{"id":5621,"date":"2019-01-29T14:28:27","date_gmt":"2019-01-29T11:28:27","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=5621"},"modified":"2019-01-29T14:28:27","modified_gmt":"2019-01-29T11:28:27","slug":"razy-trojan-cryptocurrency-stealer","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/razy-trojan-cryptocurrency-stealer\/5621\/","title":{"rendered":"Bitcoin h\u0131rs\u0131z\u0131 \u00c7\u0131lg\u0131n Razy"},"content":{"rendered":"<p>\u0130\u015fletim sisteminin varsay\u0131lan taray\u0131c\u0131s\u0131ndan farkl\u0131 bir taray\u0131c\u0131 kullan\u0131yorsan\u0131z b\u00fcy\u00fck ihtimalle taray\u0131c\u0131 uzant\u0131lar\u0131n\u0131 biliyor, hatta birka\u00e7 tanesini kullan\u0131yorsunuzdur. Ayr\u0131ca bu blogu devaml\u0131 olarak takip ediyorsan\u0131z, bu uzant\u0131lardan baz\u0131lar\u0131n\u0131n tehlikeli oldu\u011funun ve yaln\u0131zca resmi kaynaklardan y\u00fcklenmeleri gerekti\u011finin de fark\u0131ndas\u0131n\u0131zd\u0131r. Ancak buradaki as\u0131l sorun, k\u00f6t\u00fc ama\u00e7l\u0131 eklentilerin kullan\u0131c\u0131n\u0131n bilgisi olmadan, hatta kullan\u0131c\u0131 (neredeyse) hi\u00e7bir i\u015flem yapmadan bile kurulabilmesidir.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4368\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2017\/11\/03103357\/20171910_Bitcoin_steal.jpg\" alt=\"\" width=\"1460\" height=\"958\"><\/p>\n<h2>Razy k\u00f6t\u00fc ama\u00e7l\u0131 uzant\u0131lar\u0131 nas\u0131l y\u00fckl\u00fcyor?<\/h2>\n<p>Ba\u015f \u015f\u00fcpheli, (Windows i\u00e7in ge\u00e7erli olmak \u00fczere) Google Chrome, Mozilla Firefox ve Yandex Browser\u2019\u0131 kendi eklentileriyle yenileyen Razy Trojan\u2019d\u0131r. Securelist.com adresinden daha detayl\u0131 bilgiye ula\u015fabilirsiniz, ancak temelde bu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, y\u00fcklenen uzant\u0131lar\u0131n taranmas\u0131n\u0131 devre d\u0131\u015f\u0131 b\u0131rak\u0131r, her ihtimale kar\u015f\u0131 taray\u0131c\u0131n\u0131n g\u00fcncellenmesini engeller ve ard\u0131ndan k\u00f6t\u00fc ama\u00e7l\u0131 eklentileri y\u00fcklemeye ba\u015flar: Firefox\u2019a Firefox Protection uzant\u0131s\u0131 eklenirken Yandex Browser\u2019a Yandex Protect uzant\u0131s\u0131 y\u00fcklenir.<\/p>\n<p>Bu uzant\u0131lar\u0131n isimleri yan\u0131lt\u0131c\u0131 olsa da bir anda ortaya \u00e7\u0131kmalar\u0131 tehlike i\u015fareti olarak g\u00f6r\u00fclmelidir. Google Chrome\u2019a y\u00f6nelik komut dosyas\u0131 bu ba\u011flamda \u00f6zellikle tehlikelidir: \u00c7\u00fcnk\u00fc Razy, genel taray\u0131c\u0131 eklentileri listesinde g\u00f6r\u00fcnmeyen ve g\u00fcvenlik yaz\u0131l\u0131m\u0131 olmad\u0131k\u00e7a yaln\u0131zca dolayl\u0131 olarak tespit edilebilen Chrome Media Router sistem uzant\u0131s\u0131na bula\u015fabilir.<\/p>\n<h2>Vir\u00fcs bula\u015ft\u0131ktan sonra ne olur?<\/h2>\n<p>T\u00fcm bu senaryo, man-in-the-browser (taray\u0131c\u0131ya yerle\u015ftirilen zararl\u0131 yaz\u0131l\u0131m) sald\u0131r\u0131lar\u0131n\u0131n tipik bir \u00f6rne\u011fidir. K\u00f6t\u00fc ama\u00e7l\u0131 uzant\u0131lar, internet sitesinin i\u00e7eri\u011fini yarat\u0131c\u0131lar\u0131n\u0131n iste\u011fi do\u011frultusunda de\u011fi\u015ftirir. Razy olay\u0131nda en \u00e7ok korkmas\u0131 gerekenler, kripto para sahipleridir. Uzant\u0131, kripto para borsas\u0131 sitelerini hedef al\u0131r, siteyi \u201ckazan\u00e7l\u0131\u201d teklifler g\u00f6steren reklamlarla doldurur ancak yemi yutan kullan\u0131c\u0131lar kendilerini de\u011fil, siber su\u00e7lular\u0131 zenginle\u015ftirmi\u015f olur.