{"id":1945,"date":"2016-03-09T07:20:46","date_gmt":"2016-03-09T12:20:46","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=1945"},"modified":"2020-02-26T18:38:33","modified_gmt":"2020-02-26T15:38:33","slug":"triada-androiddeki-organize-suc","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/triada-androiddeki-organize-suc\/1945\/","title":{"rendered":"Triada: Android&#8217;deki organize su\u00e7"},"content":{"rendered":"<p>Ordular\u0131n genellikle nas\u0131l hareket etti\u011fini bilirsiniz: \u00d6nce g\u00f6zc\u00fcler her \u015feyin yolunda oldu\u011funa emin olur. Daha sonra a\u011f\u0131r birlikler gelir. En az\u0131ndan siber sava\u015f \u00e7a\u011f\u0131ndan \u00f6nce bu b\u00f6yleydi. \u015eimdi Trojan vir\u00fcsleri bu \u015fekilde hareket ediyor.<\/p>\n<p>Bir\u00e7ok k\u00fc\u00e7\u00fck Android Trojan\u2019\u0131n\u0131n eri\u015fim yetkilerine sahip olma kabiliyeti vard\u0131r \u2013 di\u011fer bir deyi\u015fle k\u00f6k dizine eri\u015firler. Malware ara\u015ft\u0131rmac\u0131lar\u0131m\u0131zdan Nikita Buchka ve\u00a0 Mikhail Kuzin, bu t\u00fcr en az 11 Trojan t\u00fcrevi oldu\u011funu s\u00f6yl\u00fcyor. Bir\u00e7o\u011fu neredeyse zarars\u0131z \u2013 t\u00fcm yapt\u0131klar\u0131 size tonlarca rekalm g\u00f6stermek ve kendisi gibi di\u011fer vir\u00fcsleri indirmek. Bu konuda daha \u00e7ok bilgi i\u00e7in \u2013 <a href=\"https:\/\/securelist.com\/blog\/mobile\/71981\/taking-root\/\" target=\"_blank\" rel=\"noopener noreferrer\">ara\u015ft\u0131rmac\u0131lar\u0131m\u0131z\u0131n haz\u0131rlad\u0131\u011f\u0131 Securelist makalesine<\/a> g\u00f6z atabilirsiniz.<\/p>\n<p>\u00a0<br>\nOrdu \u00f6rne\u011finden devam etmek gerekirse \u2013 bunlar g\u00f6zc\u00fclerdir. Ve sizin de anlad\u0131\u011f\u0131n\u0131z gibi k\u00f6k dizine eri\u015fme yetene\u011fi bu vir\u00fcslere uygulamalar\u0131 indirme ve y\u00fckleme izni verir \u2013 bu sebeple e\u011fer herhangi bir tanesi sisteminize girerse kendisi gibi bir\u00e7o\u011funu sisteminize k\u0131sa s\u00fcre i\u00e7inde sokacakt\u0131r. Ama ara\u015ft\u0131rmac\u0131lar\u0131m\u0131z bu tarz k\u00fc\u00e7\u00fck Trojanlar\u0131n sisteme bula\u015ft\u0131\u011f\u0131 zaman kullan\u0131c\u0131ya ve verilere zarar verecek di\u011fer malware vir\u00fcslerini indireceklerini \u00f6ng\u00f6rm\u00fc\u015flerdi.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Dangerous trends taking root in <a href=\"https:\/\/twitter.com\/hashtag\/mobile?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#mobile<\/a> phones <a href=\"https:\/\/t.co\/DkLD8KhSuk\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/DkLD8KhSuk<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/research?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#research<\/a> <a href=\"http:\/\/t.co\/wc3NfSSv3Z\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/wc3NfSSv3Z<\/a><\/p>\n<p>\u2014 Securelist (@Securelist) <a href=\"https:\/\/twitter.com\/Securelist\/status\/636925849455996928?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">August 27, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Ve \u00f6ng\u00f6rd\u00fckleri son zamanlarda ger\u00e7ekle\u015fmeye ba\u015flad\u0131. Leech, Ztorg ve Gopro gibi k\u00fc\u00e7\u00fck Trojanlar, analistlerimizin \u015fimdiye kadar kar\u015f\u0131la\u015ft\u0131\u011f\u0131 en geli\u015fmi\u015f mobil Trojan vir\u00fcs\u00fcn\u00fc indirdi\u011fini tespit etti \u2013 biz de buna Triada diyoruz.