{"id":4987,"date":"2018-06-07T10:42:22","date_gmt":"2018-06-07T07:42:22","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=4987"},"modified":"2019-11-15T14:41:03","modified_gmt":"2019-11-15T11:41:03","slug":"evolution-of-ransomware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/evolution-of-ransomware\/4987\/","title":{"rendered":"Fidye yaz\u0131l\u0131mlar\u0131n\u0131n evrimi ve fidye yaz\u0131l\u0131mlar\u0131yla sava\u015f\u0131rken kullanabilece\u011finiz ara\u00e7lar"},"content":{"rendered":"<p>Ge\u00e7en y\u0131la damgas\u0131n\u0131 vuran fidye yaz\u0131l\u0131mlar\u0131, yaln\u0131zca evrimsel bir s\u0131\u00e7rama olarak tan\u0131mlayabilece\u011fimiz bir durumun sonucudur. Tehlikeli siber su\u00e7lular, bir zamanlar basit bir dosya \u015fifrelemesi olan tehdidi \u015fimdi olduk\u00e7a karma\u015f\u0131k bir araca d\u00f6n\u00fc\u015ft\u00fcrd\u00fcler ve b\u00fct\u00fcn her \u015fey devam eden evrimsel trende i\u015faret ediyor.<\/p>\n<h2>2017 \u00d6ncesi<\/h2>\n<p>O \u201ceski g\u00fczel\u201d g\u00fcnlerde fidye yaz\u0131l\u0131m\u0131 kurbanlar\u0131 genellikle normal insanlard\u0131. Siber su\u00e7lular, bilgisayar\u0131nda \u00f6nemli dosyalar\u0131 bulunan ve g\u00f6nderilen eki a\u00e7abilecek bir kullan\u0131c\u0131 bulabilmek i\u00e7in her yere ama her yere istenmeyen postalar yay\u0131yordu.<\/p>\n<p>Fakat bu durum 2016\u2019da de\u011fi\u015fti. Bu d\u00f6nemde, istenmeyen postalar g\u00f6nderen ki\u015filerin normalde rastgele olu\u015fturduklar\u0131 listeler, \u00e7evrimi\u00e7i ortamda bulunabilen \u015firket \u00e7al\u0131\u015fanlar\u0131n\u0131n \u00f6zellikle toplanm\u0131\u015f adresleriyle dolmaya ba\u015flad\u0131. Su\u00e7lular, \u015firketlere sald\u0131rman\u0131n daha k\u00e2rl\u0131 oldu\u011funu a\u00e7\u0131k bir \u015fekilde g\u00f6rm\u00fc\u015ft\u00fc. Mesaj i\u00e7erikleri de buna g\u00f6re de\u011fi\u015fti: Mesajlara art\u0131k ki\u015fisel bir yaz\u0131\u015fma maskesi verilmiyor; i\u015f ortaklar\u0131, m\u00fc\u015fteriler ve vergi hizmetleri taraf\u0131ndan g\u00f6nderilen postlar gibi g\u00f6steriliyordu.<\/p>\n<h2>2017<\/h2>\n<p>2017\u2019de durum bu defa radikal bir \u015fekilde de\u011fi\u015fti. Milyon dolarl\u0131k hasara neden olan iki b\u00fcy\u00fck \u00f6l\u00e7ekli salg\u0131n, fidye yaz\u0131l\u0131m\u0131n\u0131n doland\u0131r\u0131c\u0131l\u0131k d\u0131\u015f\u0131nda ama\u00e7larla da kullan\u0131labilece\u011fini g\u00f6sterdi. Bu salg\u0131nlardan ilki, k\u00f6t\u00fcl\u00fc\u011f\u00fcyle \u00fcn salm\u0131\u015f olan <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/wannacry-for-b2b\/3191\/\" target=\"_blank\" rel=\"noopener\">WannaCry<\/a>, teknolojik a\u00e7\u0131dan \u00f6nc\u00fc oldu. Bu fidye yaz\u0131l\u0131m\u0131, Windows\u2019ta SMB protokol\u00fcn\u00fcn uygulanmas\u0131ndaki g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131 k\u00f6t\u00fcye kullan\u0131yordu. Bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131 \u00e7oktan d\u00fczeltilmi\u015fti fakat \u00e7o\u011fu \u015firket yamay\u0131 y\u00fcklemekle u\u011fra\u015fmam\u0131\u015ft\u0131. Fakat bu, hikayenin yar\u0131s\u0131 bile de\u011fil.<\/p>\n<p>WannaCry, bir fidye yaz\u0131l\u0131m\u0131 olarak ba\u015far\u0131l\u0131 de\u011fildi. WannaCry, y\u00fcz binlerce makineye bula\u015fm\u0131\u015f olmas\u0131na ra\u011fmen yarat\u0131c\u0131lar\u0131na \u00e7ok b\u00fcy\u00fck miktarlarda para kazand\u0131rmad\u0131. Baz\u0131 ara\u015ft\u0131rmac\u0131lar amac\u0131n en ba\u015f\u0131ndan para olup olmad\u0131\u011f\u0131n\u0131 merak etmeye ba\u015flad\u0131lar; ama\u00e7, sabotaj yapmak veya verileri yok etmek de olabilirdi.