{"id":2414,"date":"2016-09-20T03:18:22","date_gmt":"2016-09-20T07:18:22","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2414"},"modified":"2019-11-15T14:57:30","modified_gmt":"2019-11-15T11:57:30","slug":"pokemon-go-malware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/pokemon-go-malware\/2414\/","title":{"rendered":"Guide for Pok\u00e9mon Go Trojan\u0131, Pok\u00e9mon Oyuncular\u0131n\u0131 Avl\u0131yor"},"content":{"rendered":"<p>Pok\u00e9mon Go\u2019nun yay\u0131nlanmas\u0131ndan bu yana daha \u00fc\u00e7 ay olmam\u0131\u015fken, su\u00e7lular Pok\u00e9mon oyuncular\u0131n\u0131 hedef alan zararl\u0131 bir yaz\u0131l\u0131m\u0131 Google Play\u2019e yerle\u015ftirdiler. Uzmanlar\u0131m\u0131z bu trojan\u0131 birka\u00e7 g\u00fcn \u00f6nce <a href=\"https:\/\/securelist.com\/blog\/mobile\/76081\/rooting-pokemons-in-google-play-store\/\" target=\"_blank\" rel=\"noopener noreferrer\">ke\u015ffetti<\/a> ve hemen Google\u2019a bildirdi. Maalesef o zamana kadar Guide for Pok\u00e9mon Go isimli yaz\u0131l\u0131m 500,000 defadan fazla indirilmi\u015fti.<\/p>\n<p>Ge\u00e7ti\u011fimiz birka\u00e7 ay i\u00e7erisinde yakla\u015f\u0131k 6 milyon insan Pok\u00e9mon Go\u2019yu denedi. Bu sebeple siber su\u00e7lular\u0131n <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/gotta-catch-em-all-with-caution\/2245\/\" target=\"_blank\" rel=\"noopener noreferrer\">ilgisini bu kadar \u00e7abuk \u00e7ekmesi<\/a> pek \u015fa\u015f\u0131lacak bir durum de\u011fil: Pok\u00e9mon Go hakk\u0131ndaki ilk zararl\u0131 yaz\u0131l\u0131m\u0131n izlerine ilk olarak oyun yay\u0131nland\u0131ktan k\u0131sa s\u00fcre sonra <a href=\"https:\/\/threatpost.com\/malicious-pokemon-go-app-installs-backdoor-on-android-devices\/119174\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Temmuz<\/a> ay\u0131nda rastland\u0131. O zaman durum kadar tehlikeli de\u011fildi. Trojan bu zararl\u0131 yaz\u0131l\u0131m\u0131n i\u00e7inde online olarak da\u011f\u0131lmay\u0131 bekledi. Ama \u015fimdiki hikaye tamamen farkl\u0131.<\/p>\n<p>Bu Trojan Google Play\u2019de bulundu. Son derece ba\u015far\u0131l\u0131 \u015fekilde kendisini g\u00fcvenlik uzmanlar\u0131ndan gizleyerek dikkatlice hedeflerini se\u00e7ti. \u201cSe\u00e7ilmi\u015f\u201d kullan\u0131c\u0131lara reklamlar g\u00f6sterdi \u2013 \u00e7ok\u00e7a reklam g\u00f6sterdi. Ayn\u0131 zamanda cihaz\u0131n k\u00f6k dizinine eri\u015ferek di\u011fer zararl\u0131 yaz\u0131l\u0131mlar\u0131 ve istenmeyen uygulamalar\u0131 indirdi.<\/p>\n<p><strong>Nas\u0131l \u00e7al\u0131\u015f\u0131yor?<\/strong><br>\nZararl\u0131 yaz\u0131l\u0131m\u0131 anti vir\u00fcs \u00e7\u00f6z\u00fcmlerinden saklamak i\u00e7in, Trojan\u2019\u0131n \u00e7al\u0131\u015ft\u0131r\u0131labilir dosyas\u0131 ilgili <a href=\"https:\/\/en.wikipedia.org\/wiki\/Executable_compression\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">yaz\u0131l\u0131m paketi<\/a> dosyas\u0131 ile birle\u015ftirilmi\u015f. \u00c7\u00f6z\u00fcmlenmi\u015f dosyalar i\u015fe yarar Pok\u00e9mon Go i\u00e7eri\u011fi (Trojan\u0131n b\u00fcr\u00fcnd\u00fc\u011f\u00fc k\u0131l\u0131k) ve k\u00fc\u00e7\u00fck <a href=\"https:\/\/en.wikipedia.org\/wiki\/Obfuscation_(software)\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">gizlenmi\u015f<\/a> bir kod i\u00e7eriyor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2416\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/09\/06013928\/pokemon-go-trojan-screenshot-1.png\" alt=\"pokemon-go-trojan-screenshot-1\" width=\"1247\" height=\"947\"><\/p>\n<p>Kullan\u0131c\u0131 Guide for Pok\u00e9mon Go i\u00e7eri\u011fini indirdikten sonra, zararl\u0131 yaz\u0131l\u0131m sessizce bir s\u00fcre bekler. Bekledi\u011fi s\u00fcre boyunca ger\u00e7ek bir cihazda m\u0131 yoksa <a href=\"https:\/\/tr.wikipedia.org\/wiki\/Sanal_makine\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">sanal makine<\/a>de mi oldu\u011funu anlar. Sistem g\u00fcvenlik uzmanlar\u0131 bu yaz\u0131l\u0131m\u0131n farkl\u0131 durumlarda farkl\u0131 davrand\u0131\u011f\u0131n\u0131 g\u00f6zlemledi.