{"id":2523,"date":"2016-10-13T03:08:31","date_gmt":"2016-10-13T07:08:31","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2523"},"modified":"2019-11-15T14:56:23","modified_gmt":"2019-11-15T11:56:23","slug":"dresscode-android-trojan","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/dresscode-android-trojan\/2523\/","title":{"rendered":"Google Play&#8217;de 400 Trojan"},"content":{"rendered":"<p>Android kullan\u0131c\u0131lar\u0131na s\u0131k s\u0131k uygulamalar\u0131 resmi uygulama d\u00fckkanlar\u0131ndan indirmelerini \u00f6\u011f\u00fctl\u00fcyoruz. \u00a0Google Play\u2019den uygulama indirmek di\u011fer yerlerden indirmekten daha g\u00fcvenli, \u00e7\u00fcnk\u00fc bir uygulaman\u0131n Google Play\u2019e girebilmesi i\u00e7in bir grup testlerden ge\u00e7mesi ve onaylar alabilmesi laz\u0131m.<\/p>\n<p>Bu \u00f6nlemlere ra\u011fmen zararl\u0131 yaz\u0131l\u0131m i\u00e7eren uygulamalar zaman zaman Google Play\u2019e s\u0131zabiliyor. Ge\u00e7ti\u011fimiz g\u00fcnlerde Google Play\u2019de ya\u015fanan b\u00fcy\u00fck olayda Google Play\u2019de bulunan 400\u2019den fazla uygulama (ve ba\u015fka kaynaklardaki 3,000 civar\u0131 uygulama)\u2019ya DressCode Trojan\u0131 bula\u015ft\u0131.<\/p>\n<p>\u0130lk bak\u0131\u015fta ismi komik geliyor, \u2018Giysi Kodu Trojan\u0131\u2019: Bu Trojan ilk defa ara\u015ft\u0131rmac\u0131lar taraf\u0131ndan 2016 A\u011fustos\u2019ta, k\u0131z \u00e7ocuklar\u0131 i\u00e7in haz\u0131rlanm\u0131\u015f oyunlar ve uygulamalarda <a href=\"http:\/\/blog.checkpoint.com\/2016\/08\/31\/dresscode-android-malware-discovered-on-google-play\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">ke\u015ffedildi<\/a>. <\/p>\n<p>Bu uygulamalardan bir tanesi Google Play\u2019de yakla\u015f\u0131k 500,000 defa indirilmi\u015f \u00e7ok pop\u00fcler bir uygulamayd\u0131. Ayr\u0131ca di\u011fer uygulamalar da ayn\u0131 Trojan bula\u015ft\u0131\u011f\u0131 tespit edildi. O zamana kadar 400 tane fazla zararl\u0131 yaz\u0131l\u0131m bula\u015ft\u0131\u011f\u0131 uygulama bulundu, bunlardan 40 tanesi Google Play\u2019deydi. Ara\u015ft\u0131rmac\u0131lar durumu Google\u2019a bildirdi, Google da bu zararl\u0131 uygulamalar\u0131 marketten kald\u0131rd\u0131. Ama bu buzda\u011f\u0131n\u0131n sadece g\u00f6r\u00fcnen k\u0131sm\u0131yd\u0131..<\/p>\n<p>Bu olaydan sonra ba\u015fka bir grup ara\u015ft\u0131rmac\u0131 bu Trojan ile ilgilenmeye ba\u015flad\u0131 ve derinlemesine ara\u015ft\u0131rma yapmaya, benzer uygulama marketlerini aramaya karar verdiler. Birka\u00e7 g\u00fcn sonra ekip 3,000 uygulaman\u0131n DressCode Trojan\u2019\u0131ndan etkilendi\u011fini ve 400 tanesinin Google Play\u2019de oldu\u011funu <a href=\"http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/dresscode-potential-impact-enterprises\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">belirtti<\/a>. <\/p>\n<p>Etkilenen uygulamalar\u0131n \u00e7o\u011fu oyun ve oyunla alakal\u0131 \u015feylerdi \u2013 mesela oyun hakk\u0131nda ipu\u00e7lar\u0131 ve oyunla ilgili bildirimler veren uygulamalar a\u011f\u0131rl\u0131ktayd\u0131.  <\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"tr\" dir=\"ltr\">Pok\u00e9mon e\u011fitmenleri, telefonlar\u0131n\u0131za dikkat edin! Guide for Pok\u00e9mon Go Trojan\u0131, Pok\u00e9mon Oyuncular\u0131n\u0131 Avl\u0131yor  <a href=\"https:\/\/t.co\/1CFbOPsNeD\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/1CFbOPsNeD<\/a> <a href=\"https:\/\/t.co\/WgCakhV08o\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/WgCakhV08o<\/a><\/p>\n<p>\u2014 Kaspersky T\u00fcrkiye (@KasperskyTR) <a href=\"https:\/\/twitter.com\/KasperskyTR\/status\/778134814847270912?