{"id":4623,"date":"2018-01-17T11:28:43","date_gmt":"2018-01-17T08:28:43","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=4623"},"modified":"2019-11-15T14:44:35","modified_gmt":"2019-11-15T11:44:35","slug":"skygofree-smart-trojan","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/skygofree-smart-trojan\/4623\/","title":{"rendered":"Skygofree: Hollywood tarz\u0131 mobil ajan"},"content":{"rendered":"<p>Truva Atlar\u0131n\u0131n \u00e7o\u011fu temelde ayn\u0131d\u0131r: Cihaza girdikten sonra cihaz sahibinin \u00f6deme bilgilerini \u00e7alar, sald\u0131rganlar i\u00e7in kripto para birimi madencili\u011fi yapar veya fidye istemek i\u00e7in verileri \u015fifreler. Fakat baz\u0131 g\u00f6r\u00fcnt\u00fcleme \u00f6zellikleri de Hollywood ajan filmlerini and\u0131r\u0131yor.<\/p>\n<p>Bu filmlerden \u00e7\u0131k\u0131p gelmi\u015f, Skygofree (televizyon hizmeti Sky Go ile hi\u00e7bir alakas\u0131 yok; kulland\u0131\u011f\u0131 etki alanlar\u0131ndan birinin ad\u0131n\u0131 alm\u0131\u015f) isimli sinematik Truva At\u0131n\u0131 yak\u0131n zamanda ke\u015ffettik. Skygofree ba\u015fka hi\u00e7bir yerde rastlamad\u0131\u011f\u0131m\u0131z bir dolu i\u015fleve sahip. \u00d6rne\u011fin, y\u00fcklendi\u011fi cihaz\u0131n konumunu takip edebiliyor ve cihaz sahibi belli bir yerdeyken ses kayd\u0131n\u0131 a\u00e7abiliyor. Pratikte bu, sald\u0131rganlar\u0131n kurbanlar\u0131n\u0131, mesela ofise girdiklerinde veya CEO\u2019nun evini ziyarette iken dinlemeye ba\u015flayabilece\u011fi anlam\u0131na geliyor.<\/p>\n<p>Skygofree\u2019nin uygulad\u0131\u011f\u0131 bir ba\u015fka ilgi \u00e7ekici teknik ise etkilenen telefon veya tableti sald\u0131rganlar taraf\u0131ndan kontrol edilen Wi-Fi a\u011f\u0131na gizlice ba\u011flamak; hem de sahibi, cihaz\u0131n b\u00fct\u00fcn Wi-Fi ba\u011flant\u0131lar\u0131n\u0131 kapam\u0131\u015f olsa bile. B\u00f6ylece kurban\u0131n trafi\u011fi toplan\u0131p analiz edilebiliyor. Ba\u015fka bir deyi\u015fle, birisi bir yerlerden ziyaret edilen b\u00fct\u00fcn siteleri, girilen t\u00fcm oturumlar\u0131, parolalar\u0131 ve kart numaralar\u0131n\u0131 g\u00f6rebiliyor.<\/p>\n<p>Bu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n ayn\u0131 zamanda cihaz bekleme modundayken de \u00e7al\u0131\u015fmas\u0131n\u0131 sa\u011flayan i\u015flevleri mevcut. \u00d6rne\u011fin, Android\u2019in son s\u00fcr\u00fcm\u00fc, pil \u00f6mr\u00fcn\u00fc korumak i\u00e7in etkin olmayan i\u015flemleri otomatik olarak kapatabiliyor ama Skygofree d\u00fczenli olarak sistem bildirimi g\u00f6ndererek bunu atlatabiliyor. Ayr\u0131ca teknoloji devlerinden birinin ak\u0131ll\u0131 telefonlar\u0131nda da ekran kapand\u0131\u011f\u0131 an s\u0131k kullan\u0131lan uygulamalar hari\u00e7 kalan t\u00fcm uygulamalar kapan\u0131yor olsa bile Skygofree kendini otomatik olarak s\u0131k kullan\u0131lanlar listesine ekliyor.<\/p>\n<p>K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m ayn\u0131 zamanda Facebook Messenger, Skype, Viber ve Whatsapp gibi uygulamalar\u0131 da izleyebiliyor. Sonuncu \u00f6rnekte geli\u015ftiriciler yine ufac\u0131k bir aral\u0131ktan s\u0131zmay\u0131 ba\u015farm\u0131\u015f: Truva At\u0131, Whatsapp mesajlar\u0131n\u0131 Eri\u015filebilirlik Hizmetleri arac\u0131l\u0131\u011f\u0131yla okuyor. Biz \u00f6nceden burada g\u00f6rsel veya i\u015fitsel engelli kullan\u0131c\u0131lar i\u00e7in geli\u015ftirilen bu arac\u0131n sald\u0131rganlar taraf\u0131ndan etkilenen cihaz\u0131 kontrol etmek amac\u0131yla nas\u0131l kullan\u0131ld\u0131\u011f\u0131n\u0131 <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/android-permissions-guide\/2956\/\" target=\"_blank\" rel=\"noopener\">anlatm\u0131\u015ft\u0131k<\/a>. Ekranda g\u00f6sterilenleri bir nevi \u201cdijital g\u00f6z\u201d olarak okuyan bu uygulama, Skygofree i\u00e7in WhatsApp mesajlar\u0131n\u0131 topluyor. Eri\u015filebilirlik Hizmetlerini kullanmak i\u00e7in kullan\u0131c\u0131 izni gerekiyor ama k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m bu iste\u011fi ba\u015fka, olduk\u00e7a masum g\u00f6r\u00fcnen bir iste\u011fin arkas\u0131na sakl\u0131yor.