{"id":3100,"date":"2017-04-14T02:51:47","date_gmt":"2017-04-14T06:51:47","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=3100"},"modified":"2019-11-15T14:52:02","modified_gmt":"2019-11-15T11:52:02","slug":"pegasus-spyware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/pegasus-spyware\/3100\/","title":{"rendered":"Pegasus: iOS ve Android&#8217;teki nihai casusluk yaz\u0131l\u0131m\u0131"},"content":{"rendered":"<p>iPhone ve iPad kullan\u0131c\u0131lar\u0131 genellikle g\u00fcvende olduklar\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcrler. iOS i\u00e7in zararl\u0131 yaz\u0131l\u0131m olmad\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcrler. Apple\u2019\u0131n anti vir\u00fcs \u00e7\u00f6z\u00fcmlerine izin vermeyen marketi de kullan\u0131c\u0131lar\u0131n bu g\u00f6r\u00fc\u015flerini s\u00fcrd\u00fcrmesinin en b\u00fcy\u00fck sebeplerinden biri.<\/p>\n<p>Buradaki anahtar kelime \u201ciddia etmek\u201d. Asl\u0131nda iOS\u2019u hedef alan zararl\u0131 yaz\u0131l\u0131m mevcut \u2013 birka\u00e7 \u00f6rne\u011fi de var. 2016 A\u011fustos\u2019unda ara\u015ft\u0131rmac\u0131lar istenilen iPhone ve iPad cihazlar\u0131 hackleyip, kurban hakk\u0131nda verileri toparlayabildikleri, casus yaz\u0131l\u0131m Pegasus\u2019un varl\u0131\u011f\u0131n\u0131n ba\u015flang\u0131c\u0131ndan <a href=\"https:\/\/blog.lookout.com\/blog\/2016\/08\/25\/trident-pegasus\/\" target=\"_blank\" rel=\"noopener nofollow\">haber verdiler<\/a>. Bu ke\u015fif t\u00fcm siber d\u00fcnyay\u0131 huzursuz etti.<\/p>\n<p>D\u00fczenledi\u011fimiz <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-sas\/14411\/\" target=\"_blank\" rel=\"noopener nofollow\">Security Analyst Summit<\/a>\u2018te, Lookout\u2019tan ara\u015ft\u0131rmac\u0131lar Pegasus\u2019un sadece iOS i\u00e7in de\u011fil, Android i\u00e7in de tehdit oldu\u011funu <a href=\"https:\/\/blog.lookout.com\/blog\/2017\/04\/03\/pegasus-android\/\" target=\"_blank\" rel=\"noopener nofollow\">belirttiler<\/a>. Android versiyonu, iOS versiyonuna g\u00f6re baz\u0131 farkl\u0131l\u0131klar g\u00f6steriyor. \u015eimdi Pegasus\u2019a d\u00f6nelim ve niye \u201cnihai\u201d dedi\u011fimizi a\u00e7\u0131klayal\u0131m.<\/p>\n<h2>Pegasus: Ba\u015flang\u0131\u00e7<\/h2>\n<p>Pegasus, Birle\u015fik Arap Emirlikleri insan haklar\u0131 aktivisti <a href=\"https:\/\/en.wikipedia.org\/wiki\/UAE_Five\" target=\"_blank\" rel=\"noopener nofollow\">Ahmed Mansoor<\/a> taraf\u0131ndan ke\u015ffedildi. Bu hedefli bir oltalama sald\u0131r\u0131s\u0131yd\u0131: \u0130\u00e7erisinde zararl\u0131 link oldu\u011funu d\u00fc\u015f\u00fcnd\u00fc\u011f\u00fc SMS mesajlar\u0131 alan Ahmed, bunlar\u0131 Citizen Lab\u2019a iletti. Bu kurulu\u015f da ara\u015ft\u0131rmas\u0131 i\u00e7in ba\u015fka bir g\u00fcvenlik firmas\u0131 olan Lookout\u2019a g\u00f6nderdi.<\/p>\n<p>Mansoor yan\u0131lmad\u0131. E\u011fer linke t\u0131klam\u0131\u015f olsayd\u0131, iPhonu\u2019na jailbreak i\u015flemi yap\u0131lmam\u0131\u015f iOS\u2019lar i\u00e7in yaz\u0131lm\u0131\u015f zararl\u0131 yaz\u0131l\u0131m bula\u015facakt\u0131. Lookout ara\u015ft\u0131rmac\u0131lar\u0131 \u015fimdiye kadar g\u00f6rd\u00fckleri en karma\u015f\u0131k u\u00e7 nokta zararl\u0131 yaz\u0131l\u0131m\u0131 oldu\u011funu belirtti ve bu yaz\u0131l\u0131ma Pegasus ad\u0131n\u0131 verdiler.