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">September 20, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>DressCode ile ilgili en b\u00fcy\u00fck sorun, Trojan\u0131 ke\u015ffetmenin zor olmas\u0131. Program\u0131n yaz\u0131l\u0131m kodu di\u011ferlerine nazaran \u00e7ok az. B\u00fcy\u00fck ihtimalle bu sebeple Google\u2019\u0131n yetkilileri fark edemiyor ve Google Play\u2019e girmesi i\u00e7in onay veriyorlar.<br>\n<strong><br>\nDressCode Trojan\u0131 ne i\u015fe yarar? <\/strong><br>\nGenel olarak DressCode Trojan\u2019\u0131n\u0131n tek i\u015fi y\u00f6netim ve kontrol sunucusuna ba\u011flanmakt\u0131r. Genellikle y\u00f6netim ve kontrol sunusuna bir defa ba\u011fland\u0131\u011f\u0131nda, sunucu geri komut g\u00f6ndererek Trojan\u2019\u0131 \u201cuyutur\u201d, b\u00f6ylelikle anl\u0131k olarak tespit etmek neredeyse imkans\u0131z hale gelir. <\/p>\n<p>Cihaz\u0131n\u0131za bula\u015fan zararl\u0131 yaz\u0131l\u0131m\u0131 kontrol edenler cihaz\u0131n\u0131z\u0131 kullanmaya karar verdi\u011finde Trojan\u2019I uyand\u0131r\u0131r, ak\u0131ll\u0131 cihaz\u0131n\u0131z\u0131 ya da tabletinizi proxy sunucusuna \u00e7evirirler ve internet trafi\u011fini \u00fczerinizden sa\u011flarlar. <\/p>\n<p><strong>Siber su\u00e7lular\u0131n bundan \u00e7\u0131kar\u0131 ne? <\/strong><br>\n\u00d6ncelikle zararl\u0131 yaz\u0131l\u0131m bula\u015fm\u0131\u015f cihazlar belli IP adreslerine botnet t\u00fcneli olabilirler. Bu y\u00f6ntem siber su\u00e7lular i\u00e7in trafi\u011fi artt\u0131rmak, linklere t\u0131k sa\u011flamak, reklamlara t\u0131klamak ve DDoS sald\u0131r\u0131s\u0131 d\u00fczenleyerek internet sitelerini \u00e7\u00f6kertmek ama\u00e7l\u0131 kullan\u0131labilir. <\/p>\n<p>\u0130ki, vir\u00fcs bula\u015fm\u0131\u015f cihaz baz\u0131 yerel a\u011f kaynaklar\u0131na eri\u015febilir, sald\u0131rganlar da buraya eri\u015ferek \u00f6nemli verileri \u00e7alabilir.<br>\n<strong><br>\nBotnet olmak istemiyorum! Ne yapmam laz\u0131m? <\/strong><br>\nAsl\u0131nda genel uyar\u0131m\u0131za (uygulamalar\u0131 sadece resmi kaynaklardan indirin) uydu\u011funuz zaman ba\u015f\u0131n\u0131za \u00e7ok \u00e7ok nadir gelebilecek bir olay bu. Ayr\u0131ca di\u011fer kaynaklara bak\u0131nca Google Play\u2019de bulunan zararl\u0131 yaz\u0131l\u0131m say\u0131s\u0131n\u0131n di\u011ferlerinden \u00e7ok daha az oldu\u011fu do\u011fru. Ancak ayn\u0131 anda 400 zararl\u0131 yaz\u0131l\u0131m bula\u015fm\u0131\u015f uygulama da pek az bir say\u0131 de\u011fil. Bunlar\u0131n yan\u0131 s\u0131ra bula\u015ft\u0131klar\u0131 uygulamalar da k\u00fc\u00e7\u00fck uygulamalar de\u011filler. Mesela Minecraft \u201cGTA 5\u201d modu (Evet, ger\u00e7ekten b\u00f6yle bir \u015fey var). Bu uygulama 500,000 defa indirilmi\u015f bir uygulama. <\/p>\n<p><strong>K\u0131saca yapman\u0131z gerekenler ise \u015f\u00f6yle; <\/strong><br>\n1. Uygulama indirirken dikkatli olun. Bilinmeyen bir uygulama indirecekseniz, \u00f6nce yorumlar\u0131 okuyun. Uygulaman\u0131n istedi\u011fi izinlere dikkat edin ve d\u00fc\u015f\u00fcn\u00fcn. Maalesef yorumlara <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/dont-believe-google-play-ratings\/2393\/\" target=\"_blank\" rel=\"noopener noreferrer\">g\u00fcvenilmez<\/a> ama yine de uygulama hakk\u0131nda fikir verebilir. <\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"tr\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/GooglePlay?