{"id":4552,"date":"2017-12-21T14:45:19","date_gmt":"2017-12-21T11:45:19","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=4552"},"modified":"2019-11-15T14:45:23","modified_gmt":"2019-11-15T11:45:23","slug":"loapi-trojan","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/loapi-trojan\/4552\/","title":{"rendered":"Loapi &#8211; Bu Truva At\u0131 Telefonunuzu Yakabilir!"},"content":{"rendered":"<p>Vir\u00fcs programc\u0131lar\u0131, Android cihaz kullan\u0131c\u0131lar\u0131 i\u00e7in \u00e7e\u015fitli s\u0131k\u0131nt\u0131lar yaratmaya devam ediyor. Hepimiz ki\u015fisel veri h\u0131rs\u0131zl\u0131\u011f\u0131n\u0131 ve bu verilerin karaborsaya d\u00fc\u015ft\u00fc\u011f\u00fcn\u00fc, kredi kartlar\u0131ndan s\u0131zd\u0131r\u0131lan paralar\u0131 biliyoruz. Ancak cihaz\u0131n\u0131z\u0131n ger\u00e7ekten yan\u0131p k\u00fcl olmas\u0131na neden olan bu Truva At\u0131\u2019n\u0131 daha \u00f6nce duymu\u015f muydunuz? Duymad\u0131ysan\u0131z bu <a href=\"https:\/\/securelist.com\/jack-of-all-trades\/83470\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">yaz\u0131m\u0131z\u0131<\/a> okuyabilirsiniz.<\/p>\n<h2>Bu \u00e7ok becerikli Loapi Truva At\u0131 nas\u0131l \u00e7al\u0131\u015f\u0131r?<\/h2>\n<p>Loapi Truva At\u0131, kullan\u0131c\u0131lar\u0131n cihazlar\u0131na bir reklama t\u0131kland\u0131\u011f\u0131nda veya sahte bir AV ya da yeti\u015fkinlere y\u00f6nelik reklamlar indirildi\u011finde (bu Truva At\u0131\u2019n\u0131n en \u00e7ok kulland\u0131\u011f\u0131 ara\u00e7lar) bula\u015f\u0131r. Y\u00fcklemeden sonra Loapi cihaz\u0131n\u0131zdan y\u00f6netici haklar\u0131 ister ve \u201cHay\u0131r\u201d cevab\u0131n\u0131 hi\u00e7bir \u015fekilde kabul etmez. \u00c7aresiz kullan\u0131c\u0131 en sonunda pes edip TAMAM\u2019a t\u0131klayana kadar ekranda bildirim \u00fcst\u00fcne bildirim \u00e7\u0131kar.<\/p>\n<p>Ak\u0131ll\u0131 telefonun sahibi daha sonra bu uygulaman\u0131n y\u00f6netici haklar\u0131n\u0131 elinden almaya \u00e7al\u0131\u015f\u0131rsa Truva At\u0131 ekran\u0131 kilitler ve ayarlar penceresini kapat\u0131r. Kullan\u0131c\u0131, ger\u00e7ekten cihaz\u0131n\u0131 koruyacak uygulamalar indirmeye \u00e7al\u0131\u015f\u0131rsa (\u00f6rne\u011fin; sahte olmayan ger\u00e7ek bir antivir\u00fcs gibi) Loapi bunlar\u0131n k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m oldu\u011funu bildirerek kald\u0131r\u0131lmas\u0131n\u0131 ister. Bu bildirim kullan\u0131c\u0131 pes edene kadar hi\u00e7 durmadan \u00e7\u0131kmaya devam eder.<\/p>\n<div id=\"attachment_4554\" style=\"width: 1162px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4554\" class=\"wp-image-4554 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2017\/12\/21142222\/loapi-hidden-in-apps.jpeg\" alt=\"\" width=\"1152\" height=\"603\"><p id=\"caption-attachment-4554\" class=\"wp-caption-text\">Loapi\u2019nin kendini gizledi\u011fi sahte uygulamalar\u0131n simgeleri<\/p><\/div>\n<p>Loapi, mod\u00fcler yap\u0131s\u0131 sayesinde kendi ba\u015f\u0131na gerekli eklentileri indirip y\u00fckleyerek uzak sunucunun komutas\u0131nda i\u015flevlerini de\u011fi\u015ftirebilir. Bu yeni Truva At\u0131\u2019n\u0131n bula\u015fmas\u0131 durumunda kar\u015f\u0131la\u015fabilece\u011finiz baz\u0131 sonu\u00e7lar\u0131 inceleyelim.<\/p>\n<h2>1. \u0130stenmeyen reklamlar<\/h2>\n<p>Loapi, ak\u0131ll\u0131 telefon sahibini hi\u00e7 durmadan bannerlara ve video reklamlara bo\u011far. Truva At\u0131\u2019n\u0131n bu mod\u00fcl\u00fc ayr\u0131ca ba\u015fka uygulamalar\u0131 indirebilir ve y\u00fckleyebilir, ba\u011flant\u0131lar\u0131 ziyaret edebilir ve Facebook, Instagram ve VKontakte gibi sitelerde sayfalar a\u00e7abilir. T\u00fcm bunlar\u0131n amac\u0131 muhtemelen \u00e7e\u015fitli puanlar\u0131 art\u0131rmakt\u0131r.