<\/p>\n<p>Pegasus\u2019un alt\u0131ndan \u0130srailli zararl\u0131 yaz\u0131l\u0131m geli\u015ftiricisi NSO Group \u00e7\u0131kt\u0131. Bunun anlam\u0131 \u015fu, Pegasus en fazla teklifi verene sat\u0131lan ticari bir yaz\u0131l\u0131m. Pegasus\u2019un \u00e7al\u0131\u015fma mant\u0131\u011f\u0131 daha \u00f6nceden bilinmeyen (Zero day) g\u00fc\u00e7l\u00fc bir a\u00e7\u0131\u011fa dayan\u0131yor. Bu a\u00e7\u0131k iOS cihaza sessizce jailbreak i\u015flemi yaparak casusluk yaz\u0131l\u0131m\u0131 y\u00fckl\u00fcyor. Ba\u015fka bir siber g\u00fcvenlik firmas\u0131 olan Zerodium bir defas\u0131nda iOS\u2019un zero-day a\u00e7\u0131\u011f\u0131 i\u00e7in 1 milyon dolar para teklif etmi\u015fti, yani Pegasus\u2019un epey maliyetli oldu\u011funu s\u00f6yleyebiliriz.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">An emergency <a href=\"https:\/\/twitter.com\/hashtag\/iOS?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#iOS<\/a> update patches <a href=\"https:\/\/twitter.com\/hashtag\/0day?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#0day<\/a> used by government spyware <a href=\"https:\/\/t.co\/VyDbMcHRGL\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/VyDbMcHRGL<\/a> <a href=\"https:\/\/t.co\/6U8nX0baXY\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/6U8nX0baXY<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/769149977490780160?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">August 26, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Casusluk demi\u015fken biraz daha a\u00e7\u0131klayal\u0131m: Tam anlam\u0131yla casusluktan bahsediyoruz. Pegasus mod\u00fcler bir zararl\u0131 yaz\u0131l\u0131m. Bula\u015ft\u0131\u011f\u0131 cihaz\u0131 tarad\u0131ktan sonra, kurban\u0131n mesajlar\u0131n\u0131 ve maillerini okuyacak, aramalar\u0131n\u0131 dinleyecek, ekran g\u00f6r\u00fcnt\u00fcleri alacak, bas\u0131lan tu\u015flar\u0131 ve yaz\u0131lan harfleri kaydedecek, taray\u0131c\u0131 ge\u00e7mi\u015fini \u00e7ekecek, rehbere eri\u015fecek ve ba\u015fka \u015feyler yapacak ek mod\u00fcller y\u00fckl\u00fcyor. K\u0131saca, kurban\u0131n tam anlam\u0131yla her \u015feyini \u00f6\u011frenmek \u00fczere kurul bir zararl\u0131 yaz\u0131l\u0131m.<\/p>\n<p>\u015eunu da belirtmekte fayda var, Pegasus tu\u015f kaydetme ve ses kaydetme \u00f6zellikleri sayesinde \u015fifrelenmi\u015f ses yay\u0131nlar\u0131n\u0131 ve \u015fifrelenmi\u015f mesajlar\u0131 da okuyabiliyor. Mesajlar \u015fifrelenmeden \u00f6nce (yaz\u0131ld\u0131\u011f\u0131 s\u0131rada) \u00e7al\u0131yor, gelen mesajlar\u0131 da \u015fifresi \u00e7\u00f6z\u00fcld\u00fckten sonra \u00e7al\u0131yor.<\/p>\n<p>Di\u011fer ilgin\u00e7 bilgi ise bu yaz\u0131l\u0131m\u0131n kendini son derece \u00f6zenle gizlemesi. E\u011fer y\u00f6netim ve kontrol sunucusu ile 60 g\u00fcnden fazla ileti\u015fime ge\u00e7emezse, yanl\u0131\u015f bir cihaza veya yanl\u0131\u015f bir SIM kart olan cihaza y\u00fcklenirse yaz\u0131l\u0131m kendini siliyor (Hat\u0131rlay\u0131n, bu hedefli bir sald\u0131r\u0131; NSO\u2019nun m\u00fc\u015fterileri rastgele kullan\u0131c\u0131lar\u0131n pe\u015finde de\u011filler).<\/p>\n<h2>T\u00fcm g\u00fczel atlar<\/h2>\n<p>Belki de Pegasus\u2019un geli\u015ftiricileri bu yaz\u0131l\u0131m \u00fczerine \u00e7ok durduklar\u0131n\u0131 ve tek bir platform ile s\u0131n\u0131rlaman\u0131n do\u011fru olmad\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcnd\u00fcler. \u0130lk versiyon ke\u015ffedildikten sonra, ikincisini bulmak uzun s\u00fcrmedi. Security Analyst Summit 2017\u2019de, Lookout ara\u015ft\u0131rmac\u0131lar\u0131 Android\u2019teki Pegasus \u2013 ki Google buna Chrysaor diyor, hakk\u0131nda konu\u015fma yapt\u0131lar. Kapasite olarak Android versiyonu iOS versiyonuna \u00e7ok benziyor ancak teknik olarak farkl\u0131l\u0131k g\u00f6steriyor.