<\/p>\n<p>\u00a0<br>\nTriada k\u00f6k dizini kullarak, sistem dosyalar\u0131yla yer de\u011fi\u015ftiren\u00a0 birimsel (mod\u00fcler) bir Trojand\u0131r. Genellikle cihaz\u0131n RAM\u2019inde bulunur ki bu da vir\u00fcs\u00fcn bulunmas\u0131n\u0131 son derece zorla\u015ft\u0131r\u0131r.<\/p>\n<p>\u00a0<br>\n<strong>Triada\u2019n\u0131n karanl\u0131k y\u00f6ntemleri<\/strong><br>\nBir defa sisteminize indirilip kuruldu\u011funda, Triada Trojan \u00f6nce sistem hakk\u0131nda bilgi toplamaya \u00e7al\u0131\u015f\u0131r \u2013 cihaz modeli, i\u015fletim sistemi versiyonu, SD kart kapasitesi, y\u00fckl\u00fc uygulamalar\u0131n listesini ve benzer \u015feyleri. Daha sonra bu bilgileri Y\u00f6netim &amp; Kontrol sunucusuna g\u00f6nderir. Toplamda 4 domain \u00fczerinde 17 farkl\u0131 Y\u00f6netim &amp; Kontrol sunucusu ke\u015ffettik. Bu da k\u00f6t\u00fc adamlar\u0131n muhtemelen bi\u00e7ok farkl\u0131 yola ba\u015fvurdu\u011funu g\u00f6steriyor.<\/p>\n<p>\u00a0<br>\nY\u00f6netim &amp; Kontrol sunucusu cihaz i\u00e7in ki\u015fisel kimlik numaras\u0131 ve baz\u0131 di\u011fer ayarlar\u0131 \u2013 sunucuya ba\u011flan\u0131rken ge\u00e7en s\u00fcre, y\u00fcklenecek birimlerin (mod\u00fcllerin) listesi ve di\u011fer \u015feyler i\u00e7eren bir sistem dosyas\u0131 ile cevap veriyor. Birimler y\u00fcklendikten sonra k\u0131sa s\u00fcreli belle\u011fe yay\u0131l\u0131p telefon haf\u0131zas\u0131ndan silinir. Bu da Trojan\u2019\u0131 yakalamay\u0131 daha da zorla\u015ft\u0131r\u0131r.<\/p>\n<p>\u00a0<br>\nTriada\u2019n\u0131n yakalanmas\u0131n\u0131 bu denli zorla\u015ft\u0131ran ve ara\u015ft\u0131rmac\u0131lar\u0131m\u0131z\u0131 bir hayli etkilemesinin iki sebebi daha var. \u0130lk olarak <a href=\"https:\/\/anatomyofandroid.com\/2013\/10\/15\/zygote\/\" target=\"_blank\" rel=\"noopener nofollow\">Zygote s\u00fcreci<\/a>ni de\u011fi\u015ftirir. Zygote, Android i\u015fletim sisteminin her uygulama \u015fablonuna uygulad\u0131\u011f\u0131 temel s\u00fcre\u00e7tir. Yani, Trojan Zygote\u2019a girerse cihazda \u00e7al\u0131\u015fan her uygulaman\u0131n bir par\u00e7as\u0131 haline gelir.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1947\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/03\/06014308\/triada-zygote.png\" alt=\"triada-zygote\" width=\"2536\" height=\"3304\"><\/p>\n<p>\u0130kincisi, sistem fonksiyonlar\u0131n\u0131n yerine ge\u00e7er ve sistemin birimlerini \u00e7al\u0131\u015fan s\u00fcre\u00e7lerin ve indirilen uygulamalar\u0131n listesinden gizler. B\u00f6ylelikle sistem olmamas\u0131 gereken \u00e7al\u0131\u015fan s\u00fcre\u00e7leri g\u00f6rmez ve alarm vermez.<\/p>\n<p>\u00a0<\/p>\n<p>Bunlar Triada\u2019n\u0131n etkiledi\u011fi sistem fonksiyonlar\u0131n\u0131n sadece birka\u00e7\u0131. Ara\u015ft\u0131rmac\u0131lar\u0131m\u0131z\u0131n ke\u015ffine g\u00f6re ayn\u0131 zamanda giden SMSlere el at\u0131yor ve gelenleri filtreliyor. K\u00f6t\u00fc adamlar da Trojan\u2019dan bu \u015fekilde gelir elde ediyorlar.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">A SMS <a href=\"https:\/\/twitter.com\/hashtag\/Trojan?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Trojan<\/a> Bypasses <a href=\"https:\/\/twitter.com\/hashtag\/CAPTCHA?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#CAPTCHA<\/a> and Steals Money: <a href=\"https:\/\/t.co\/9fjQ0PwZuw\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/9fjQ0PwZuw<\/a> <a href=\"http:\/\/t.co\/r5jKqQUc3y\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/r5jKqQUc3y<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/578254848203837440?