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5622\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2019\/01\/29133720\/razy-trojan-cryptocurrency-stealer-scr1.jpg\" alt=\"\" width=\"1460\" height=\"890\"><\/p>\n<p>Bu da yetmezmi\u015f gibi, uzant\u0131 Google\u2019da veya Yandex\u2019te yap\u0131lan kullan\u0131c\u0131 aramalar\u0131n\u0131 g\u00f6zetler ve e\u011fer arama sorusu kripto para birimiyle ilgiliyse uzant\u0131, bu ba\u011flant\u0131lar\u0131 arama sonu\u00e7lar\u0131 sayfas\u0131ndaki kimlik av\u0131 sitelerine ekler.<\/p>\n<div id=\"attachment_5623\" style=\"width: 1237px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-5623\" class=\"wp-image-5623 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2019\/01\/29133757\/razy-trojan-cryptocurrency-stealer-scr2-TR.jpg\" alt=\"\" width=\"1227\" height=\"813\"><p id=\"caption-attachment-5623\" class=\"wp-caption-text\">Razy sonu\u00e7lar\u0131: Arama sonu\u00e7lar\u0131ndaki ilk be\u015f ba\u011flant\u0131, k\u00f6t\u00fc ama\u00e7l\u0131 uzant\u0131 taraf\u0131ndan eklenir ve kimlik av\u0131 sitelerini g\u00f6sterir<\/p><\/div>\n<p>Coin\u2019leri \u201cyeniden da\u011f\u0131tman\u0131n\u201d bir ba\u015fka yolu da, bir Web sayfas\u0131ndaki t\u00fcm c\u00fczdan numaralar\u0131n\u0131 (veya QR kodlar\u0131n\u0131) siber su\u00e7lulara ait c\u00fczdanlar\u0131n numaralar\u0131yla de\u011fi\u015ftirmektir.<\/p>\n<p>A\u015fa\u011f\u0131dakilere benzer c\u00f6mert teklifler sunan reklamlar, vir\u00fcs bula\u015fm\u0131\u015f taray\u0131c\u0131 kullan\u0131c\u0131lar\u0131n\u0131n pe\u015fini Vkontakte veya Youtube gibi sitelerde de b\u0131rakmaz: \u201c\u015eimdi biraz yat\u0131r\u0131m yap\u0131n, sonras\u0131nda bir milyon kazan\u0131n,\u201d \u201c\u00c7evrimi\u00e7i bir ankete kat\u0131larak para kazan\u0131n\u201d vb. Vikipedi sayfalar\u0131nda kullan\u0131c\u0131lardan projeyi desteklemelerini isteyen sahte ba\u015fl\u0131k da cabas\u0131.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5624\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2019\/01\/29134041\/razy-trojan-cryptocurrency-stealer-scr3.png\" alt=\"\" width=\"1676\" height=\"897\"><\/p>\n<h2>Razy\u2019den korunma yollar\u0131<\/h2>\n<p>Razy Trojan, <a href=\"https:\/\/www.kaspersky.com\/blog\/file-sharing-affiliate-programs\/23413\/\" target=\"_blank\" rel=\"noopener nofollow\">ba\u011fl\u0131 programlar arac\u0131l\u0131\u011f\u0131yla<\/a> faydal\u0131 yaz\u0131l\u0131m g\u00f6r\u00fcnt\u00fcs\u00fc alt\u0131nda gizlenerek yay\u0131l\u0131r ve \u00e7e\u015fitli \u00fccretsiz dosya bar\u0131nd\u0131rma hizmetlerinden indirilebilir, bu nedenle bu vir\u00fcsten nas\u0131l korunulaca\u011f\u0131na dair tavsiyeler de olduk\u00e7a standartt\u0131r:<\/p>\n<ul>\n<li>Uygulamalar\u0131 yaln\u0131zca geli\u015ftirici internet sitelerinden ve g\u00fcvendi\u011finiz kaynaklardan indirin.<\/li>\n<li>Bilgisayar\u0131n\u0131zda (bilinmeyen iyile\u015ftirici ara\u00e7lar\u0131n\u0131n ortaya \u00e7\u0131kmas\u0131 gibi) herhangi bir \u015f\u00fcpheli etkinlik oldu\u011funu fark ederseniz bir an \u00f6nce bilgisayar\u0131n\u0131z\u0131 taray\u0131n \u00e7\u00fcnk\u00fc bu durum kand\u0131r\u0131l\u0131p k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m y\u00fckledi\u011finizi g\u00f6steriyor olabilir.<\/li>\n<li>Bir anda ortaya \u00e7\u0131km\u0131\u015f gibi g\u00f6r\u00fcnen taray\u0131c\u0131 uzant\u0131lar\u0131n\u0131 kontrol edin ve \u015f\u00fcpheli g\u00f6r\u00fcnenleri devre d\u0131\u015f\u0131 b\u0131rak\u0131n.