{"id":2719,"date":"2016-12-15T09:47:37","date_gmt":"2016-12-15T14:47:37","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2719"},"modified":"2019-11-15T14:54:20","modified_gmt":"2019-11-15T11:54:20","slug":"indian-techsupport-scam","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/indian-techsupport-scam\/2719\/","title":{"rendered":"Sahte teknik destek ile insanlar\u0131 doland\u0131rmak"},"content":{"rendered":"<p>Birka\u00e7 y\u0131l \u00f6nce, Hindistanl\u0131 bir su\u00e7 \u00f6rg\u00fct\u00fc Avrupa, Avustralya ve \u0130ngiltere\u2019de bulunan ve teknik olaylardan pek anlamayan insanlar\u0131 doland\u0131rd\u0131. Kaspersky Lab\u2019dan David Jacoby olay\u0131 fark edip, Hindistan polisi olaya el atana kadar \u00e7ok insan\u0131 doland\u0131rd\u0131lar.<\/p>\n<p>Takip\u00e7ilerimiz i\u00e7in senaryo tan\u0131d\u0131k gelebilir: Su\u00e7lular g\u00fcn i\u00e7erisinde rastgele numaralar ar\u0131yorlar. Telefonda kendilerini iyi bilinen bir yaz\u0131l\u0131m \u015firketinden arad\u0131klar\u0131n\u0131 ve kullan\u0131c\u0131n\u0131n bilgisayalar\u0131nda sorun oldu\u011funu s\u00f6yl\u00fcyorlar. Bilgisayarlar hakk\u0131nda pek bir \u015fey bilmeyen kullan\u0131c\u0131lar da bu numaray\u0131 yutuyor. <\/p>\n<p>Kurbanlar\u0131 ikna etmek i\u00e7in, bilgisayarlar\u0131nda bir zararl\u0131 yaz\u0131l\u0131m\u0131n oldu\u011fu ve bilgisayar\u0131 yava\u015flatt\u0131\u011f\u0131 s\u00f6yleniyor. Ayr\u0131ca kullan\u0131c\u0131lardan DOS command\u2019e girerek \u00fcr\u00fcn lisanslar\u0131nda sorun olup olmad\u0131\u011f\u0131n\u0131 kontrol ettiriyorlar. Bu y\u00f6ntem i\u015fe yaramad\u0131\u011f\u0131nda (ki tabi i\u015fe yaramaz, i\u015fletim sistemi lisans\u0131 b\u00f6yle kontrol edilmez) doland\u0131r\u0131c\u0131lar kullan\u0131c\u0131ya kulland\u0131klar\u0131 lisans\u0131n sahte oldu\u011funu s\u00f6yl\u00fcyor. <\/p>\n<p>Daha sonra kurbana uzaktan bilgisayarlar\u0131na m\u00fcdahele edebilecekleri bir program indirtip, olmayan sorunu \u00e7\u00f6zmek i\u00e7in bilgisayarlar\u0131na ba\u011flan\u0131yorlar. Son olarak, doland\u0131r\u0131c\u0131lar sunduklar\u0131 teknik destek ve \u00f6m\u00fcr boyu \u00fccretsiz teknik destek, \u00fccretsiz g\u00fcvenlik ara\u00e7lar\u0131 ve do\u011fru olamayacak kadar iyi ba\u015fka tekliflerle para talep ediyorlar. Hatta baz\u0131 su\u00e7lular kurbanlar\u0131na PayPal kullanmay\u0131 bile \u00f6\u011fretiyor. <\/p>\n<p>Do\u011fal olarak, sahte teknik destek hi\u00e7bir sorunu \u00e7\u00f6zm\u00fcyor (ki ortada sorun da \u00acolmuyor genelde), ve hi\u00e7bir i\u015fe yaramayan programlar y\u00fckl\u00fcyorlar. Bu y\u00f6ntem \u015fa\u015f\u0131rt\u0131c\u0131 \u015fekilde \u00e7ok i\u015fe yar\u0131yor ve siber su\u00e7lulara milyon dolarlar kazand\u0131r\u0131yor. <\/p>\n<p>Plandaki zekice olan nokta da aramalar\u0131n g\u00fcn i\u00e7erisinde yap\u0131lmas\u0131yd\u0131. B\u00f6ylelikle daha ya\u015fl\u0131 insanlar hedef al\u0131narak bilgisayar hakk\u0131nda az bilgileri olmas\u0131ndan yararlan\u0131labilirdi. Ama bug\u00fcnlerde bir\u00e7ok teknolojik bilgiye sahip insan evinden \u00e7al\u0131\u015fabiliyor. Mesela \u00fcst d\u00fczey g\u00fcvenlik uzman\u0131m\u0131z David Jacoby. <\/p>\n<p><span class=\"embed-youtube\" style=\"text-align:center; display: block;\"><iframe class=\"youtube-player\" type=\"text\/html\" width=\"640\" height=\"390\" src=\"https:\/\/www.youtube.com\/embed\/kdhhQhqi_AE?version=3&amp;rel=1&amp;fs=1&amp;showsearch=0&amp;showinfo=1&amp;iv_load_policy=1&amp;wmode=transparent\" frameborder=\"0\" allowfullscreen=\"true\"><\/iframe><\/span><\/p>\n<p>Sahte teknik servisin uzman\u0131m\u0131z\u0131 aramas\u0131 \u00fczerine, uzman\u0131m\u0131z doland\u0131r\u0131c\u0131larla bu oyunu oynamaya karar verdi. Su\u00e7lular\u0131n, kendi bilgisayar\u0131nda bulunan sanal makineye ba\u011flanmalar\u0131na izin verdi, b\u00f6ylelikle planlar\u0131n\u0131 g\u00f6rebilecek ve kan\u0131t yakalayabilecekti. Doland\u0131r\u0131c\u0131lar\u0131 son ad\u0131ma kadar dinledi ve istedikleri her \u015feyi yapt\u0131. Doland\u0131r\u0131c\u0131lar 250$ istedi\u011finde ise \u201ckredi kart\u0131n\u0131n online i\u015flemlere a\u00e7\u0131k olmad\u0131\u011f\u0131n\u0131\u201d belirtti. <\/p>\n<p>Su\u00e7lular\u0131 kendi haz\u0131rlad\u0131\u011f\u0131 ve arkada\u015f\u0131n\u0131n kendi kredi kart\u0131 bilgileri i\u00e7in kulland\u0131\u011f\u0131 bir siteye girmeye ikna etti. Asl\u0131nda sitede sadece tek bir sat\u0131r kod yaz\u0131yordu. Su\u00e7lular siteye girdiklerinde internet sunucusu veriyi (ki