{"id":2707,"date":"2016-12-09T02:23:18","date_gmt":"2016-12-09T07:23:18","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2707"},"modified":"2019-11-15T14:54:30","modified_gmt":"2019-11-15T11:54:30","slug":"fighting-ransomware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/fighting-ransomware\/2707\/","title":{"rendered":"2016&#8217;n\u0131n fidye yaz\u0131l\u0131m\u0131 salg\u0131n\u0131"},"content":{"rendered":"<p>\u015eifreleme ve fidye konular\u0131 insanl\u0131k tarihinde \u00e7ok eskiye dayan\u0131yor. Bu iki konuyu bir araya getirdi\u011finde ne oldu\u011funu d\u00fcnya yeni yeni ke\u015ffediyor. Bug\u00fcnk\u00fc fidye yaz\u0131l\u0131m\u0131n\u0131n temeli 1989\u2019da Dr. Joseph L. Popp taraf\u0131ndan at\u0131ld\u0131.<\/p>\n<p><strong><br>\nK\u00f6ken<\/strong><br>\nBilgisayar temelli zorbal\u0131klar\u0131n temeli olarak bilinen Popp, kendisinin zararl\u0131 yaz\u0131l\u0131m\u0131n\u0131 D\u00fcnya Sa\u011fl\u0131k Organizasyonu\u2019nun AIDS konferans\u0131nda da\u011f\u0131tt\u0131. Da\u011f\u0131tt\u0131\u011f\u0131 disklerde \u201cAIDS Bilgileri \u2013 Bilgilendirme Disketi\u201d yaz\u0131yordu. Asl\u0131nda her bir diskette i\u00e7erisindeki verilerin bilgisayarlara zarar verebilece\u011fi yaz\u0131yordu.<\/p>\n<p>Ama uyar\u0131lar\u0131 kim okur ki? Popp\u2019un \u00fcretti\u011fi 20,000 civar\u0131 disket bilgisayarlara tak\u0131ld\u0131, kurbanlar\u0131n bilgisayarlar\u0131 kitlendi ve fidye talep bilgilendirmeleri ald\u0131lar. Fidye olarak 189$\u2019l\u0131k isteniyordu. \u0130stenen para Panama\u2019da bulunan bir postaneye normal mektup olarak g\u00f6nderilmesi isteniyordu. Bu hikaye blog takip\u00e7ilerimize tan\u0131d\u0131k gelecektir.<\/p>\n<p><strong>G\u00fcn\u00fcm\u00fczde fidye yaz\u0131l\u0131mlar\u0131 <\/strong><br>\n\u0130lk fidye yaz\u0131l\u0131m\u0131 konseptinden bug\u00fcne bir iki ufak de\u011fi\u015fiklik ya\u015fand\u0131. San\u0131r\u0131m ya\u015fanan de\u011fi\u015fikliklerin en b\u00fcy\u00fc\u011f\u00fc, talep edilen fidye art\u0131k mektup olarak de\u011fil, TOR taray\u0131c\u0131s\u0131 ve bitcoin ile yap\u0131larak kolluk kuvvetlerinin atlat\u0131lmaya \u00e7al\u0131\u015f\u0131lmas\u0131d\u0131r. Peki bu konsept g\u00fcn\u00fcm\u00fcze kadar nas\u0131l dayand\u0131?<\/p>\n<p>Direkt olarak paraya d\u00f6n\u00fc\u015febilmesi sayesinde. Ortalama talep edilen fidye 300$ civar\u0131. B\u00fcy\u00fck \u015firketlerden talep edilen u\u00e7uk fidye miktarlar\u0131n\u0131 g\u00f6rmezden gelirsek \u015funu s\u00f6yleyebiliriz, istenen fidye miktar\u0131 gittik\u00e7e art\u0131yor. Bu durum da \u015funu kan\u0131tl\u0131yor, fidye yaz\u0131l\u0131mlar\u0131 hem g\u00fc\u00e7l\u00fc hem de etkilidir.<\/p>\n<p>Tahminlere g\u00f6re ortalama bir kullan\u0131c\u0131 er ya da ge\u00e7 fidye yaz\u0131l\u0131m\u0131yla kar\u015f\u0131lacak ve verilerini kaybetmek ile fidye \u00f6demek aras\u0131nda se\u00e7im yapmak durumunda kalacak. <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/no-no-ransom\/2582\/\" target=\"_blank\" rel=\"noopener noreferrer\">Fidye \u00f6dememenizi<\/a>, <a href=\"https:\/\/www.nomoreransom.org\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">No More Ransom<\/a> \u00fczerinden uygun \u015fifre \u00e7\u00f6z\u00fcc\u00fcy\u00fc bulan\u0131z\u0131 ya