{"id":11060,"date":"2022-09-27T11:10:11","date_gmt":"2022-09-27T08:10:11","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=11060"},"modified":"2022-09-27T11:10:11","modified_gmt":"2022-09-27T08:10:11","slug":"agent-tesla-spam-mailout","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/agent-tesla-spam-mailout\/11060\/","title":{"rendered":"\u0130\u015fletmelere g\u00f6nderilen spam e-postalar\u0131nda parola \u00e7alma Truva at\u0131 h\u0131rs\u0131z\u0131 tespit edildi"},"content":{"rendered":"<p>Agent Tesla casus yaz\u0131l\u0131m eklerini kullanan ve \u015firket \u00e7al\u0131\u015fanlar\u0131n\u0131 hedefleyen yeni bir k\u00f6t\u00fc ama\u00e7l\u0131 toplu posta kampanyas\u0131na tan\u0131kl\u0131k ediyoruz. Sald\u0131rganlar bu kez e-postalar\u0131 olu\u015ftururken ayr\u0131nt\u0131lara \u00f6zel bir \u00f6nem g\u00f6steriyor. B\u00f6ylece sald\u0131rganlar\u0131n haz\u0131rlad\u0131klar\u0131 e-postalar\u0131, ekli belgelere sahip s\u0131radan i\u015f e-postalardan sanan \u00e7al\u0131\u015fanlar tuza\u011fa d\u00fc\u015febilir. As\u0131l ama\u00e7lar\u0131, al\u0131c\u0131n\u0131n tuza\u011fa d\u00fc\u015ferek ekli ar\u015fivi a\u00e7mas\u0131n\u0131 ve daha sonra k\u00f6t\u00fc ama\u00e7l\u0131 dosyay\u0131 \u00e7al\u0131\u015ft\u0131rmas\u0131n\u0131 sa\u011flamak.<\/p>\n<h2>Bu k\u00f6t\u00fc ama\u00e7l\u0131 e-postay\u0131 di\u011ferlerinden ay\u0131ran \u015fey ne?<\/h2>\n<p>\u0130lk olarak, siber su\u00e7lular ger\u00e7ek \u015firketleri bir maske olarak kullan\u0131yor. E-posta iletilerine ger\u00e7ek logolar ve yasal g\u00f6r\u00fcnen imzalar ekliyorlar. \u0130ngilizceleri m\u00fckemmelli\u011fin yan\u0131ndan bile ge\u00e7miyor. Bu y\u00fczden, daha az \u015f\u00fcphe uyand\u0131rmak i\u00e7in ana dili \u0130ngilizce olmayan \u00fclkelerde (Bulgaristan veya Malezya gibi) ya\u015f\u0131yor gibi davran\u0131yorlar.<\/p>\n<p>Sald\u0131rganlar, metni duruma uygun \u015fekilde de\u011fi\u015ftirerek bir\u00e7ok \u015firket ad\u0131na k\u00f6t\u00fc ama\u00e7l\u0131 ar\u015fivlerini g\u00f6nderiyor. \u015eirket \u00e7al\u0131\u015fanlar\u0131na bazen ekte g\u00f6nderdikleri ar\u015fivde yer alma ihtimali olan baz\u0131 \u00fcr\u00fcnlerin fiyatlar\u0131n\u0131, bazen de listelenmi\u015f bir \u00fcr\u00fcn\u00fcn stokta olup olmad\u0131\u011f\u0131n\u0131 soruyorlar. B\u00fcy\u00fck ihtimalle, kurbanlar\u0131n\u0131 kand\u0131rmak i\u00e7in kulland\u0131klar\u0131 metnin t\u00fcm versiyonlar\u0131n\u0131 hen\u00fcz g\u00f6rmedik bile. Buradaki ama\u00e7, e-posta al\u0131c\u0131s\u0131n\u0131, bu sahte m\u00fc\u015fterinin ilgilendi\u011fi \u00fcr\u00fcn t\u00fcrlerini kontrol etmeye ikna etmek. Siber su\u00e7lular, haz\u0131rl\u0131k a\u015famas\u0131nda \u00e7ok \u00e7aba sarf etmi\u015fler, bu genellikle bu tarz toplu posta kampanyalar\u0131nda yapt\u0131klar\u0131 bir \u015fey de\u011fil. Daha \u00f6nce bu t\u00fcr tekniklere sadece hedefli sald\u0131r\u0131larda ba\u015fvurduklar\u0131n\u0131 g\u00f6rm\u00fc\u015ft\u00fck.<\/p>\n<div id=\"attachment_11062\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-11062\" class=\"wp-image-11062 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/09\/27110738\/agent-tesla-spam-mailout-letter-1024x462.jpg\" alt=\"\" width=\"1024\" height=\"462\"><p id=\"caption-attachment-11062\" class=\"wp-caption-text\">Ekte Ajan Tesla bulunan bir mail \u00f6rne\u011fi.