<\/p>\n<p>Sonraki tehdit, \u015f\u00fcpheleri ortadan kald\u0131rd\u0131. <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/expetr-for-b2b\/3342\/\" target=\"_blank\" rel=\"noopener\">ExPetr<\/a> \u015fifrelenmi\u015f verileri kurtarmaya bile yetmiyordu: fidye yaz\u0131l\u0131m\u0131 k\u0131l\u0131\u011f\u0131na girmi\u015f bir <a href=\"https:\/\/securelist.com\/threats\/wiper-glossary\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=termin-explanation\" target=\"_blank\" rel=\"noopener\">siliciydi<\/a>. Dahas\u0131, yeni bir hilesi vard\u0131. Tedarik zinciri sald\u0131r\u0131s\u0131 kullanan yarat\u0131c\u0131lar, MeDoc ad\u0131ndaki Ukraynal\u0131 muhasebe yaz\u0131l\u0131m\u0131n\u0131 ele ge\u00e7irdiler ve Ukrayna\u2019da i\u015f yapan neredeyse her \u015firketi vir\u00fcs kapma riskiyle kar\u015f\u0131 kar\u015f\u0131ya getirdiler.<\/p>\n<h2>2018<\/h2>\n<p>Bu y\u0131l\u0131n ba\u015f\u0131ndan bu yana kar\u015f\u0131la\u015ft\u0131\u011f\u0131m\u0131z olaylar, bize fidye yaz\u0131l\u0131mlar\u0131n\u0131n hala geli\u015fmekte oldu\u011funu g\u00f6steriyor. Uzmanlar\u0131m\u0131z k\u0131sa bir s\u00fcre \u00f6nce nispeten yeni bir tehlike olan <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/synack-ransomware-featured\/4907\/\" target=\"_blank\" rel=\"noopener\">SynAck<\/a> fidye yaz\u0131l\u0131m\u0131n\u0131n en yeni \u015fekli \u00fczerine bir ara\u015ft\u0131rma yapt\u0131. Yap\u0131lan ara\u015ft\u0131rmada, koruma teknolojilerine kar\u015f\u0131 karma\u015f\u0131k mekanizmalar\u0131n kullan\u0131ld\u0131\u011f\u0131 belirlendi. Elde edilen bulgular da hedefli sald\u0131r\u0131ya i\u015faret ediyordu. Kar\u015f\u0131 tedbirler aras\u0131nda a\u015fa\u011f\u0131dakiler g\u00f6sterilebilir:<\/p>\n<ul>\n<li>K\u00f6t\u00fc ama\u00e7l\u0131 bir i\u015flemi yasalm\u0131\u015f gibi g\u00f6stermek i\u00e7in \u0130\u015flem \u0130kizleme olarak bilinen i\u015flem \u00e7o\u011faltma y\u00f6ntemini kullanmak;<\/li>\n<li>Derleme \u00f6ncesinde y\u00fcr\u00fct\u00fclebilir kodu g\u00f6z ard\u0131 etmek;<\/li>\n<li>Kontroll\u00fc bir ortamda izlenmedi\u011finden emin olmak i\u00e7in kontroller sa\u011flamak;<\/li>\n<li>\u00d6nemli dosyalara eri\u015fim sa\u011flamak i\u00e7in i\u015flemleri ve hizmetleri kapatmak;<\/li>\n<li>Olay sonras\u0131 analizi engellemek i\u00e7in olay g\u00fcnl\u00fcklerini temizlemek.<\/li>\n<\/ul>\n<p>Fidye yaz\u0131l\u0131m\u0131n\u0131n evrimini tamamlad\u0131\u011f\u0131na inanmak i\u00e7in bir sebep bulunmuyor. Fidye yaz\u0131l\u0131m\u0131 yarat\u0131c\u0131lar\u0131, bu yaz\u0131l\u0131mlar\u0131 hep daha fazla geli\u015ftirmenin yollar\u0131n\u0131 aramaya devam edecek.<\/p>\n<h2>Fidye yaz\u0131l\u0131m\u0131n\u0131n evrimi nas\u0131l durdurulabilir?<\/h2>\n<p>Fidye yaz\u0131l\u0131m\u0131n\u0131n geli\u015fimine son vermek i\u00e7in tek yol, sald\u0131r\u0131lar\u0131 etkisiz hale getirmektir. Sald\u0131r\u0131lar\u0131 etkisiz hale getirebilmek i\u00e7in de en son teknolojiyi kullanman\u0131z gerekir. M\u00fc\u015fterilerimiz uzun zamand\u0131r g\u00fcvende: T\u00fcm kurumsal u\u00e7 nokta \u00e7\u00f6z\u00fcmlerimiz fidye yaz\u0131l\u0131mlar\u0131yla etkili bir \u015fekilde m\u00fccadele etmemizi sa\u011flayan alt sistemler i\u00e7ermektedir.<\/p>\n<p>Kaspersky Lab\u2019in kurumsal \u00e7\u00f6z\u00fcmlerini kullanm\u0131yor olsan\u0131z bile bu, verilerinizi korumas\u0131z b\u0131rakman\u0131z i\u00e7in bir bahane olamaz. \u00d6zel \u00e7\u00f6z\u00fcm\u00fcm\u00fcz olan Kaspersky Anti-Ransomware Tool, \u00e7o\u011fu \u00fc\u00e7\u00fcnc\u00fc taraf tedarik\u00e7inin g\u00fcvenlik mekanizmas\u0131n\u0131 y\u00fckseltir. Fidye yaz\u0131l\u0131m\u0131n\u0131 a\u00e7\u0131\u011fa \u00e7\u0131karmak i\u00e7in en son davran\u0131\u015f tespit teknolojilerini kullanarak bulut tabanl\u0131 ara\u00e7lar\u0131m\u0131z\u0131n t\u00fcm avantajlar\u0131ndan yararlan\u0131r. Ayr\u0131ca, bu \u00fcr\u00fcn\u00fcm\u00fcz modern tehditlerin zorluklar\u0131n\u0131 kar\u015f\u0131lamak i\u00e7in s\u00fcrekli olarak geli\u015ftiriliyor: yak\u0131n zamanda \u00fc\u00e7\u00fcnc\u00fc versiyonunu piyasaya s\u00fcrd\u00fck.