da ba\u015fka yollar denemenizi s\u00f6ylememize ra\u011fmen, \u00fcz\u00fcc\u00fc \u015fekilde bir\u00e7ok kurban fidye \u00f6demeyi se\u00e7iyor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/12\/06013547\/b2c_teaser.jpg\" alt=\"b2c_teaser\" width=\"1135\" height=\"840\" class=\"alignnone size-full wp-image-2709\"><\/p>\n<p>Fidye yaz\u0131l\u0131mlar\u0131n\u0131n her g\u00fcn artmas\u0131 korkutucu g\u00f6r\u00fcnebilir ama \u00f6nemli olan say\u0131s\u0131 de\u011fil g\u00fcc\u00fcd\u00fcr. Asl\u0131nda fidye yaz\u0131l\u0131mlar\u0131n\u0131n kalitesini ve say\u0131s\u0131n\u0131 oranlarsak, fidye yaz\u0131l\u0131mlar\u0131n\u0131n \u00e7ok k\u00fc\u00e7\u00fck bir k\u0131sm\u0131 son derece g\u00fc\u00e7l\u00fc kodlanm\u0131\u015f ve ara\u015ft\u0131rmac\u0131lar\u0131 epey me\u015fgul ediyor (G\u00f6zler \u00fczerinizde <a href=\"https:\/\/www.kaspersky.com\/blog\/locky-ransomware\/11667\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Locky<\/a> ve <a href=\"https:\/\/www.kaspersky.com\/blog\/cerber-multipurpose-malware\/12221\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Cerber<\/a>). <\/p>\n<p>Tek bir akt\u00f6r bile fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131s\u0131 d\u00fczenleyebilecekken, su\u00e7lular genelde bu i\u015fi tak\u0131m olarak yap\u0131yorlar. Teknik destek veriyorlar, ma\u011fdurlar\u0131n bitcoin al\u0131p fidye \u00f6demesine yard\u0131mc\u0131 oluyorlar, bu s\u0131rada yaz\u0131l\u0131m\u0131 g\u00fc\u00e7lendirip \u00e7\u00f6z\u00fcmesini zorla\u015ft\u0131r\u0131yorlar. Tam bir tak\u0131m i\u015fi!<br>\nFidye yaz\u0131l\u0131mlar\u0131n\u0131n i\u015f modeli haline gelmesi birka\u00e7 y\u0131l s\u00fcrd\u00fc. Bu hale gelmesinin sebeplerinden biri de anahtar teslim \u00e7\u00f6z\u00fcm\u00fc olmas\u0131. Bir\u00e7ok zararl\u0131 yaz\u0131l\u0131m\u0131 \u00fcretmek teknik yetenek gerektirirken, \u00e7ok g\u00fc\u00e7l\u00fc bir fidye yaz\u0131l\u0131m\u0131 yapmak ba\u015ftan sona \u00e7ok zor bir i\u015ftir. \u0130\u015fin p\u00fcf noktas\u0131 g\u00fc\u00e7l\u00fc \u015fifreleme olu\u015fturebilmek (e\u011fer bir yerlerde hata yap\u0131l\u0131rsa iyi adamlar \u00e7abucak \u00e7\u00f6z\u00fcm anahtar\u0131 olu\u015fturabilir \u2013 mesela bizim yapt\u0131\u011f\u0131m\u0131z gibi). <\/p>\n<p>Amat\u00f6rlerin dahi fidye yaz\u0131l\u0131m\u0131n\u0131 i\u015f modeli olarak se\u00e7mesinin bir nedeni var: Kolayca da\u011f\u0131t\u0131l\u0131yor ve kazand\u0131\u011f\u0131 paralar\u0131n bir k\u0131sm\u0131n\u0131 program geli\u015ftiricilerle payla\u015f\u0131yorlar. Maalesef bu da su\u00e7lular i\u00e7in yeterince karl\u0131 bir i\u015f. <\/p>\n<p><strong>Fidye yaz\u0131l\u0131m\u0131 t\u00fcrleri <\/strong><br>\nFidye yaz\u0131l\u0131m\u0131nlar\u0131n\u0131n evrimi \u2013 kolaydan, \u00fc\u00e7\u00fcnc\u00fc parti ara\u00e7lar (WinRAR, GPG gibi) Microsoft Developer Network gibi \u015feyleri harmanlayarak olu\u015fturulmu\u015f t\u00fcrlere kadar \u2013 siber su\u00e7lular\u0131n bu konuda ne kadar istekli olduklar\u0131n\u0131 g\u00f6zler \u00f6n\u00fcne seriyor.