<\/p><\/div>\n<p>\u00a0<\/p>\n<p>E-posta al\u0131c\u0131lar\u0131n\u0131n g\u00f6zleriyle fark edebilecekleri tek tehlike i\u015fareti var: g\u00f6nderenin adresi. Alan ad\u0131, \u015firketin alan ad\u0131yla nadiren e\u015fle\u015fiyor. G\u00f6nderenin ad\u0131 ise, yasal i\u015f adreslerinde pek de rastlanmayan imzadaki addan farkl\u0131. Yukar\u0131daki \u00f6rnekte, e-posta \u201cnewsletter@\u201d adresinden g\u00f6nderilmi\u015f. Bir pazarlama e-postas\u0131 d\u00fc\u015f\u00fcn\u00fcld\u00fc\u011f\u00fcnde normal olabilir, ancak fiyat teklifi talebi i\u00e7eren bir e-posta i\u00e7in kesinlikle ola\u011fand\u0131\u015f\u0131.<\/p>\n<h2>Agent Tesla truva at\u0131 nedir?<\/h2>\n<p>\u00c7\u00f6z\u00fcmlerimizin Trojan-PSW.MSIL.Agensla tan\u0131mlad\u0131\u011f\u0131 Agent Tesla, gizli bilgileri \u00e7al\u0131p sald\u0131rgan operat\u00f6rlere g\u00f6nderen olduk\u00e7a eski bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m. \u00d6ncelikle, farkl\u0131 programlarda saklanan kimlik bilgilerinin pe\u015finde: taray\u0131c\u0131lar, e-posta istemcileri, FTP\/SCP istemcileri, veritabanlar\u0131, uzaktan y\u00f6netim ara\u00e7lar\u0131, VPN uygulamalar\u0131 ve \u00e7e\u015fitli anl\u0131k mesajla\u015fma programlar\u0131. Ancak Agent Tesla, pano verilerini \u00e7alabiliyor, tu\u015f vuru\u015flar\u0131n\u0131 kaydedebiliyor ve ekran g\u00f6r\u00fcnt\u00fcs\u00fc alabiliyor.<\/p>\n<p>Agent Tesla, toplanan t\u00fcm bilgileri e-posta yoluyla sald\u0131rganlara g\u00f6nderir. Ancak, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n baz\u0131 modifikasyonlar\u0131, verileri Telegram kullanarak da aktarabilir. Ayr\u0131ca, bir internet sitesine veya FTP sunucusuna y\u00fckleyebilir.<\/p>\n<p>Bu <a href=\"https:\/\/securelist.com\/agent-tesla-malicious-spam-campaign\/107478\/\" target=\"_blank\" rel=\"noopener\">Securelist yaz\u0131s\u0131nda<\/a>, bahsetti\u011fimiz k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m ve kampanya hakk\u0131nda verilen ayr\u0131nt\u0131lar\u0131n yan\u0131 s\u0131ra g\u00fcvenli\u011fin ihlal edildi\u011fini g\u00f6steren i\u015faretleri bulabilirsiniz.<\/p>\n<h2>Kendinizi koruman\u0131n yollar\u0131<\/h2>\n<p>Asl\u0131nda en iyi \u00e7\u00f6z\u00fcm, bu t\u00fcr siber tehditlerin, k\u00f6t\u00fc ama\u00e7l\u0131 bir e-posta, kurumsal posta sunucusuna ula\u015ft\u0131\u011f\u0131nda erken bir a\u015famada durdurulmas\u0131. Bir tehdidi, \u00e7\u0131plak g\u00f6zle ilk bak\u0131\u015fta her zaman fark edemesek de, e-posta taray\u0131c\u0131lar\u0131 bu t\u00fcr g\u00f6revleri ger\u00e7ekle\u015ftirmek i\u00e7in bi\u00e7ilmi\u015f kaftan. Bu y\u00fczden, do\u011fru <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security\/mail-server?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fcyle<\/a> e-posta sunucusunu korumak iyi bir fikir.<\/p>\n<p>Bunun yan\u0131 s\u0131ra, <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">\u00e7evrimi\u00e7i \u00f6\u011frenme platformlar\u0131yla<\/a>, \u00e7al\u0131\u015fanlar\u0131n\u0131z\u0131n siber g\u00fcvenlik bilincini art\u0131rmay\u0131 da g\u00f6z \u00f6n\u00fcnde bulundurmal\u0131s\u0131n\u0131z.