<\/p>\n<p>Kaspersky Anti-Ransomware Tool\u2019un bu son versiyonu, komut sat\u0131r\u0131ndan da\u011f\u0131t\u0131larak \u015firket a\u011flar\u0131nda otomatik uygulamay\u0131 kolayla\u015ft\u0131r\u0131r. Sundu\u011fu ayr\u0131cal\u0131klar\u0131n yan\u0131nda, bu \u00e7\u00f6z\u00fcm tamamen \u00fccretsiz! Buradan kaydolun, uygulamay\u0131 indirin ve <a href=\"https:\/\/go.kaspersky.com\/TR_Anti-ransomware-tool_soc.html?utm_source=dailyblog&amp;utm_medium=social&amp;utm_campaign=tr_KART_organic&amp;utm_content=sm-post&amp;utm_term=tr_dailyblog_organic_sm-post_social_KART\" target=\"_blank\" rel=\"noopener nofollow\">y\u00fckleyin<\/a>.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kartb2b\">\n","protected":false},"excerpt":{"rendered":"<p>Ge\u00e7en y\u0131la damgas\u0131n\u0131 vuran fidye yaz\u0131l\u0131mlar\u0131, yaln\u0131zca  evrimsel bir s\u0131\u00e7rama olarak tan\u0131mlayabilece\u011fimiz bir durumun sonucudur. Tehlikeli siber su\u00e7lular, bir zamanlar basit bir dosya \u015fifrelemesi olan tehdidi \u015fimdi olduk\u00e7a karma\u015f\u0131k bir araca d\u00f6n\u00fc\u015ft\u00fcrd\u00fcler ve b\u00fct\u00fcn her \u015fey devam eden evrimsel trende i\u015faret ediyor.<\/p>\n","protected":false},"author":700,"featured_media":4988,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1194,1727],"tags":[1262,591,935,1613,1227],"class_list":{"0":"post-4987","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"tag-expetr","10":"tag-fidye-yazilimi","11":"tag-sifreleyiciler","12":"tag-synack","13":"tag-wannacry"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/evolution-of-ransomware\/4987\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/evolution-of-ransomware\/13450\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/evolution-of-ransomware\/11240\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/evolution-of-ransomware\/15508\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/evolution-of-ransomware\/13796\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/evolution-of-ransomware\/13040\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/evolution-of-ransomware\/16275\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/evolution-of-ransomware\/22516\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/evolution-of-ransomware\/10610\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/evolution-of-ransomware\/10434\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/evolution-of-ransomware\/9244\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/evolution-of-ransomware\/16919\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/evolution-of-ransomware\/23828\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/evolution-of-ransomware\/20382\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/evolution-of-ransomware\/20389\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimi\/","name":"Fidye Yaz\u0131l\u0131m\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4987","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/700"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=4987"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4987\/revisions"}],"predecessor-version":[{"id":6931,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4987\/revisions\/6931"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/4988"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=4987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=4987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=4987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}