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">March 18, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Baz\u0131 uygulamalar sat\u0131n alma i\u015flemi i\u00e7in SMS onay\u0131 gerektirir \u2013 al\u0131\u015fveri\u015f yap\u0131lan veri k\u0131sa mesaj ile transfer olur. Uygulama geli\u015ftiricilerin geleneksel \u0130nternet \u00f6demesi yerine SMS\u2019i se\u00e7mesinin as\u0131l nedeni SMS\u2019in internete ihtiyac\u0131n\u0131n olmamas\u0131. Kullan\u0131c\u0131lar\u0131n bu SMS\u2019leri g\u00f6rmeme sebebi ise SMSlerin mesajlar uygulamas\u0131 taraf\u0131ndan de\u011fil uygulama \u00fczerinden i\u015flenmesidir \u2013 mesela \u00fccretsiz oyunlar.<\/p>\n<p>\u00a0<br>\nTriada\u2019n\u0131n mesajlar\u0131 de\u011fi\u015ftirme \u00f6zelli\u011fi olmas\u0131 sonucunda, para uyguluma geli\u015ftiriciye de\u011fil direkt malware y\u00f6neticisine gider. Triada kullan\u0131c\u0131lardan \u015fu \u015fekillerde de para \u00e7alabilir. Kullan\u0131c\u0131lar sat\u0131n alma i\u015fleminde ba\u015far\u0131s\u0131z olursa Triada i\u015flemi kendi istedi\u011fi gibi ger\u00e7ekle\u015ftirir. Hatta ba\u015far\u0131l\u0131 sat\u0131n almalarda bile paray\u0131 uygulama geli\u015ftiriciye g\u00f6ndermek yerine kendi istedi\u011fi yere g\u00f6nderebilir.<\/p>\n<p>\u00a0<br>\n\u015eimdilik, siber su\u00e7lular Triada\u2019dan sadece bu \u015fekilde kar elde edebiliyor, ama \u015funu unutmay\u0131n ki Triada birimsel bir Trojan\u2019d\u0131r. Y\u00f6netim &amp; Kontrol sunucusundan bir komutla istenilen her \u015fekle sokulabilir.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Evolution of <a href=\"https:\/\/twitter.com\/hashtag\/Asacub?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Asacub<\/a> trojan: from small fish to ultimate weapon \u2013 <a href=\"https:\/\/t.co\/lLv0pY4lol\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/lLv0pY4lol<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/infosec?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#infosec<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/mobile?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#mobile<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/banking?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#banking<\/a> <a href=\"https:\/\/t.co\/gAM3zzy7aC\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/gAM3zzy7aC<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/689836995196129281?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">January 20, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><strong>Telefonunuzdan organize su\u00e7lara kar\u015f\u0131 sava\u015f\u0131n<\/strong><br>\nTriada\u2019n\u0131n as\u0131l problemlerinden biri, B\u0130R\u00c7OK insana zarar verebilecek olmas\u0131d\u0131r. Daha \u00f6nce de\u011findi\u011fimiz gibi, Triada k\u00f6k dizini kontrol edebilen k\u00fc\u00e7\u00fck Trojanlar taraf\u0131ndan telefonunuza indirilir.\u00a0 Ara\u015ft\u0131rmac\u0131lar\u0131m\u0131z 2015\u2019in ikinci yar\u0131s\u0131nda her 10 Android kullan\u0131c\u0131s\u0131ndan 1\u2019inin bir ya da bir\u00e7ok Trojan vir\u00fcs\u00fc taraf\u0131ndan sald\u0131r\u0131ya u\u011frad\u0131\u011f\u0131n\u0131 tahmin ediyor, yani milyonlarca cihaza \u00e7ok b\u00fcy\u00fck ihtimalle Tirada bula\u015fm\u0131\u015f olabilir.