{"id":11034,"date":"2022-09-19T10:25:32","date_gmt":"2022-09-19T07:25:32","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=11034"},"modified":"2022-09-19T10:25:32","modified_gmt":"2022-09-19T07:25:32","slug":"redline-stealer-self-propagates-on-youtube","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/redline-stealer-self-propagates-on-youtube\/11034\/","title":{"rendered":"YouTube kanal\u0131n\u0131zdaki oyun hileleri videosu nereden geldi?"},"content":{"rendered":"<p>D\u00fcnya genelinde 3,2 milyarl\u0131k g\u00fc\u00e7l\u00fc bir kitleye sahip video oyun pazar\u0131, her t\u00fcrl\u00fc i\u015f kolunun ilgisini \u00e7ekiyor. Zamanla b\u00f6ylesine bir kitlenin oyuncular\u0131na \u00f6zel her t\u00fcrl\u00fc bilgisayar cihaz\u0131n\u0131n tasarlanmas\u0131 beklenen bir \u015fey olsa da, durum bununla s\u0131n\u0131rl\u0131 kalmad\u0131. G\u00fcn\u00fcm\u00fczde art\u0131k \u201coyun\u201d ad\u0131yla ba\u015flayan her t\u00fcrden \u00fcr\u00fcnle kar\u015f\u0131la\u015fabilirsiniz: Oyun mobilyalar\u0131, oyun i\u00e7ecekleri, vs. Durum b\u00f6yleyken siber su\u00e7lular\u0131n da bo\u015f durmas\u0131 beklenir mi?<\/p>\n<p>Tutkulu insanlar olan oyuncular\u0131n hobilerine olan d\u00fc\u015fk\u00fcnl\u00fc\u011f\u00fc, onlar\u0131 iyi tasarlanm\u0131\u015f sosyal m\u00fchendislik faaliyetlerinin hedefi haline getiriyor. Bunlar aras\u0131nda Google Play\u2019de olmayan <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/fortnite-security\/5222\/\" target=\"_blank\" rel=\"noopener\">bir oyunun Android s\u00fcr\u00fcm\u00fcn\u00fc<\/a> veya \u00fccretli bir <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/free-smartphone-games\/8916\/\" target=\"_blank\" rel=\"noopener\">oyunu \u00fccretsiz oynama<\/a> \u015fans\u0131 sunmak gibi faaliyetler yer alabilir. Oyun d\u00fcnyas\u0131nda korsanl\u0131k, hile gibi eylemlerin yer ald\u0131\u011f\u0131 ve ele ge\u00e7irilmi\u015f hesaplar\u0131 satan karanl\u0131k web forumlar\u0131n da olmas\u0131 adeta sald\u0131rganlara istedikleri eylemleri ger\u00e7ekle\u015ftirebilecekleri geni\u015f bir tuval sunuyor.<\/p>\n<p>Oyuncu av sezonu ba\u015flad\u0131: Siber su\u00e7lular; hesap, kart numaras\u0131 ve kripto c\u00fczdan dahil eri\u015febilecekleri her \u015feyi \u00e7almak amac\u0131yla oyun hilesi payla\u015f\u0131yor kisvesi alt\u0131nda RedLine <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/psw-trojans-password-stealing-trojans\/\" target=\"_blank\" rel=\"noopener\">Truva at\u0131 h\u0131rs\u0131z\u0131n\u0131<\/a> yay\u0131yor.<\/p>\n<h2>YouTube\u2019da izleyin: Oyun hilesi gibi g\u00f6r\u00fcnen Truva at\u0131<\/h2>\n<p>Ayr\u0131nt\u0131lar\u0131n\u0131 <a href=\"https:\/\/securelist.com\/self-spreading-stealer-attacks-gamers-via-youtube\/107407\/\" target=\"_blank\" rel=\"noopener\">Securelist g\u00f6nderimizde<\/a> de payla\u015ft\u0131\u011f\u0131m\u0131z Kaspersky\u2019nin son ke\u015ffi temelde \u015fu \u015fekilde \u00e7al\u0131\u015f\u0131yor: Sald\u0131rganlar, Rust, FIFA 22, DayZ gibi pop\u00fcler \u00e7evrimi\u00e7i oyunlarda nas\u0131l hile kullan\u0131laca\u011f\u0131n\u0131 payla\u015ft\u0131klar\u0131n\u0131 iddia ettikleri videolar\u0131 Youtube\u2019da payla\u015f\u0131r. Olduk\u00e7a inand\u0131r\u0131c\u0131 g\u00f6r\u00fcnen bu videolar, <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/malware-like-cheats\/6687\/\" target=\"_blank\" rel=\"noopener\">hile yapmaya a\u015fina olan oyuncular\u0131<\/a> video a\u00e7\u0131klamalar\u0131ndaki bir ba\u011flant\u0131ya t\u0131klay\u0131p kendili\u011finden a\u00e7\u0131lan bir ar\u015fivi indirmeleri ve \u00e7al\u0131\u015ft\u0131rmalar\u0131 gibi h\u0131zl\u0131 eylemler almaya y\u00f6nlendirir.