<\/p>\n<p>Sonuncu fakat bir o kadar da \u00f6nemli olarak, Skygofree, kullan\u0131c\u0131 cihaz\u0131n kilidini a\u00e7t\u0131\u011f\u0131nda gizlice \u00f6n kameray\u0131 a\u00e7arak foto\u011fraf \u00e7ekebiliyor: su\u00e7lular\u0131n bu foto\u011fraflar\u0131 nas\u0131l kullanaca\u011f\u0131n\u0131 tahmin edebilirsiniz.<\/p>\n<p>Tabii bu yenilik\u00e7i Truva At\u0131n\u0131n geli\u015ftiricileri, yaz\u0131l\u0131ma daha s\u0131radan \u00f6zellikler eklemeyi de ihmal etmedi. Skygofree ayr\u0131ca aramalar\u0131, SMS mesajlar\u0131n\u0131, takvim girdilerini ve di\u011fer kullan\u0131c\u0131 verilerini engelleyebilir.<\/p>\n<h2>H\u0131zl\u0131 \u0130nternet vaadi<\/h2>\n<p>Skygofree\u2019yi yak\u0131n zamanda, 2017\u2019nin sonlar\u0131na do\u011fru ke\u015ffettik ama analizlerimiz sald\u0131rganlar\u0131n bunu 2014\u2019ten beri kulland\u0131\u011f\u0131n\u0131 ve devaml\u0131 olarak geli\u015ftirdi\u011fini s\u00f6yl\u00fcyor. Son \u00fc\u00e7 y\u0131lda olduk\u00e7a basit bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m par\u00e7as\u0131ndan tam te\u015fekk\u00fcll\u00fc, \u00e7ok i\u015flevli bir casus yaz\u0131l\u0131ma d\u00f6n\u00fc\u015ft\u00fc.<\/p>\n<p>K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, sahte mobil operat\u00f6r\u00fc web sitelerinden, Skygofree\u2019yi mobil internet h\u0131z\u0131n\u0131 geli\u015ftirecek bir g\u00fcncelleme gibi g\u00f6stererek da\u011f\u0131t\u0131l\u0131yor. Kullan\u0131c\u0131 tuza\u011fa d\u00fc\u015f\u00fcp Truva At\u0131n\u0131 indirirse yaz\u0131l\u0131m y\u00fcklemenin g\u00fcya ger\u00e7ekle\u015ftirildi\u011fini belirten bir bildirim g\u00f6steriyor ve kendini kullan\u0131c\u0131dan saklayarak ana sunucudan di\u011fer y\u00f6nergeleri al\u0131yor. Yaz\u0131l\u0131m, ald\u0131\u011f\u0131 yan\u0131ta g\u00f6re bir dizi <a href=\"https:\/\/securelist.com\/threats\/payload-glossary\/\" target=\"_blank\" rel=\"noopener\">zararl\u0131 y\u00fck<\/a> indirebiliyor; sald\u0131rganlar\u0131n neredeyse her durum i\u00e7in bir \u00e7\u00f6z\u00fcm\u00fc bulunuyor.<\/p>\n<h2>\u00d6n\u00fcn\u00fc g\u00f6ren tedbirini al\u0131r<\/h2>\n<p>Bug\u00fcne kadar bulut koruma hizmetimiz, yaz\u0131l\u0131m\u0131n cihazlara bula\u015ft\u0131\u011f\u0131 yaln\u0131zca birka\u00e7 vaka kaydetti; bu vakalar\u0131n tamam\u0131 ise \u0130talya\u2019da ger\u00e7ekle\u015fti. Tabii bu di\u011fer \u00fclkelerdeki kullan\u0131c\u0131lar\u0131n korunmay\u0131 b\u0131rakabilece\u011fi anlam\u0131na gelmiyor; k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m da\u011f\u0131t\u0131c\u0131lar\u0131 her an hedef kitlelerini de\u011fi\u015ftirmeye karar verebilir. \u0130yi haber ise, kendinizi bu geli\u015fmi\u015f Truva At\u0131ndan korumak istiyorsan\u0131z di\u011fer vir\u00fcslerden korunmak i\u00e7in kulland\u0131\u011f\u0131n\u0131z y\u00f6ntemler yeterli olacakt\u0131r:<\/p>\n<ol>\n<li>Yaln\u0131zca resmi sitelerden uygulama indirin. \u00dc\u00e7\u00fcnc\u00fc parti kaynaklardan uygulama indirmeyi engellemek ak\u0131ll\u0131ca olacakt\u0131r; bu de\u011fi\u015fikli\u011fi ak\u0131ll\u0131 telefonunuzun ayarlar\u0131ndan yapabilirsiniz.<\/li>\n<li>Sizi \u015f\u00fcpheye d\u00fc\u015f\u00fcren hi\u00e7bir \u015feyi indirmeyin. Yanl\u0131\u015f yaz\u0131lm\u0131\u015f uygulama isimlerine, indirme say\u0131s\u0131n\u0131n azl\u0131\u011f\u0131na veya izinlere y\u00f6nelik \u015f\u00fcpheli isteklere dikkat edin: Bunlar\u0131n hepsi tehlike demek olabilir.