<\/p>\n<p>Android i\u00e7in Pegasus zero-day a\u00e7\u0131klar\u0131n\u0131 kullan\u0131yor. Aksine \u00e7ok iyi bilinen root y\u00f6ntemi olan Framaroot\u2019u kullan\u0131yor. Di\u011fer bir fark: E\u011fer iOS versiyonu cihaza jailbreak yapmay\u0131 ba\u015faramazsa, t\u00fcm sald\u0131r\u0131 ba\u015far\u0131s\u0131z oluyor. Ancak Android versiyonunda zararl\u0131 yaz\u0131l\u0131m root i\u015fleminde ba\u015far\u0131l\u0131 olamazsa ba\u015fka bir casusluk yaz\u0131l\u0131m\u0131 indiriyor ve en az\u0131ndan baz\u0131 verileri alabilmek i\u00e7in kullan\u0131c\u0131dan direkt olarak izin istiyor.<\/p>\n<p>Google bu sald\u0131r\u0131dan sadece birka\u00e7 d\u00fczine Android cihaz\u0131n etkilendi\u011fini <a href=\"https:\/\/security.googleblog.com\/2017\/04\/an-investigation-of-chrysaor-malware-on.html\" target=\"_blank\" rel=\"noopener nofollow\">s\u00f6yl\u00fcyor<\/a>. Ancak hedefli casusluk sald\u0131r\u0131s\u0131 i\u00e7in bu say\u0131 \u00e7ok fazla. En \u00e7ok Android i\u00e7in Pegasus sald\u0131r\u0131s\u0131 \u0130srail\u2019de g\u00f6r\u00fcld\u00fc. \u0130kinci s\u0131rada G\u00fcrcistan ve \u00fc\u00e7\u00fcnc\u00fc s\u0131rada Meksika var. Ayr\u0131ca bu zararl\u0131 yaz\u0131l\u0131m T\u00fcrkiye, Kenya, Nijerya, Birle\u015fik Arap Emirlikleri ve baz\u0131 di\u011fer \u00fclkelerde g\u00f6r\u00fcld\u00fc.<\/p>\n<p>https:\/\/twitter.com\/josephfcox\/status\/849137702889033729<\/p>\n<h2>Muhtemelen g\u00fcvendesinizdir ama\u2026<\/h2>\n<p>iOS\u2019u etkileyen Pegasus haberleri \u00e7\u0131kt\u0131\u011f\u0131nda Apple h\u0131zl\u0131ca davranarak 9.3.5 g\u00fcncellemesi \u00e7\u0131kartt\u0131 ve bahsi ge\u00e7en 3 sistem a\u00e7\u0131\u011f\u0131n\u0131 d\u00fczeltti.<\/p>\n<p>Android versiyonundaki olay\u0131 ara\u015ft\u0131rmaya yard\u0131m eden Google, potansiyel tehdit alt\u0131ndaki kullan\u0131c\u0131lar\u0131 direkt olarak uyard\u0131. E\u011fer iOS g\u00fcncellemesini yapt\u0131ysan\u0131z veya Google\u2019dan uyar\u0131 mesaj\u0131 almad\u0131ysan\u0131z, b\u00fcy\u00fck ihtimalle g\u00fcvendesinizdir.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3102\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2017\/04\/06013328\/what-is-sas-5.png\" alt=\"\" width=\"951\" height=\"341\"><\/p>\n<p>Ama bu hen\u00fcz ke\u015ffedilememi\u015f bir zararl\u0131 yaz\u0131l\u0131m olmad\u0131\u011f\u0131 anlam\u0131na gelmiyor. Pegasus\u2019un varl\u0131\u011f\u0131 bize iOS zararl\u0131 yaz\u0131l\u0131mlar\u0131n\u0131n basit\u00e7e engellenebilen fidye yaz\u0131l\u0131mlar\u0131ndan ve reklam vir\u00fcslerinden \u00e7ok daha karma\u015f\u0131k oldu\u011funu g\u00f6sterdi. D\u0131\u015far\u0131da ba\u015fka tehlikeler de olabilir. M\u00fcmk\u00fcn oldu\u011funca g\u00fcvende kalman\u0131z i\u00e7in \u00fc\u00e7 \u00f6nerimiz var:<\/p>\n<ol>\n<li>Cihaz\u0131n\u0131z\u0131 zaman\u0131nda g\u00fcncelleyin. G\u00fcvenlik g\u00fcncellemelerine \u00f6zellikle ilgi g\u00f6sterin.<\/li>\n<li>Cihazlar\u0131n\u0131z i\u00e7in g\u00fc\u00e7l\u00fc bir <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.kms.free&amp;referrer=af_tranid%3DpyO-XzswhgmixgcPwx0nyA%26pid%3Dsmm%26c%3Dww_kdaily\" target=\"_blank\" rel=\"noopener nofollow\">antivir\u00fcs<\/a> \u00e7\u00f6z\u00fcm\u00fc kullan\u0131n. iOS i\u00e7in \u015fimdilik b\u00f6yle bir \u015fey yok ancak umar\u0131z bu olaydan sonra Apple de\u011fi\u015fiklik yapmaya karar verir.