<\/p>\n<p>Videonun yarat\u0131c\u0131lar\u0131, indirmenin ba\u015far\u0131s\u0131z olmas\u0131 durumunda ise oyunculara Microsoft Edge kullan\u0131c\u0131lar\u0131n\u0131 kimlik av\u0131 ve k\u00f6t\u00fc ama\u00e7l\u0131 sitelere kar\u015f\u0131 koruyan bir filtre olan Windows SmartScreen\u2019i devre d\u0131\u015f\u0131 b\u0131rakmalar\u0131n\u0131 tavsiye eder. Ancak ayn\u0131 yarat\u0131c\u0131lar, nedense bu i\u015flemi yapan kullan\u0131c\u0131lar\u0131n bilgisayarlar\u0131na bir anda k\u00f6t\u00fc ama\u00e7l\u0131 bir yaz\u0131l\u0131m paketi y\u00fcklenece\u011finden bahsetmez.<\/p>\n<p>Hile yapmak i\u00e7in bu i\u015flemi yapan \u015fanss\u0131z oyuncu, \u00f6ncelikle taray\u0131c\u0131lardaki kay\u0131tl\u0131 parolalardan ba\u015flayarak bilgisayardaki neredeyse her t\u00fcrl\u00fc de\u011ferli bilgiyi \u00e7alan RedLine Truva at\u0131 h\u0131rs\u0131z\u0131yla kar\u015f\u0131la\u015f\u0131r. Ayr\u0131ca RedLine, bilgisayardaki komutlar\u0131 \u00e7al\u0131\u015ft\u0131r\u0131p vir\u00fcsl\u00fc cihaza ba\u015fka program da indirip y\u00fckleyebilir. Yani k\u00f6t\u00fc niyetli bir g\u00f6revi tek ba\u015f\u0131na ger\u00e7ekle\u015ftiremezse, arkada\u015flar\u0131ndan destek alabilir.<\/p>\n<p>Kurban\u0131n indirdi\u011fi RedLine h\u0131rs\u0131z\u0131, bilgisayar\u0131na da\u011f\u0131t\u0131lacak bir kripto para madencili\u011fi yaz\u0131l\u0131m\u0131 ile birlikte gelir. Oyun bilgisayarlar\u0131, kripto para madencili\u011finde yayg\u0131n olarak faydalan\u0131lan g\u00fc\u00e7l\u00fc GPU\u2019lara sahip olduklar\u0131ndan, siber su\u00e7lular i\u00e7in uygun bir hedef haline geliyor.<\/p>\n<h2>Hile kullanman\u0131n bedeli<\/h2>\n<p>Ger\u00e7ek hile kullanan oyuncular oyun moderat\u00f6rleri taraf\u0131ndan yasaklanabilir. Ancak sahte bir hile indirip bilgisayar\u0131na y\u00fckleyen kullan\u0131c\u0131lar \u00e7ok daha k\u00f6t\u00fc sorunlarla kar\u015f\u0131la\u015fabilir.<\/p>\n<p>Oyun hilesi gibi g\u00f6r\u00fcnen ve indirilip kurulan RedLine h\u0131rs\u0131z\u0131n\u0131n \u00f6ncelikli amac\u0131 bilgisayardaki de\u011ferli her \u015feyi \u00e7almaya \u00e7al\u0131\u015fmakt\u0131r. Bu de\u011ferli \u015feyler ba\u015fta \u015funlar\u0131 i\u00e7erir:<\/p>\n<ul>\n<li>Hesap parolalar\u0131,<\/li>\n<li>Kart numaralar\u0131,<\/li>\n<li>Hesaplara parolas\u0131z bir \u015fekilde giri\u015f yapmay\u0131 sa\u011flayan oturum \u00e7erezleri,<\/li>\n<li>Kripto c\u00fczdan anahtarlar\u0131,<\/li>\n<li>Mesajla\u015fma uygulamalar\u0131 sohbet ge\u00e7mi\u015fi.<\/li>\n<\/ul>\n<p>\u0130kinci olarak, RedLine ile birlikte gelen kripto madencili\u011fi yaz\u0131l\u0131m\u0131 a\u015fa\u011f\u0131daki \u00f6zel etkilerin g\u00f6r\u00fcnmesine neden olur:<\/p>\n<ul>\n<li>Bilgisayar yava\u015flamas\u0131,<\/li>\n<li>GPU a\u015f\u0131nmas\u0131 ve eskimesi,<\/li>\n<li>Daha y\u00fcksek elektrik faturalar\u0131.