<\/p>\n<p>Ger\u00e7ek bir cihazda oldu\u011funu do\u011frularsa, Trojan siber su\u00e7lular\u0131n \u00f6netti\u011fi <a href=\"http:\/\/y%C3%B6netim%20ve%20kontrol%20sunucusuna\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">y\u00f6netim ve kontrol sunucusuna<\/a> mesaj g\u00f6nderir. Bu raporda vir\u00fcsl\u00fc cihaz\u0131n modeli, yaz\u0131l\u0131m versiyonu, \u00fclkesi, varsay\u0131lan dili ve daha fazlas\u0131ndan bahseder.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2417\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/09\/06013926\/pokemon-go-trojan-screenshot-2.png\" alt=\"pokemon-go-trojan-screenshot-2\" width=\"1223\" height=\"931\"><\/p>\n<p>Sunucu g\u00f6nderilen raporu inceler, e\u011fer kurban\u0131n uygun oldu\u011funa karar verirse trojan\u0131 bilgilendirir. Sunucunun izni ile, Guide for Pok\u00e9mon Go uygulamas\u0131 zararl\u0131 yaz\u0131l\u0131mlar\u0131 indirmeye ba\u015flar. Bu dosyalar trojan\u0131n a\u011f\u0131r silahlar\u0131: 2012\u2019den 2015\u2019e kadar ke\u015ffedilmi\u015f sistem a\u00e7\u0131klar\u0131n\u0131 kullan\u0131yor.<\/p>\n<p>Zararl\u0131 yaz\u0131l\u0131m en b\u00fcy\u00fck kozlar\u0131n\u0131 oynayarak sistemin k\u00f6k dizinine eri\u015fiyor, sessizce uygulamalar\u0131 y\u00fckl\u00fcyor ve telefonu reklam ile dolduruyor.<\/p>\n<p><strong>Sadece reklam m\u0131? Reklamlar ger\u00e7ekten bu kadar tehlikeli mi?<\/strong><br>\nReklamlar \u00e7ok olmad\u0131\u011f\u0131 zaman g\u00fczel \u015feylerdir. Bunun yan\u0131nda reklam izleterek Google\u2019dan para kazanabilirsiniz. Bu y\u00fczden siber su\u00e7lular telefonunuza zararl\u0131 yaz\u0131l\u0131m\u0131 bula\u015ft\u0131r\u0131rsa, size s\u00fcrekli reklam g\u00f6stererek para kazanmak isteyecekler.<\/p>\n<p>Buna ra\u011fmen en k\u00f6t\u00fc senaryo bu de\u011fil: Guide for Pok\u00e9mon Go gizlice her uygulamay\u0131 bilgisayar\u0131n\u0131za indirebilir. \u015eimdilik, siber su\u00e7lular gayet \u0131l\u0131man bir \u015fekilde, reklamlarla para kazanmay\u0131 hedeflemi\u015fler. Yar\u0131n, fikirlerini de\u011fi\u015ftirip cihazlar\u0131n\u0131z kitleyip fidye isteyebilir ya da bankac\u0131l\u0131k hesaplar\u0131n\u0131z\u0131 \u00e7alabilirler.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"tr\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/GooglePlay?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#GooglePlay<\/a>\u2019deki yorumlara ve de\u011ferlendirmelere g\u00fcvenmeyin  <a href=\"https:\/\/t.co\/XMlxWNi4lD\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/XMlxWNi4lD<\/a> <a href=\"https:\/\/t.co\/sFIXPmDENH\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/sFIXPmDENH<\/a><\/p>\n<p>\u2014 Kaspersky T\u00fcrkiye (@KasperskyTR) <a href=\"https:\/\/twitter.com\/KasperskyTR\/status\/771669805417963522?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">September 2, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Program Google Play\u2019den kald\u0131r\u0131lana kadar yar\u0131m milyon insan taraf\u0131ndan indirildi. Kesin olarak Rusya, Hindistan ve Endonezya\u2019daki cihazlar\u0131 etkiledi\u011fini biliyoruz. \u00d6zellikle \u0130ngilizce konu\u015fulan b\u00f6lgeleri hedefledi\u011fini de biliyoruz, d\u00fcnya \u00e7evresinde ba\u015fka kurbanlar\u0131n\u0131n oldu\u011funu da biliyoruz.<\/p>\n<p><strong>Kendinizi nas\u0131l koruyabilirsiniz<\/strong><br>\nE\u011fer cihaz\u0131n\u0131z\u0131n bu Trojandan etkilenmi\u015f olabilece\u011fini d\u00fc\u015f\u00fcn\u00fcyorsan\u0131z, zararl\u0131 yaz\u0131l\u0131m\u0131 bir an \u00f6nce cihaz\u0131n\u0131zdan kald\u0131rarak cihaz\u0131n\u0131z\u0131 <a href=\"https:\/\/kas.pr\/kdkisatr\" target=\"_blank\" rel=\"noopener noreferrer\">Kaspersky Antivirus &amp; Security for Android<\/a> ile tarat\u0131n. \u00dccretsizdir. G\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fcm\u00fcz bu Trojan\u0131 HEUR:Trojan.AndroidOS.Ztorg.ad. olarak tan\u0131maktad\u0131r.