{"id":3677,"date":"2017-08-18T11:01:05","date_gmt":"2017-08-18T08:01:05","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=3677"},"modified":"2019-11-15T14:49:17","modified_gmt":"2019-11-15T11:49:17","slug":"faketoken-trojan-taxi","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/faketoken-trojan-taxi\/3677\/","title":{"rendered":"Taksi Trojanlar\u0131 yolda"},"content":{"rendered":"<p>\u00c7ok aceleniz var. \u0130\u015fe, toplant\u0131ya veya ba\u015fka bir randevunuza ge\u00e7 kal\u0131yorsunuz. Taksi \u00e7a\u011f\u0131rmak i\u00e7in kulland\u0131\u011f\u0131n\u0131z uygulamay\u0131 a\u00e7\u0131yorsunuz ancak uygulama sizden kredi kart\u0131 numaran\u0131z\u0131 girmenizi istiyor. \u015e\u00fcphelenir miydiniz? Pek \u015f\u00fcphelenmezdiniz \u00e7\u00fcnk\u00fc uygulamalar bazen bilgilerimizi unutabiliyor, silebiliyorlar ve bilgileri tekrar girmek zorunda kalabiliyorsunuz.<\/p>\n<p>Bir s\u00fcre sonra hesab\u0131n\u0131zdan para gitti\u011fini g\u00f6r\u00fcyorsunuz. Peki ne oldu? Yeni bir mobil trojan kurban\u0131 olabilirsiniz. \u00c7\u00fcnk\u00fc ge\u00e7enlerde <a href=\"https:\/\/securelist.com\/booking-a-taxi-for-faketoken\/81457\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">taksi \u00e7a\u011f\u0131rma uygulamalar\u0131n\u0131n ara y\u00fcz\u00fcne sahip banka bilgileri \u00e7alan yeni bir zararl\u0131 yaz\u0131l\u0131m ke\u015ffedildi<\/a>.<\/p>\n<p>Faketoken Trojan\u0131 y\u0131llard\u0131r mevcut ve y\u0131llar i\u00e7erisinde s\u00fcrekli g\u00fcncellendi. Uzmanlar\u0131m\u0131z bu g\u00fcncel s\u00fcr\u00fcme \u201cFaketoken.q,\u201d ad\u0131n\u0131 verdi.<\/p>\n<p>Bu zararl\u0131 yaz\u0131l\u0131m ak\u0131ll\u0131 telefona girdikten sonra (ikondan yola \u00e7\u0131karak, Faketoken\u2019in telefona gelen ve foto\u011fraf indirme ba\u011flant\u0131s\u0131yla bula\u015ft\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcyoruz) \u00f6nemli mod\u00fclleri y\u00fckl\u00fcyor. Trojan k\u0131sa yolunu sakl\u0131yor ve sistemde olan her \u015feyi arka planda izlemeye ba\u015fl\u0131yor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3679\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2017\/08\/18100139\/faketoken-installed.jpg\" alt=\"\" width=\"768\" height=\"570\"><\/p>\n<p>\u00d6ncelik, trojan kullan\u0131c\u0131n\u0131n yapt\u0131\u011f\u0131 aramalar\u0131 dinliyor. Kullan\u0131c\u0131n\u0131n yapt\u0131\u011f\u0131 aramalar\u0131 kaydederek, konu\u015fma sonras\u0131nda bu konu\u015fmalar\u0131 su\u00e7lular\u0131n sunucusuna g\u00f6nderiyor. Daha sonra, trojan kullan\u0131c\u0131n\u0131n sahip oldu\u011fu uygulamalar\u0131 kontrol ediyor.<\/p>\n<p>Faketoken zararl\u0131 yaz\u0131l\u0131m\u0131, aray\u00fcz\u00fcn\u00fc taklit edebilece\u011fi bir uygulama ke\u015ffederse, hemen taklit edebilece\u011fi uygulaman\u0131n \u00fczerine kendi ekran\u0131n\u0131 yerle\u015ftiriyor. Bunu yapmak i\u00e7in ise standart Android \u00f6zelli\u011fi olan e<a href=\"https:\/\/www.kaspersky.com.tr\/blog\/cloak-and-dagger-attack\/3248\/\" target=\"_blank\" rel=\"noopener\">kran katman\u0131n\u0131 di\u011fer uygulamalar \u00fczerinde g\u00f6stermeyi<\/a> kullan\u0131yor. Messenger, Windows Manager ve bir\u00e7ok yayg\u0131n kullan\u0131lan uygulama bu \u00f6zelli\u011fi kullan\u0131yor.