veri i\u00e7eri\u011fi su\u00e7lular\u0131n IP adresi ve mail adresleriydi) Jacoby\u2019e g\u00f6nderdi. Ayr\u0131ca arad\u0131klar\u0131 i\u00e7in zaten numaralar\u0131 ve PayPal hesap bilgileri kendisinde mevcuttu. T\u00fcm bu bilgileri PayPal teknik deste\u011fi ve Hindistan polisi ile payla\u015ft\u0131. <\/p>\n<p><strong>Tamamen mutlu biten bir son <\/strong><br>\nO zavall\u0131 doland\u0131r\u0131c\u0131 David Jacoby\u2019I arayal\u0131 d\u00f6rt y\u0131l oldu (Daha detayl\u0131 bilgi i\u00e7in <a href=\"https:\/\/securelist.com\/blog\/incidents\/33734\/trying-to-unmask-the-fake-microsoft-support-scammers-17\/\" target=\"_blank\" rel=\"noopener noreferrer\">ki\u015fisel blo\u011funa<\/a> g\u00f6z atabilirsiniz). Bug\u00fcn bu hikayeyi tekrar anlatmak i\u00e7in bir sebebimiz var. Bu su\u00e7a ortak olan sekiz su\u00e7lu sonunda Hindistan Polisi\u2019nin Siber Su\u00e7 Ara\u015ft\u0131rma dairesi taraf\u0131ndan tutukland\u0131. <\/p>\n<p>Siber su\u00e7larla daha etkili \u015fekilde sava\u015fmak i\u00e7in, kolluk kuvvetleri ve siber g\u00fcvenlik uzmanlar\u0131 i\u015f birli\u011fi i\u00e7erisinde olmal\u0131lar. Yaz\u0131l\u0131m \u015firketlerinin su\u00e7lular\u0131 tutuklayacak yetkilileri yok, kolluk kuvvetlerinin de bizim bilgilerimize, deste\u011fimize ve verilerimize ihtiyac\u0131 var. <\/p>\n<p>Kaspersky Lab ekibi olarak umar\u0131z ba\u015fka \u00fclkelerde de kolluk kuvvetleri ile i\u015f birli\u011fi yapma \u015fans\u0131m\u0131z olur. Asl\u0131nda buna benzer ba\u015fka bir hikayemiz daha var, onu da yak\u0131nda payla\u015faca\u011f\u0131z. Takipte kal\u0131n! <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Birka\u00e7 y\u0131l \u00f6nce, Hindistanl\u0131 bir su\u00e7 \u00f6rg\u00fct\u00fc Avrupa, Avustralya ve \u0130ngiltere&#8217;de bulunan ve teknik olaylardan pek anlamayan insanlar\u0131 doland\u0131rd\u0131. Kaspersky Lab&#8217;dan David Jacoby olay\u0131 fark edip, Hindistan polisi olaya el atana kadar \u00e7ok insan\u0131 doland\u0131rd\u0131lar.<\/p>\n","protected":false},"author":696,"featured_media":2720,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[612,80,1095,1096,549],"class_list":{"0":"post-2719","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-dolandiricilik","9":"tag-fraud","10":"tag-kasperksy-lab","11":"tag-scam","12":"tag-teknik-destek-2"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/indian-techsupport-scam\/2719\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/indian-techsupport-scam\/5759\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/indian-techsupport-scam\/4030\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/indian-techsupport-scam\/10577\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/indian-techsupport-scam\/8150\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/indian-techsupport-scam\/8708\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/indian-techsupport-scam\/9759\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/indian-techsupport-scam\/9504\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/indian-techsupport-scam\/13740\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/indian-techsupport-scam\/13606\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/indian-techsupport-scam\/6453\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/indian-techsupport-scam\/6795\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/indian-techsupport-scam\/5834\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/indian-techsupport-scam\/9387\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/indian-techsupport-scam\/13448\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/indian-techsupport-scam\/13740\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/indian-techsupport-scam\/13606\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/indian-techsupport-scam\/13606\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/dolandiricilik\/","name":"doland\u0131r\u0131c\u0131l\u0131k"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2719","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/696"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2719"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2719\/revisions"}],"predecessor-version":[{"id":7102,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2719\/revisions\/7102"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2720"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2719"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2719"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}