<br>\n<strong><br>\nE\u011filimler <\/strong><br>\nBrezilya\u2019da ke\u015ffredilen yeni fidye yaz\u0131l\u0131mlar\u0131, fidye yaz\u0131l\u0131mlar\u0131n\u0131n artmaya devam etti\u011fini ama genellikle eski fidye yaz\u0131l\u0131mlar\u0131n\u0131n elden ge\u00e7irilmesi ile olu\u015fturuldu\u011funu g\u00f6sterdi. Niye s\u0131f\u0131rdan kod yazas\u0131n ki? \u015eu an hi\u00e7bir bilgisi olmayan \u00e7ocuklar bile fidye yaz\u0131l\u0131m\u0131 ara\u00e7lar\u0131 alabilir, fidye yaz\u0131l\u0131m\u0131na isim verebilir ve bunu da\u011f\u0131tabilir. E\u011fer olu\u015fturulan marka ilgin\u00e7e, medya bu durum hakk\u0131nda birka\u00e7 c\u00fcmle yazar, bu su\u00e7lulara sadece para kazand\u0131rmakla kalmaz ayn\u0131 zamanda markaya k\u00f6t\u00fc bir \u015f\u00f6hret de kazand\u0131r\u0131r. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/12\/06013545\/14876454_10154703707261248_756590392391278286_o.jpg\" alt=\"14876454_10154703707261248_756590392391278286_o\" width=\"2048\" height=\"1344\" class=\"alignnone size-full wp-image-2710\"><\/p>\n<p>Yeterince fazla say\u0131da kalitesiz fidye yaz\u0131l\u0131m\u0131n\u0131 sadece kulland\u0131\u011f\u0131 pop\u00fcler TV show logosu, film karakteri foto\u011fraf\u0131 ya da siyaset\u00e7iler hakk\u0131ndaki esprileri y\u00fcz\u00fcnden haberlerde g\u00f6rd\u00fck. \u0130yi olan \u015fey ise bu pop\u00fcler fidye yaz\u0131l\u0131mlar\u0131n\u0131n kolayca tespit edilebilir olmalar\u0131. \u015eimdilerde bir\u00e7ok su\u00e7lu olu\u015fturduklar\u0131 fidye yaz\u0131l\u0131mlar\u0131 i\u00e7in bir isim se\u00e7iyor ve ma\u011fdurlar\u0131 ileti\u015fim bilgisi ve bitcoin \u00f6deme adresi ile ba\u015fba\u015fa b\u0131rak\u0131yor. <\/p>\n<p>Fidye \u00f6demek i\u00e7in bir\u00e7ok yol olmas\u0131na ra\u011fmen, en pop\u00fcler talep y\u00f6ntemi hala bitcoin. Tabi hala makbuz verebilen sistemleri (PaySafeCard gibi) tercih eden su\u00e7lular da var. B\u00f6lgesel ve kendileri taraf\u0131ndan olu\u015fturulmu\u015f \u00f6deme y\u00f6ntemleri de de\u011fi\u015fik b\u00f6lgelerde kullan\u0131labiliyor. <\/p>\n<p><strong>S\u0131k\u0131 \u00e7al\u0131\u015fmak ve gelece\u011fe bakmak <\/strong><br>\nFidye yaz\u0131l\u0131mlar\u0131 g\u00fcn ge\u00e7tik\u00e7e iyile\u015fiyor ancak kat edece\u011fi hala \u00e7ok yol var. Ancak sorunlar hakk\u0131nda somut istatistik verileri toplayarak uygun \u00e7\u00f6z\u00fcmleri de\u011ferlendirebiliriz. Ama ne yaz\u0131k ki fidye yaz\u0131l\u0131m\u0131ndan etkilenen herkes bunu rapor etmiyor, rapor edenlerin de b\u00fcy\u00fck bir k\u0131sm\u0131 farkl\u0131 yerler rapor ediyor. Bu da veri toparlamay\u0131 olduk\u00e7a zorla\u015ft\u0131r\u0131yor. <\/p>\n<p>Kolluk kuvvetlerinin ve BT g\u00fcvenlik firmalar\u0131n\u0131n siber su\u00e7lular\u0131n fidye i\u015fini durdurmak i\u00e7in birlikteli\u011finin sonu\u00e7lar\u0131 etkili oldu. \u00d6ne\u011fin, No More Ransom giri\u015fimi fidye yaz\u0131l\u0131m\u0131 kurbanlar\u0131na fidye \u00f6detmeden verilerini geri alma iste\u011fiyle ortaya \u00e7\u0131km\u0131\u015f bir giri\u015fimdir. <\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"tr\" dir=\"ltr\">13 \u00fclke fidye yaz\u0131l\u0131m\u0131 ile sava\u015f\u0131m\u0131za kat\u0131l\u0131yor <a href=\"https:\/\/t.co\/lu9yDwq1a4\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/lu9yDwq1a4<\/a> <a href=\"https:\/\/t.co\/fAArxUTLDQ\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/fAArxUTLDQ<\/a><\/p>\n<p>\u2014 Kaspersky T\u00fcrkiye (@KasperskyTR) <a href=\"https:\/\/twitter.com\/KasperskyTR\/status\/788373492135788544?