{"id":5847,"date":"2019-04-09T12:16:34","date_gmt":"2019-04-09T09:16:34","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=5847"},"modified":"2019-11-15T14:30:36","modified_gmt":"2019-11-15T11:30:36","slug":"macos-exe-malware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/macos-exe-malware\/5847\/","title":{"rendered":"Mac&#8217;inize EXE bula\u015fmas\u0131"},"content":{"rendered":"<p>Daha \u00f6nce defalarca s\u00f6yledi\u011fimiz gibi, <a href=\"https:\/\/www.kaspersky.com\/blog\/wirelurker-ios-osx-malware\/6563\/\" target=\"_blank\" rel=\"noopener nofollow\">macOS\u2019un zarar verilemez oldu\u011fu fikri bir mitten ibarettir<\/a>. Son zamanlarda siber su\u00e7lular, macOS\u2019un yerle\u015fik koruma mekanizmas\u0131n\u0131n etraf\u0131ndan dolanmak i\u00e7in yeni bir yol daha buldu. Vir\u00fcs bula\u015fan sistemle ilgili toplad\u0131klar\u0131 verileri, normalde yaln\u0131zca Windows\u2019ta \u00e7al\u0131\u015fan EXE uzant\u0131s\u0131na sahip dosyalar\u0131 kullanan <a href=\"https:\/\/thehackernews.com\/2019\/02\/macos-windows-exe-malware.html\" target=\"_blank\" rel=\"noopener nofollow\">reklam yaz\u0131l\u0131mlar\u0131na yerle\u015ftirdiler<\/a>. Mac kullan\u0131c\u0131lar\u0131na vir\u00fcs bula\u015ft\u0131ran bir EXE dosyas\u0131 m\u0131? Tuhaf ama bu y\u00f6ntem ger\u00e7ekten de i\u015fe yar\u0131yor.<\/p>\n<h2>Bir bula\u015fma \u00f6yk\u00fcs\u00fc: K\u00f6t\u00fc ama\u00e7l\u0131 EXE yaz\u0131l\u0131mlar\u0131yla dolu korsan bir g\u00fcvenlik duvar\u0131<\/h2>\n<p>\u0130ronik olan, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n herhangi bir yere de\u011fil, bir <em>g\u00fcvenlik<\/em> \u00fcr\u00fcn\u00fcn\u00fcn, Little Snitch g\u00fcvenlik duvar\u0131n\u0131n korsan bir kopyas\u0131na eklenmi\u015f olmas\u0131. Tahmin edilebilece\u011fi \u00fczere, lisans i\u00e7in para \u00f6demekten ka\u00e7\u0131nan kullan\u0131c\u0131lar\u0131n ba\u015f\u0131 a\u011fr\u0131d\u0131.<\/p>\n<p>G\u00fcvenlik duvar\u0131n\u0131n vir\u00fcsl\u00fc s\u00fcr\u00fcmleri, torrent kullan\u0131larak yay\u0131ld\u0131. Kurbanlar, bilgisayarlar\u0131na DMG format\u0131nda bir disk g\u00f6r\u00fcnt\u00fcs\u00fc i\u00e7eren ZIP dosyalar\u0131 indirdi. Buraya kadar her \u015fey normal. Fakat bu DMG dosyas\u0131n\u0131n i\u00e7eri\u011fine daha yak\u0131ndan bak\u0131nca, i\u00e7inde belirli bir intaller.exe bulunan MonoBundle klas\u00f6r\u00fc oldu\u011fu ortaya \u00e7\u0131k\u0131yor. Bu, normal bir macOS nesnesi de\u011fil; EXE dosyalar\u0131 genelde Mac cihazlarda \u00e7al\u0131\u015fmaz.<\/p>\n<h3>Gatekeeper buna g\u00f6z yumuyor<\/h3>\n<p>Hatta macOS, y\u00fcr\u00fct\u00fclebilir Windows dosyalar\u0131n\u0131 macOS\u2019ta <em>o kadar desteklemiyor ki<\/em>, Gatekeeper (\u015f\u00fcpheli programlar\u0131n \u00e7al\u0131\u015fmas\u0131n\u0131 \u00f6nleyen bir macOS g\u00fcvenlik \u00f6zelli\u011fi) EXE dosyalar\u0131n\u0131 g\u00f6rmezden geliyor. Bu gayet anla\u015f\u0131labilir: Aktif olmad\u0131\u011f\u0131 apa\u00e7\u0131k dosyalar\u0131 tarayarak sistemi a\u015f\u0131r\u0131 y\u00fcklemek pek de mant\u0131kl\u0131 de\u011fil; hele ki Apple\u2019\u0131n sat\u0131\u015f noktalar\u0131ndan birinin i\u015fletim h\u0131z\u0131 oldu\u011fu d\u00fc\u015f\u00fcn\u00fcl\u00fcrse.<\/p>\n<p>\u0130\u015fin i\u00e7inde bir \u201cama\u201d olmasa her \u015fey yolunda olabilirdi, \u201cama\u201d: Bir\u00e7ok program Windows i\u00e7in mevcut ve bazen Mac kullan\u0131c\u0131lar\u0131 da bunlardan baz\u0131lar\u0131na ihtiya\u00e7 duyuyor. Bu y\u00fczden platforma \u00f6zg\u00fc olmayan dosyalar\u0131 \u00e7al\u0131\u015ft\u0131rmak i\u00e7in \u00e7e\u015fitli \u00e7\u00f6z\u00fcmler var. Kullan\u0131c\u0131lar\u0131n Windows uygulamalar\u0131n\u0131 macOS da dahil di\u011fer i\u015fletim sistemlerinde \u00e7al\u0131\u015ft\u0131rmas\u0131n\u0131 sa\u011flayan \u00fccretsiz bir sistem olan Mono altyap\u0131s\u0131, bunlardan biri.