<\/li>\n<\/ul>\n<p>Ancak Redline h\u0131rs\u0131z\u0131n\u0131n yapt\u0131klar\u0131 bunlarla da s\u0131n\u0131r de\u011fil. Komuta ve kontrol sunucusu \u00fczerinden video indirerek bu videolar\u0131 kurban\u0131n YouTube kanal\u0131nda da yay\u0131nlar. Dolay\u0131s\u0131yla bu etkilere, \u00f6deme yapan kullan\u0131c\u0131n\u0131n itibar\u0131n\u0131 zedeleme riskini de ekleyebiliriz. Bu videolar, kurban\u0131n da indirme i\u015flemini yapt\u0131\u011f\u0131 \u2018kendi kendine a\u00e7\u0131lan ar\u015fivi indirin ve y\u00fcr\u00fct\u00fcn\u2019 a\u00e7\u0131klamas\u0131n\u0131n yer ald\u0131\u011f\u0131 hile videolar\u0131n\u0131n ayn\u0131s\u0131. B\u00f6ylece d\u00f6ng\u00fc s\u0131radaki kurban\u0131 ile devam eder. Dolay\u0131s\u0131yla, otomatik olarak yay\u0131lmaya devam eden Truva at\u0131, bu s\u00fcre\u00e7te ne yapt\u0131\u011f\u0131ndan habersiz daha fazla savunucuya ula\u015f\u0131r.<\/p>\n<p>Bu arada, RedLine distrib\u00fct\u00f6rleri daha \u00f6nce olduk\u00e7a benzer bir teknik kullanarak k\u00f6t\u00fc ama\u00e7l\u0131 bir yaz\u0131l\u0131m y\u00fckleyicisini bir Windows 11 g\u00fcncellemesi veya oyuncular aras\u0131nda pop\u00fcler bir platform olan Discord i\u00e7in <a href=\"https:\/\/threatresearch.ext.hp.com\/redline-stealer-disguised-as-a-windows-11-upgrade\/\" target=\"_blank\" rel=\"noopener nofollow\">bir y\u00fckleyici olarak g\u00f6stermeye de \u00e7al\u0131\u015ft\u0131lar<\/a>.<\/p>\n<h2>Kendinizi koruman\u0131n yollar\u0131<\/h2>\n<p>\u00d6nce malumun ilam\u0131yla ba\u015flayal\u0131m: Hile indirmeyin. Hile indirmek, etik olmad\u0131\u011f\u0131 kadar tehlikelidir de. Hile yapmak, oyun geli\u015ftiricisiyle yapt\u0131\u011f\u0131n\u0131z kullan\u0131c\u0131 s\u00f6zle\u015fmesini ihlal ederek otomatik olarak gri b\u00f6lgeye al\u0131nman\u0131za neden olur. Ayr\u0131ca bu hileler, hi\u00e7bir zaman g\u00fcvenli ve resmi kanallar arac\u0131l\u0131\u011f\u0131yla da\u011f\u0131t\u0131lmazlar. Resmi olmayan ve do\u011frulanmam\u0131\u015f kaynaklardan bir \u015fey indirdi\u011finizde ise, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlarla kar\u015f\u0131la\u015fma olas\u0131l\u0131\u011f\u0131n\u0131z her zaman daha fazlad\u0131r.<\/p>\n<p>Bu nedenle, m\u00fcmk\u00fcn olan her yerde iki fakt\u00f6rl\u00fc kimlik do\u011frulamay\u0131 etkinle\u015ftirmenizi \u00f6neririz. B\u00f6ylece, k\u00f6t\u00fc ama\u00e7l\u0131 bir yaz\u0131l\u0131m bilgisayar\u0131n\u0131za s\u0131zmay\u0131 ba\u015farsa ve \u00f6nemli parolalar\u0131n\u0131z\u0131 \u00e7alsa bile onlar\u0131 kullanamaz.<\/p>\n<p>Ancak yine de, taray\u0131c\u0131 filtreleme gibi koruma \u00f6zelliklerine sahip <a href=\"https:\/\/www.kaspersky.com.tr\/advert\/security-cloud?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____ksc___\" target=\"_blank\" rel=\"noopener\">g\u00fcvenli bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> kullan\u0131n ve asla devre d\u0131\u015f\u0131 b\u0131rakmay\u0131n. Antivir\u00fcs programlar\u0131n\u0131n s\u0131kl\u0131kla ger\u00e7ek hilelerin kurulumunu bile engellemesi onlar\u0131n da k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlarla bir\u00e7ok ortak noktas\u0131 oldu\u011funu g\u00f6steriyor. Hile geli\u015ftiricilerinin kurbanlar\u0131n\u0131 antivir\u00fcs programlar\u0131n\u0131 devre d\u0131\u015f\u0131 b\u0131rakmaya te\u015fvik etmesinin nedeni de bu. Bunu hi\u00e7bir ko\u015fulda yapmamal\u0131s\u0131n\u0131z. \u00c7\u00fcnk\u00fc koruman\u0131z\u0131 devre d\u0131\u015f\u0131 b\u0131rakt\u0131\u011f\u0131n\u0131z anda sizi hi\u00e7bir \u015fey koruyamaz.