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>Siz #pokemon yakalarken, siber su\u00e7lular #GooglePlay\u2019de sizi yakalamaya \u00e7al\u0131\u015f\u0131yor<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2FfeY2&amp;text=%3C%2Fp%3E%0A%3Cp%3ESiz+%23pokemon+yakalarken%2C+siber+su%C3%A7lular+%23GooglePlay%26%238217%3Bde+sizi+yakalamaya+%C3%A7al%C4%B1%C5%9F%C4%B1yor%3C%2Fp%3E%0A%3Cp%3E\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>\u00a0<\/p>\n<p>\u0130lerde kendinizi korumak i\u00e7in \u015fu ad\u0131mlar\u0131 takip edin:<\/p>\n<p>1. Orijinal kayna\u011f\u0131ndan indirseniz bile, hi\u00e7bir \u015fey %100 g\u00fcvenli de\u011fildir. Siber su\u00e7lular bazen Google ve di\u011fer \u015firketlerin g\u00fcvenliklerini a\u015fabiliyorlar \u2013 Guide for Pok\u00e9mon Go harika bir \u00f6rnek.<\/p>\n<p>2. En yak\u0131n zamanda ak\u0131ll\u0131 telefonunuza (tabi bilgisayar\u0131n\u0131za da) g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc y\u00fckleyin. Siber su\u00e7lular telefon ve bilgisayarlardaki sistem a\u00e7\u0131klar\u0131ndan yararlanmay\u0131 \u00e7ok severler.<\/p>\n<p>3. Google Play\u2019de bulunan de\u011ferlendirmeler genellikle g\u00fcvenilir de\u011fillerdir \u2013 siber su\u00e7lular ba\u015fka zararl\u0131 yaz\u0131l\u0131mlar kullanarak ortalamalar\u0131 <a href=\"http:\/\/kas.pr\/7Doi\" target=\"_blank\" rel=\"noopener noreferrer\">y\u00fckseltebilirler<\/a>. \u00d6rne\u011fin Guide for Pok\u00e9mon Go yaz\u0131l\u0131m\u0131n\u0131n Google Play\u2019de 4 y\u0131ld\u0131z\u0131 vard\u0131.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pok\u00e9mon Go\u2019nun yay\u0131nlanmas\u0131ndan bu yana daha \u00fc\u00e7 ay olmam\u0131\u015fken, su\u00e7lular Pok\u00e9mon oyuncular\u0131n\u0131 hedef alan zararl\u0131 bir yaz\u0131l\u0131m\u0131 Google Play\u2019e yerle\u015ftirdiler. Uzmanlar\u0131m\u0131z bu trojan\u0131 birka\u00e7 g\u00fcn \u00f6nce ke\u015ffetti ve hemen Google\u2019a<\/p>\n","protected":false},"author":522,"featured_media":2415,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1351],"tags":[580,105,109,591,22,685,441,998,899,241,599],"class_list":{"0":"post-2414","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-akilli-telefon","10":"tag-android","11":"tag-apps","12":"tag-fidye-yazilimi","13":"tag-google","14":"tag-mobil-cihaz","15":"tag-online-gaming","16":"tag-play-store","17":"tag-pokemon-go","18":"tag-trojan","19":"tag-uygulamalar"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/pokemon-go-malware\/2414\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/pokemon-go-malware\/5567\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/pokemon-go-malware\/3892\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/pokemon-go-malware\/7648\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/pokemon-go-malware\/7649\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/pokemon-go-malware\/7671\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/pokemon-go-malware\/9095\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/pokemon-go-malware\/8938\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/pokemon-go-malware\/13044\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/pokemon-go-malware\/12953\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/pokemon-go-malware\/6063\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/pokemon-go-malware\/6543\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/pokemon-go-malware\/5388\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/pokemon-go-malware\/8703\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/pokemon-go-malware\/12577\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/pokemon-go-malware\/13044\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/pokemon-go-malware\/12953\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/pokemon-go-malware\/12953\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/akilli-telefon\/","name":"ak\u0131ll\u0131 telefon"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/522"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2414"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2414\/revisions"}],"predecessor-version":[{"id":7144,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2414\/revisions\/7144"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2415"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}