer-man-on-the-side\/9953\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/windealer-man-on-the-side\/26583\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/windealer-man-on-the-side\/24541\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/windealer-man-on-the-side\/24893\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/windealer-man-on-the-side\/27257\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/windealer-man-on-the-side\/33313\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/windealer-man-on-the-side\/44518\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/windealer-man-on-the-side\/19007\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/windealer-man-on-the-side\/19555\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/windealer-man-on-the-side\/28853\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/windealer-man-on-the-side\/32549\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/windealer-man-on-the-side\/25100\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/windealer-man-on-the-side\/30617\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/windealer-man-on-the-side\/30366\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/apt\/","name":"APT"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10764","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=10764"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10764\/revisions"}],"predecessor-version":[{"id":10766,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10764\/revisions\/10766"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/10765"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=10764"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=10764"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=10764"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}