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksc-gaming\">\n","protected":false},"excerpt":{"rendered":"<p>RedLine Truva at\u0131 h\u0131rs\u0131z\u0131, pop\u00fcler oyunlar i\u00e7in hile sunma ad\u0131 alt\u0131nda yay\u0131larak videolar\u0131n a\u00e7\u0131klama k\u0131sm\u0131nda kendi ba\u011flant\u0131s\u0131n\u0131 ekleyip kurbanlar\u0131n\u0131n YouTube kanallar\u0131nda video yay\u0131nl\u0131yor.<\/p>\n","protected":false},"author":696,"featured_media":11035,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1351],"tags":[585,2583,2582,1986],"class_list":{"0":"post-11034","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-oyuncular","10":"tag-parola-hirsizi","11":"tag-redline","12":"tag-truva-atlari"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/redline-stealer-self-propagates-on-youtube\/11034\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/redline-stealer-self-propagates-on-youtube\/24588\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/redline-stealer-self-propagates-on-youtube\/20054\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/redline-stealer-self-propagates-on-youtube\/10101\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/redline-stealer-self-propagates-on-youtube\/27046\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/redline-stealer-self-propagates-on-youtube\/24945\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/redline-stealer-self-propagates-on-youtube\/25309\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/redline-stealer-self-propagates-on-youtube\/27664\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/redline-stealer-self-propagates-on-youtube\/27225\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/redline-stealer-self-propagates-on-youtube\/33995\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/redline-stealer-self-propagates-on-youtube\/45528\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/redline-stealer-self-propagates-on-youtube\/19474\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/redline-stealer-self-propagates-on-youtube\/20057\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/redline-stealer-self-propagates-on-youtube\/29300\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/redline-stealer-self-propagates-on-youtube\/28488\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/redline-stealer-self-propagates-on-youtube\/25462\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/redline-stealer-self-propagates-on-youtube\/30995\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/redline-stealer-self-propagates-on-youtube\/30690\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/oyuncular\/","name":"oyuncular"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/696"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=11034"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11034\/revisions"}],"predecessor-version":[{"id":11036,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11034\/revisions\/11036"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/11035"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=11034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=11034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=11034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}