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">October 18, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Bu tarz desteklerle beraber, fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 geli\u015ftirdi\u011fimiz projelerle \u015fans\u0131m\u0131z her ge\u00e7en g\u00fcn daha \u00e7ok art\u0131yor. Her kurulu\u015fun fidye yaz\u0131l\u0131m\u0131na olan bak\u0131\u015f\u0131 belli ve bu nedenle ba\u015far\u0131l\u0131 olman\u0131n tek yolu beraber \u00e7al\u0131\u015fmak. <\/p>\n<p>Bireysel kullan\u0131c\u0131lar i\u00e7in (ki potansiyel kurbanlar da denebilir), bilgi g\u00fc\u00e7t\u00fcr. Bu y\u00fczden fidye yaz\u0131l\u0131mlar\u0131 hakk\u0131nda bilmeniz gereken her \u015feyi <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/ransomware-faq\/2613\/\" target=\"_blank\" rel=\"noopener noreferrer\">bir arada toplad\u0131k<\/a>. \u0130nternet kullanan herkesin kesinlikle okumas\u0131 gerekiyor. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u015eifreleme ve fidye konular\u0131 insanl\u0131k tarihinde \u00e7ok eskiye dayan\u0131yor.<\/p>\n","protected":false},"author":313,"featured_media":2708,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[1091,591,36,1093,447,1090,552,1092,553],"class_list":{"0":"post-2707","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-cryptores","9":"tag-fidye-yazilimi","10":"tag-malware-2","11":"tag-no-more-ransom","12":"tag-ransomware","13":"tag-sifreliyiciler","14":"tag-tarih","15":"tag-uzmanlar","16":"tag-zararli-yazilim-2"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/fighting-ransomware\/2707\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/fighting-ransomware\/10510\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/fighting-ransomware\/8036\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/fighting-ransomware\/9605\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/fighting-ransomware\/9405\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/fighting-ransomware\/13650\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/fighting-ransomware\/13525\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/fighting-ransomware\/6344\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/fighting-ransomware\/5762\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/fighting-ransomware\/9285\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/fighting-ransomware\/13332\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/fighting-ransomware\/13650\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/fighting-ransomware\/13525\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/fighting-ransomware\/13525\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimi\/","name":"Fidye Yaz\u0131l\u0131m\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2707","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/313"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2707"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2707\/revisions"}],"predecessor-version":[{"id":7104,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2707\/revisions\/7104"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2708"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}