<\/p>\n<p>\u00dczerine yerle\u015fen ekran ger\u00e7ek uygulaman\u0131n renkleri ile e\u015fle\u015fiyor. Bu ekranda trojan kullan\u0131c\u0131dan kredi kart\u0131 bilgilerini ve kart\u0131n arkas\u0131nda bulunan CVC kodunu girmesini istiyor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3680\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2017\/08\/18101619\/faketoken-stealing-interface.jpg\" alt=\"\" width=\"1600\" height=\"1280\"><\/p>\n<p>Faketoken.q gibi uygulamalar\u0131n ortak tek bir amac\u0131 vard\u0131r: taklit ettikleri \u00f6deme ekran\u0131n\u0131n \u015f\u00fcphe \u00e7ekmeyecek kadar ger\u00e7ek\u00e7i olmas\u0131. Bug\u00fcne kadar bu \u015fekilde sald\u0131r\u0131ya u\u011frayan bir\u00e7ok uygulama oldu, Android Pay, Google Play Store, u\u00e7ak ve otel uygulamalar\u0131, trafik cezas\u0131 \u00f6deme uygulamalar\u0131 ve \u015fimdi de taksi uygulamalar\u0131.<\/p>\n<p>Faketoken\u2019in para \u00e7almak i\u00e7in yapt\u0131\u011f\u0131 \u015feylerden biri de, cep telefonuna gelen SMS mesajlar\u0131n\u0131 kullan\u0131c\u0131dan gizleyerek <a href=\"https:\/\/www.kaspersky.com\/blog\/banking-trojans-bypass-2fa\/11545\/\" target=\"_blank\" rel=\"noopener nofollow\">su\u00e7lulara g\u00f6ndermesi<\/a>. B\u00f6ylelikle su\u00e7lular cep telefonuna gelen tek kullan\u0131ml\u0131k onay kodunu girerek \u00f6demeyi ger\u00e7ekle\u015ftirebiliyorlar.<\/p>\n<p>Az say\u0131daki sald\u0131r\u0131dan ve yukar\u0131da g\u00f6rebilece\u011fini kullan\u0131c\u0131 aray\u00fcz\u00fcnden anlad\u0131\u011f\u0131m\u0131z kadar\u0131yla, ara\u015ft\u0131rmac\u0131lar\u0131n ele ge\u00e7irdikleri bu Torjan, <a href=\"https:\/\/securelist.com\/booking-a-taxi-for-faketoken\/81457\/\" target=\"_blank\" rel=\"noopener\">Trojan\u0131n bitmi\u015f hali de\u011fil sadece test versiyonu<\/a>.<\/p>\n<p>Faketoken\u2019in yarat\u0131c\u0131lar\u0131na hakk\u0131n\u0131 vermemiz gerek. B\u00fcy\u00fck ihtimalle trojan\u0131 \u015fu an geli\u015ftiriyorlard\u0131r. Ve b\u00fcy\u00fck ihtimalle daha b\u00fcy\u00fck bir sald\u0131r\u0131 dalgas\u0131 ya\u015fayaca\u011f\u0131z.<\/p>\n<p>Bu Trojan \u015fimdilik Rusya\u2019daki kullan\u0131c\u0131lara odaklanm\u0131\u015f durumda. Ancak \u00f6nceden de \u00f6rneklerini g\u00f6rd\u00fc\u011f\u00fcm\u00fcz gibi, siber su\u00e7lular birbirlerinin fikirlerini \u00e7al\u0131p kendi \u00fclkelerinde de ayn\u0131s\u0131n\u0131 yaparlar. K\u0131sacas\u0131 bu sald\u0131r\u0131 t\u00fcr\u00fcn\u00fc di\u011fer \u00fclkelerde de yak\u0131nda g\u00f6rebiliriz. Taksi uygulamalar\u0131 g\u00fcn ge\u00e7tik\u00e7e artmakta, bu da su\u00e7lular i\u00e7in uygun zemini haz\u0131rlamaktad\u0131r.<\/p>\n<p>A\u015fa\u011f\u0131da kendinizi Faketoken\u2019a ve benzer tehditlere kar\u015f\u0131 nas\u0131l koruyaca\u011f\u0131n\u0131zdan bahsetti\u011fimiz ipu\u00e7lar\u0131na g\u00f6z atabilirsiniz.<\/p>\n<ul>\n<li>Android ayarlar\u0131nda bilinmeyen kaynaklardan yap\u0131lan y\u00fcklemeleri engellemeniz \u00e7ok \u00f6nemli. Bunun i\u00e7in Ayarlar \u2013 G\u00fcvenlik k\u0131sm\u0131ndaki Bilinmeyen Kaynaklar\u2019dan i\u015fareti kald\u0131r\u0131n.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3681\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2017\/08\/18102652\/unknown-sources-EN.jpg\" alt=\"\" width=\"1080\" height=\"750\"><\/p>\n<ul>\n<li>Bir uygulama y\u00fcklerken mutlaka uygulaman\u0131n eri\u015fmek istedi\u011fi izinlere dikkat edin. Google Play\u2019den de indirmi\u015f olsan\u0131z (Resmi uygulama ma\u011fazalar\u0131nda da trojanlar olabiliyor) izinler konusunda \u00e7ok dikkatli olun. Android izinleri hakk\u0131nda \u015fu yaz\u0131m\u0131za g\u00f6z atabilirsiniz.