<\/li>\n<li>Oltalama sald\u0131r\u0131lar\u0131na kar\u015f\u0131 dikkatli olun, \u00f6zellikle Ahmed Mansoor\u2019a yap\u0131lan <a href=\"https:\/\/usa.kaspersky.com\/resource-center\/definitions\/spear-phishing#.WOuMffnyupo\" target=\"_blank\" rel=\"noopener\">hedefli oltalama sald\u0131r\u0131lar\u0131<\/a> gibilerine. Bilinmeyen kaynaktan ald\u0131\u011f\u0131n\u0131z linklere t\u0131klamay\u0131n. T\u0131klay\u0131p t\u0131klamaman\u0131z hakk\u0131nda d\u00fc\u015f\u00fcn\u00fcn.<\/li>\n<\/ol>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"tr\" dir=\"ltr\">Test: \u0130nternetteki doland\u0131r\u0131c\u0131l\u0131klar\u0131 fark edebilir misin? <a href=\"https:\/\/t.co\/LG6ENagHTx\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/LG6ENagHTx<\/a> <a href=\"https:\/\/t.co\/zlYllPoOUj\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/zlYllPoOUj<\/a><\/p>\n<p>\u2014 Kaspersky T\u00fcrkiye (@KasperskyTR) <a href=\"https:\/\/twitter.com\/KasperskyTR\/status\/801321451055890432?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">November 23, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>iPhone ve iPad kullan\u0131c\u0131lar\u0131 genellikle g\u00fcvende olduklar\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcrler. iOS i\u00e7in zararl\u0131 yaz\u0131l\u0131m olmad\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcrler. Apple&#8217;\u0131n anti vir\u00fcs \u00e7\u00f6z\u00fcmlerine izin vermeyen marketi de kullan\u0131c\u0131lar\u0131n bu g\u00f6r\u00fc\u015flerini s\u00fcrd\u00fcrmesinin en b\u00fcy\u00fck sebeplerinden biri.<\/p>\n","protected":false},"author":696,"featured_media":3101,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1352,1351],"tags":[1183,105,1193,1189,1192,750,1190,337,1191,1116],"class_list":{"0":"post-3100","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-special-projects","9":"category-threats","10":"tag-thesas2017","11":"tag-android","12":"tag-casus-yazilimi","13":"tag-chrysaoir","14":"tag-hedefli-oltalama","15":"tag-ios","16":"tag-pegasus","17":"tag-sas","18":"tag-sas-2017","19":"tag-spyware"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/pegasus-spyware\/3100\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/pegasus-spyware\/11002\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/pegasus-spyware\/9077\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/pegasus-spyware\/10374\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/pegasus-spyware\/10058\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/pegasus-spyware\/14569\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/pegasus-spyware\/14604\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/pegasus-spyware\/7237\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/pegasus-spyware\/6551\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/pegasus-spyware\/10046\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/pegasus-spyware\/15217\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/pegasus-spyware\/14604\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/pegasus-spyware\/14604\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/sas\/","name":"SAS"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/3100","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/696"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=3100"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/3100\/revisions"}],"predecessor-version":[{"id":7071,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/3100\/revisions\/7071"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/3101"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=3100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=3100"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=3100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}