<\/p>\n<p>\u00a0<br>\nPeki, siz bu gizli canavardan kendinizi nas\u0131l koruyabilirsiniz?<\/p>\n<p>\u00a0<br>\n1. Sisteminizi g\u00fcncellemeyi asla unutmay\u0131n. G\u00f6r\u00fcnen o ki, bu k\u00fc\u00e7\u00fck Trojanlar Android 4.4.4 ve daha y\u00fcksek sistemlerin k\u00f6k dizininde \u00e7ok ciddi sorunlarlarla kar\u015f\u0131la\u015f\u0131r \u00e7\u00fcnk\u00fc bir\u00e7ok eksik bu versiyonlarda giderildi.\u00a0 Yani, cihaz\u0131n\u0131zda Android 4.4.4 veya daha \u00fcst\u00fc bir versiyon kullan\u0131yorsan\u0131z, Triada\u2019dan etkilenme riskiniz bir hayli azald\u0131. Ger\u00e7i, istatisklerimiz hala kullan\u0131c\u0131lar\u0131n %60\u2019\u0131n\u0131n Android 4.4.2 ve daha d\u00fc\u015f\u00fck s\u00fcr\u00fcmlerini kulland\u0131\u011f\u0131n\u0131 s\u00f6yl\u00fcyor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1948\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/03\/06014306\/01_en.png\" alt=\"01_en\" width=\"1196\" height=\"934\"><\/p>\n<p>2. Hangi versiyonu kullan\u0131rsan\u0131z kullan\u0131n, riske girmemek en do\u011frusu. Bu y\u00fczden Anroid cihazlar i\u00e7in anti-vir\u00fcs programlar\u0131 kullanman\u0131z\u0131 \u00f6neriyoruz.\u00a0<a href=\"https:\/\/www.kaspersky.com\/tr\/android-security\" target=\"_blank\" rel=\"noopener noreferrer nofollow\"> Kaspersky Internet Security for Android<\/a> b\u00fct\u00fcn Triada mod\u00fcllerini farkeder ve b\u00f6ylelikle paran\u0131z\u0131 Triada arkas\u0131ndaki siber su\u00e7lulardan korur. Ama \u015funu unutmay\u0131n ki, vir\u00fcs tarama \u00fccretsiz versiyonlarda otomatik ba\u015flamaz.<\/p>\n<p>\u00a0<br>\nAma hepsinden \u00f6te, Triada bu zararl\u0131 ak\u0131mdan sadece bir \u00f6rnek: malware geli\u015ftiricileri Android ile \u00e7ok ilgilidir, ve son \u00f6rnekler ger\u00e7ekten\u00a0 Windows temelli vir\u00fcs t\u00fcrlerinden \u00e7ok daha karma\u015f\u0131k ve kar\u015f\u0131 konmas\u0131 \u00e7ok daha zordur. Bu tehditlere kar\u015f\u0131 sava\u015fman\u0131n en iyi yolu s\u00fcrekli tetikte olmak, ve iyi bir anti vir\u00fcs kullanmakt\u0131r.<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ordular\u0131n genellikle nas\u0131l hareket etti\u011fini bilirsiniz: \u00d6nce g\u00f6zc\u00fcler her \u015feyin yolunda oldu\u011funa emin olur. Daha sonra a\u011f\u0131r birlikler gelir. En az\u0131ndan siber sava\u015f \u00e7a\u011f\u0131ndan \u00f6nce bu b\u00f6yleydi. \u015eimdi Trojan vir\u00fcsleri<\/p>\n","protected":false},"author":706,"featured_media":1946,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1284,1351],"tags":[],"class_list":{"0":"post-1945","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-tips","9":"category-threats"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/triada-androiddeki-organize-suc\/1945\/"}],"acf":[],"banners":"","maintag":[],"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/1945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/706"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=1945"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/1945\/revisions"}],"predecessor-version":[{"id":7826,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/1945\/revisions\/7826"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/1946"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=1945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=1945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=1945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}