<\/li>\n<li>Ak\u0131ll\u0131 telefonunuza g\u00fcvenlik uygulamas\u0131 indirmeniz iyi bir ad\u0131md\u0131r. B\u00f6ylelikle uygulamalar\u0131n yapt\u0131\u011f\u0131 zararl\u0131 davran\u0131\u015flar\u0131 ke\u015ffedebilirsiniz. Kaspersky Internet Security for Android \u00fcr\u00fcn\u00fcm\u00fcz\u00fc Google Play\u2019den \u00fccretsiz indirebilirsiniz.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"android-malware\">\n","protected":false},"excerpt":{"rendered":"<p>\u00c7ok aceleniz var. \u0130\u015fe, toplant\u0131ya veya ba\u015fka bir randevunuza ge\u00e7 kal\u0131yorsunuz. Taksi \u00e7a\u011f\u0131rmak i\u00e7in kulland\u0131\u011f\u0131n\u0131z uygulamay\u0131 a\u00e7\u0131yorsunuz ancak uygulama sizden kredi kart\u0131 numaran\u0131z\u0131 girmenizi istiyor. \u015e\u00fcphelenir miydiniz? Pek \u015f\u00fcphelenmezdiniz \u00e7\u00fcnk\u00fc uygulamalar bazen bilgilerimizi unutabiliyor, silebiliyorlar ve bilgileri tekrar girmek zorunda kalabiliyorsunuz.<\/p>\n","protected":false},"author":421,"featured_media":3678,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1351],"tags":[105,1045,1322,685,1323,537,889],"class_list":{"0":"post-3677","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-android","10":"tag-bankacilik-trojani","11":"tag-faketoken","12":"tag-mobil-cihaz","13":"tag-taksi","14":"tag-tehditler","15":"tag-trojanlar"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/faketoken-trojan-taxi\/3677\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/faketoken-trojan-taxi\/11105\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/faketoken-trojan-taxi\/9203\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/faketoken-trojan-taxi\/4942\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/faketoken-trojan-taxi\/12435\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/faketoken-trojan-taxi\/11642\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/faketoken-trojan-taxi\/11170\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/faketoken-trojan-taxi\/14102\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/faketoken-trojan-taxi\/14119\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/faketoken-trojan-taxi\/18462\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/faketoken-trojan-taxi\/18002\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/faketoken-trojan-taxi\/9380\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/faketoken-trojan-taxi\/9584\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/faketoken-trojan-taxi\/7246\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/faketoken-trojan-taxi\/14446\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/faketoken-trojan-taxi\/8321\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/faketoken-trojan-taxi\/17610\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/faketoken-trojan-taxi\/17725\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/faketoken-trojan-taxi\/17694\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/android\/","name":"android"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/3677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/421"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=3677"}],"version-history":[{"count":5,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/3677\/revisions"}],"predecessor-version":[{"id":7038,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/3677\/revisions\/7038"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/3678"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=3677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=3677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=3677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}