<\/p>\n<h2>2. \u00dccretli Abonelikler<\/h2>\n<p>Truva At\u0131\u2019n\u0131n ba\u015fka bir mod\u00fcl\u00fc kullan\u0131c\u0131lar\u0131n \u00fccretli hizmetlere \u00fcye olmas\u0131na neden olur. Bu t\u00fcr aboneliklerin genellikle SMS yoluyla do\u011frulanmas\u0131 gerekir. Ancak bu da Loapi\u2019yi durdurmaz. Gerekli numaraya gizlice mesaj g\u00f6nderen \u00f6zel bir mod\u00fcle daha sahiptir. Ayr\u0131ca t\u00fcm mesajlar (hem g\u00f6nderilen hem de gelen mesajlar) an\u0131nda silinir.<\/p>\n<h2>3. DDoS sald\u0131r\u0131lar\u0131<\/h2>\n<p>Truva At\u0131, telefonunuzu bir zombiye d\u00f6n\u00fc\u015ft\u00fcrerek Web kaynaklar\u0131na kar\u015f\u0131 d\u00fczenlenen <a href=\"https:\/\/securelist.com\/threats\/dos-denial-of-service-attack-glossary\/\" target=\"_blank\" rel=\"noopener\">DDoS sald\u0131r\u0131lar\u0131nda<\/a> kullanabilir. Bunu yapmak i\u00e7in dahili bir Proxy sunucu kullan\u0131r ve vir\u00fcsl\u00fc cihazdan HTTP talepleri g\u00f6nderir.<\/p>\n<h2>4. Kriptomadencilik<\/h2>\n<p>Loapi, ak\u0131ll\u0131 telefonunuzu kullanarak Monero tokenleri i\u00e7in madencilik de yapar. Bu i\u015flem nedeniyle i\u015flemciniz maksimum y\u00fck alt\u0131nda uzun bir s\u00fcre boyunca \u00e7al\u0131\u015farak cihaz\u0131n\u0131z\u0131n a\u015f\u0131r\u0131 \u0131s\u0131nmas\u0131na neden olur. Ara\u015ft\u0131rmalar\u0131m\u0131z s\u0131ras\u0131nda test etti\u011fimiz ak\u0131ll\u0131 telefonunun bataryas\u0131, Truva At\u0131\u2019n\u0131n cihaza bula\u015fmas\u0131ndan 48 saat sonra yand\u0131.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4555\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2017\/12\/21142719\/loapi-battery-overheat-photo.jpg\" alt=\"\" width=\"960\" height=\"600\"><\/p>\n<h2>5. Yeni mod\u00fcller indirme<\/h2>\n<p>Bu i\u015flev, Truva At\u0131\u2019n\u0131n en ilgin\u00e7 yan\u0131. K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, bir uzak sunucunun komutas\u0131nda yeni mod\u00fcller indirerek yarat\u0131c\u0131lar\u0131n\u0131n geli\u015ftirdi\u011fi t\u00fcm yeni nakit \u00e7alma stratejilerine uyum sa\u011flayabilir. \u00d6rne\u011fin; kendini fidye yaz\u0131l\u0131m\u0131na, casus yaz\u0131l\u0131ma veya bankac\u0131l\u0131k Truva At\u0131\u2019na d\u00f6n\u00fc\u015ft\u00fcrebilir. Uzmanlar\u0131m\u0131z, mevcut s\u00fcr\u00fcm\u00fcn kodlar\u0131nda hen\u00fcz kullan\u0131lmam\u0131\u015f i\u015flevler oldu\u011funu ve bu i\u015flevlerin \u00e7ok y\u00fcksek ihtimalle gelecekte kullan\u0131lmak \u00fczere tasarland\u0131\u011f\u0131n\u0131 ke\u015ffetti.<\/p>\n<h2>Kendinizi Loapi Truva At\u0131\u2019ndan nas\u0131l koruyabilirsiniz?<\/h2>\n<p>Bu durumda da her zamanki gibi \u00f6nlem almak tedaviden daha iyidir. K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m yemini yutmaktan korunmak i\u00e7in uygulayabilece\u011finiz baz\u0131 basit kurallar var:<\/p>\n<ul>\n<li>Uygulamalar\u0131 yaln\u0131zca resmi ma\u011fazalardan indirerek kurun. Google Play ma\u011fazas\u0131n\u0131n mobil k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 yakalamakla g\u00f6revli \u00f6zel bir ekibi var. Truva Atlar\u0131 arada s\u0131rada resmi ma\u011fazalara s\u0131zsa da bu alanlarda Truva At\u0131\u2019na rastlama olas\u0131l\u0131\u011f\u0131n\u0131z \u015f\u00fcpheli sitelere k\u0131yasla \u00e7ok daha d\u00fc\u015f\u00fckt\u00fcr.<\/li>\n<li>Ek g\u00fcvenlik \u00f6nlemi olarak bilmedi\u011finiz kaynaklardan uygulama y\u00fcklemeyi devre d\u0131\u015f\u0131 b\u0131rak\u0131n. Bunu yapmak i\u00e7in Ayarlar\u2019dan G\u00fcvenlik \u00f6gesine gidin ve Bilinmeyen Kaynaklar kutucu\u011funun se\u00e7ili olmad\u0131\u011f\u0131ndan emin olun.