<\/li>\n<li>Kaspersky Internet Security for Android gibi g\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc y\u00fckleyin. B\u00f6ylece cihaz\u0131n\u0131z \u00e7o\u011fu zararl\u0131 uygulama ve dosyadan, \u015f\u00fcpheli web sitelerinden veya zararl\u0131 ba\u011flant\u0131lardan korunur. \u00dccretsiz s\u00fcr\u00fcmde taramalar\u0131n elle \u00e7al\u0131\u015ft\u0131r\u0131lmas\u0131 gerekir; \u00fccretli s\u00fcr\u00fcm ise taramay\u0131 otomatik olarak ger\u00e7ekle\u015ftirir.<\/li>\n<\/ol>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"android-malware\">\n<p>4. \u0130\u015fletme kullan\u0131c\u0131lar\u0131n\u0131n, \u00e7al\u0131\u015fanlar\u0131n kulland\u0131\u011f\u0131 telefon ve tabletleri korumalar\u0131 i\u00e7in Kaspersky Endpoint Security for Business bile\u015feni Kaspersky Security for Mobile\u2019\u0131 kurmalar\u0131n\u0131 \u00f6neriyoruz.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial-leadgen\">\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Truva Atlar\u0131n\u0131n \u00e7o\u011fu temelde ayn\u0131d\u0131r: Cihaza girdikten sonra cihaz sahibinin \u00f6deme bilgilerini \u00e7alar, sald\u0131rganlar i\u00e7in kripto para birimi madencili\u011fi yapar veya fidye istemek i\u00e7in verileri \u015fifreler. Fakat baz\u0131 g\u00f6r\u00fcnt\u00fcleme \u00f6zellikleri de Hollywood ajan filmlerini and\u0131r\u0131yor.<\/p>\n","protected":false},"author":2484,"featured_media":4624,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[105,709,500,744,1512,537,241,652],"class_list":{"0":"post-4623","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-android","9":"tag-casusluk","10":"tag-gizlilik","11":"tag-guvenlik","12":"tag-skygofree","13":"tag-tehditler","14":"tag-trojan","15":"tag-truva-ati"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/skygofree-smart-trojan\/4623\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/skygofree-smart-trojan\/12216\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/skygofree-smart-trojan\/10148\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/skygofree-smart-trojan\/5576\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/skygofree-smart-trojan\/14418\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/skygofree-smart-trojan\/12641\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/skygofree-smart-trojan\/12327\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/skygofree-smart-trojan\/15125\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/skygofree-smart-trojan\/14920\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/skygofree-smart-trojan\/19484\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/skygofree-smart-trojan\/20717\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/skygofree-smart-trojan\/9929\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/skygofree-smart-trojan\/10014\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/skygofree-smart-trojan\/8783\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/skygofree-smart-trojan\/15657\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/skygofree-smart-trojan\/9162\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/skygofree-smart-trojan\/19255\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/skygofree-smart-trojan\/19378\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/skygofree-smart-trojan\/19341\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/android\/","name":"android"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2484"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=4623"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4623\/revisions"}],"predecessor-version":[{"id":6978,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4623\/revisions\/6978"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/4624"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=4623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=4623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=4623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}