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#GooglePlay<\/a>\u2019deki yorumlara ve de\u011ferlendirmelere g\u00fcvenmeyin  <a href=\"https:\/\/t.co\/XMlxWNi4lD\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/XMlxWNi4lD<\/a> <a href=\"https:\/\/t.co\/sFIXPmDENH\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/sFIXPmDENH<\/a><\/p>\n<p>\u2014 Kaspersky T\u00fcrkiye (@KasperskyTR) <a href=\"https:\/\/twitter.com\/KasperskyTR\/status\/771669805417963522?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">September 2, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>2. Mobil cihaz\u0131n\u0131za g\u00fc\u00e7l\u00fc bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc y\u00fckleyin. <a href=\"https:\/\/kas.pr\/kdkisatr\" target=\"_blank\" rel=\"noopener noreferrer\">Kaspersky Antivirus &amp; Security for Android<\/a>, DressCode trojan\u0131n\u0131 HEUR:Backdoor.AndroidOS.Sobot.a. ismiyle tan\u0131yor. E\u011fer uygulamam\u0131z\u0131 sat\u0131n ald\u0131ysan\u0131z, indirdi\u011finiz t\u00fcm uygulamalar\u0131 tarayarak size DressCode\u2019a kar\u015f\u0131 koruyor. E\u011fer \u00fccretsiz s\u00fcr\u00fcm\u00fc kullan\u0131yorsan\u0131z, cihaz\u0131n\u0131z\u0131 d\u00fczenli olarak taramay\u0131 unutmay\u0131n. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Android kullan\u0131c\u0131lar\u0131na s\u0131k s\u0131k uygulamalar\u0131 resmi uygulama d\u00fckkanlar\u0131ndan indirmelerini \u00f6\u011f\u00fctl\u00fcyoruz. \u00a0Google Play\u2019den uygulama indirmek di\u011fer yerlerden indirmekten daha g\u00fcvenli, \u00e7\u00fcnk\u00fc bir uygulaman\u0131n Google Play\u2019e girebilmesi i\u00e7in bir grup testlerden ge\u00e7mesi<\/p>\n","protected":false},"author":696,"featured_media":2524,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[105,392,1033,1034,183,241],"class_list":{"0":"post-2523","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-android","9":"tag-botnet","10":"tag-ddos","11":"tag-dresscode","12":"tag-google-play","13":"tag-trojan"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/dresscode-android-trojan\/2523\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/dresscode-android-trojan\/7779\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/dresscode-android-trojan\/7791\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/dresscode-android-trojan\/7819\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/dresscode-android-trojan\/9282\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/dresscode-android-trojan\/9139\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/dresscode-android-trojan\/13297\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/dresscode-android-trojan\/13219\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/dresscode-android-trojan\/6643\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/dresscode-android-trojan\/5521\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/dresscode-android-trojan\/8923\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/dresscode-android-trojan\/12849\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/dresscode-android-trojan\/13297\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/dresscode-android-trojan\/13219\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/dresscode-android-trojan\/13219\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/android\/","name":"android"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/696"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2523"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2523\/revisions"}],"predecessor-version":[{"id":7128,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2523\/revisions\/7128"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2524"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}