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"android-malware\">\n<ul>\n<li>Ger\u00e7ekten ihtiya\u00e7 duymad\u0131\u011f\u0131n\u0131z \u015feyleri y\u00fcklemeyin. Genellikle ne kadar az uygulama y\u00fcklerseniz cihaz\u0131n\u0131z o kadar g\u00fcvenli olur.<\/li>\n<li>Android i\u00e7in g\u00fcvenilir ve ba\u015far\u0131s\u0131n\u0131 kan\u0131tlam\u0131\u015f bir antivir\u00fcs uygulamas\u0131 edinin ve cihaz\u0131n\u0131z\u0131 bu uygulamayla d\u00fczenli olarak tarat\u0131n. <a href=\"https:\/\/kas.pr\/kisatr\" target=\"_blank\" rel=\"noopener\">Kaspersky Internet Security for Android<\/a>\u2018in temel s\u00fcr\u00fcm\u00fc gibi \u00fccretsiz uygulamalar bile iyi bir koruma sa\u011flar.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Vir\u00fcs programc\u0131lar\u0131, Android cihaz kullan\u0131c\u0131lar\u0131 i\u00e7in \u00e7e\u015fitli s\u0131k\u0131nt\u0131lar yaratmaya devam ediyor. Hepimiz ki\u015fisel veri h\u0131rs\u0131zl\u0131\u011f\u0131n\u0131 ve bu verilerin karaborsaya d\u00fc\u015ft\u00fc\u011f\u00fcn\u00fc, kredi kartlar\u0131ndan s\u0131zd\u0131r\u0131lan paralar\u0131 biliyoruz. Ancak cihaz\u0131n\u0131z\u0131n ger\u00e7ekten yan\u0131p k\u00fcl olmas\u0131na neden olan bu Truva At\u0131\u2019n\u0131 daha \u00f6nce duymu\u015f muydunuz?<\/p>\n","protected":false},"author":2484,"featured_media":4553,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[105,1033,1336,1490,1339,537,889,652],"class_list":{"0":"post-4552","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-android","9":"tag-ddos","10":"tag-kripto-para-birimi","11":"tag-loapi","12":"tag-madencilik","13":"tag-tehditler","14":"tag-trojanlar","15":"tag-truva-ati"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/loapi-trojan\/4552\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/loapi-trojan\/12017\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/loapi-trojan\/10004\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/loapi-trojan\/14245\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/loapi-trojan\/12461\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/loapi-trojan\/12224\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/loapi-trojan\/15024\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/loapi-trojan\/14846\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/loapi-trojan\/19382\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/loapi-trojan\/20510\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/loapi-trojan\/8690\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/loapi-trojan\/9041\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/loapi-trojan\/19061\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/loapi-trojan\/19228\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/loapi-trojan\/19216\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/android\/","name":"android"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4552","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2484"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=4552"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4552\/revisions"}],"predecessor-version":[{"id":6988,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4552\/revisions\/6988"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/4553"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=4552"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=4552"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=4552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}