<\/p>\n<p>Sald\u0131rganlar\u0131n g\u00f6nderdi\u011fi k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m ne olursa olsun, \u00e7al\u0131\u015ft\u0131r\u0131lmad\u0131\u011f\u0131ndan emin olmak i\u00e7in \u00e7al\u0131\u015fanlar\u0131n\u0131z\u0131n bilgisayarlar\u0131nda <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> bulundurmay\u0131 da d\u00fc\u015f\u00fcnebilirsiniz.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial-leadgen\">\n","protected":false},"excerpt":{"rendered":"<p>Siber su\u00e7lular, \u015firketlere e-posta ekinde casus truva at\u0131 gizleyen ve m\u00fckemmele yak\u0131n taklit edilmi\u015f i\u015f e-postalar\u0131 g\u00f6nderiyor.<\/p>\n","protected":false},"author":2598,"featured_media":11061,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[2456,2204,240,1986],"class_list":{"0":"post-11060","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-e-posta-tehditleri","10":"tag-posta","11":"tag-spam","12":"tag-truva-atlari"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/agent-tesla-spam-mailout\/11060\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/agent-tesla-spam-mailout\/24662\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/agent-tesla-spam-mailout\/20120\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/agent-tesla-spam-mailout\/10154\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/agent-tesla-spam-mailout\/27108\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/agent-tesla-spam-mailout\/24996\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/agent-tesla-spam-mailout\/25326\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/agent-tesla-spam-mailout\/27738\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/agent-tesla-spam-mailout\/27246\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/agent-tesla-spam-mailout\/34025\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/agent-tesla-spam-mailout\/45621\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/agent-tesla-spam-mailout\/19517\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/agent-tesla-spam-mailout\/20076\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/agent-tesla-spam-mailout\/29318\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/agent-tesla-spam-mailout\/32685\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/agent-tesla-spam-mailout\/28508\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/agent-tesla-spam-mailout\/25482\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/agent-tesla-spam-mailout\/31056\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/agent-tesla-spam-mailout\/30755\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/e-posta-tehditleri\/","name":"e-posta tehditleri"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11060","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2598"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=11060"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11060\/revisions"}],"predecessor-version":[{"id":11064,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11060\/revisions\/11064"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/11061"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=11060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=11060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=11060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}