<\/li>\n<li>G\u00fcvenilir bir <a href=\"http:\/\/kas.pr\/kdkistr\" target=\"_blank\" rel=\"noopener\">antivir\u00fcs yaz\u0131l\u0131m\u0131<\/a> kullan\u0131n.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"gandalf30\">\n","protected":false},"excerpt":{"rendered":"<p>\u0130\u015fletim sisteminin varsay\u0131lan taray\u0131c\u0131s\u0131ndan farkl\u0131 bir taray\u0131c\u0131 kullan\u0131yorsan\u0131z b\u00fcy\u00fck ihtimalle taray\u0131c\u0131 uzant\u0131lar\u0131n\u0131 biliyor, hatta birka\u00e7 tanesini kullan\u0131yorsunuzdur.<\/p>\n","protected":false},"author":2506,"featured_media":5625,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1351],"tags":[374,16,1164,1832,1831,1166,1833,1551,241,1750],"class_list":{"0":"post-5621","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-bitcoin","10":"tag-chrome","11":"tag-eklentiler","12":"tag-firefpx","13":"tag-kripto-paralar","14":"tag-plugin","15":"tag-razy","16":"tag-tarayici","17":"tag-trojan","18":"tag-uzantilar"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/razy-trojan-cryptocurrency-stealer\/5621\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/razy-trojan-cryptocurrency-stealer\/15127\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/razy-trojan-cryptocurrency-stealer\/12705\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/razy-trojan-cryptocurrency-stealer\/17048\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/razy-trojan-cryptocurrency-stealer\/15239\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/razy-trojan-cryptocurrency-stealer\/13983\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/razy-trojan-cryptocurrency-stealer\/17737\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/razy-trojan-cryptocurrency-stealer\/16829\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/razy-trojan-cryptocurrency-stealer\/22168\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/razy-trojan-cryptocurrency-stealer\/25454\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/razy-trojan-cryptocurrency-stealer\/11383\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/razy-trojan-cryptocurrency-stealer\/11362\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/razy-trojan-cryptocurrency-stealer\/10284\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/razy-trojan-cryptocurrency-stealer\/18422\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/razy-trojan-cryptocurrency-stealer\/22322\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/razy-trojan-cryptocurrency-stealer\/23756\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/razy-trojan-cryptocurrency-stealer\/17864\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/razy-trojan-cryptocurrency-stealer\/22010\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/razy-trojan-cryptocurrency-stealer\/21947\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/uzantilar\/","name":"uzant\u0131lar"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/5621","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2506"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=5621"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/5621\/revisions"}],"predecessor-version":[{"id":5626,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/5621\/revisions\/5626"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/5625"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=5621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=5621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=5621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}