<\/p>\n<p>Tahmin edebilece\u011finiz gibi, siber su\u00e7lular\u0131n kendi \u00e7\u0131karlar\u0131 do\u011frultusunda k\u00f6t\u00fcye kulland\u0131\u011f\u0131 \u015fey i\u015fte bu altyap\u0131. Genelde altyap\u0131n\u0131n bilgisayara ayr\u0131ca kurulmas\u0131 gerekir, fakat bu siber sahtekarlar bunu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlarla birlikte paketlemenin bir yolunu bulmu\u015flar (MonoBundle klas\u00f6r\u00fcndeki k\u00f6t\u00fc niyetli EXE\u2019yi hat\u0131rlay\u0131n). Sonu\u00e7 olarak k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, sahipleri yaln\u0131zca yerel programlar kullanan Mac\u2019lerde bile ba\u015far\u0131yla \u00e7al\u0131\u015f\u0131yor.<\/p>\n<h3>Bir bula\u015fma \u00f6yk\u00fcs\u00fc: Casus yaz\u0131l\u0131mlar ve reklam yaz\u0131l\u0131mlar\u0131<\/h3>\n<p>Kurulumun ard\u0131ndan k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m ilk \u00f6nce vir\u00fcs bula\u015fan sistemle ilgili bilgi topluyor. Siber su\u00e7lular modelin ad\u0131yla, cihaz\u0131n kimli\u011fiyle, i\u015flemci \u00f6zellikleriyle, RAM\u2019le ve ba\u015fka bir\u00e7ok \u015feyle ilgileniyor. K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m ayn\u0131 zamanda kurulu uygulamalarla ilgili bilgiler de topluyor ve bunlar\u0131 C&amp;C sunucusuna g\u00f6nderiyor.<\/p>\n<p>E\u015f zamanl\u0131 olarak, bula\u015ft\u0131\u011f\u0131 bilgisayara Adobe Flash Media Player ya da Little Snitch maskesi alt\u0131nda \u00e7ok say\u0131da g\u00f6r\u00fcnt\u00fc de indiriyor. \u0130ndirdi\u011fi bu g\u00f6r\u00fcnt\u00fcler asl\u0131nda sizi reklama bo\u011facak s\u0131radan reklam yaz\u0131l\u0131m\u0131 ara\u00e7lar\u0131.<\/p>\n<h3>Nas\u0131l korunulur<\/h3>\n<p>Bu \u00f6yk\u00fcden \u00e7\u0131kar\u0131lacak ders basit: Bilgi teknolojileri d\u00fcnyas\u0131nda hi\u00e7bir sistem tamamen g\u00fcvenli de\u011fildir. Ve ne kadar g\u00fcvenilir g\u00f6r\u00fcl\u00fcrse g\u00f6r\u00fcls\u00fcn, yerle\u015fik g\u00fcvenlik \u00f6zelliklerine g\u00f6z\u00fc kapal\u0131 g\u00fcvenilmemelidir. \u0130\u015fte bilgisayar\u0131n\u0131z\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 kurnaz yaz\u0131l\u0131mlara kar\u015f\u0131 nas\u0131l koruyabilece\u011finize dair birka\u00e7 ipucu:<\/p>\n<ul>\n<li>Uygulamalar\u0131n korsan s\u00fcr\u00fcmlerini kurmay\u0131n. Bir programa ger\u00e7ekten ihtiyac\u0131n\u0131z varsa ve ger\u00e7ekten \u00fccretini \u00f6demeye haz\u0131r de\u011filseniz, \u00f6nce \u00fccretsiz bir alternatif bulmay\u0131 deneyin.<\/li>\n<li>Programlar\u0131 daima resmi kaynaklardan, yani App Store\u2019dan ve geli\u015ftiricilerin web sitelerinden indirin.<\/li>\n<li>Bir uygulamay\u0131 resmi olmayan bir kaynaktan, \u00f6rne\u011fin yukar\u0131da de\u011finildi\u011fi gibi bir torrent izleyicisinden indirmeye karar verirseniz tam olarak ne indirdi\u011finizi kontrol etti\u011finizden emin olun. Kurulum paketindeki \u201cekstra\u201d dosyalardan ku\u015fku duyun.<\/li>\n<li>\u015e\u00fcpheli g\u00f6r\u00fcnen t\u00fcm dosyalar\u0131 tarayan, hi\u00e7birini atlamayan, <a href=\"http:\/\/kas.pr\/kdkistr\" target=\"_blank\" rel=\"noopener\">g\u00fcvenilir bir antivir\u00fcs \u00e7\u00f6z\u00fcm\u00fc<\/a> kullan\u0131n.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Windows \u00e7al\u0131\u015ft\u0131ran bilgisayarlar i\u00e7in EXE dosyalar\u0131n\u0131n tehlikeli olabilece\u011fini herkes bilir. Fakat g\u00f6r\u00fcnen o ki, EXE dosyalar\u0131 macOS&#8217;a da vir\u00fcs bula\u015ft\u0131rabiliyor.<\/p>\n","protected":false},"author":2484,"featured_media":5848,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1284,1351],"tags":[1087,14,1730,1901,1902,1170,1879,1116],"class_list":{"0":"post-5847","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tips","8":"category-threats","9":"tag-adware","10":"tag-apple","11":"tag-casusluk-yazilimi","12":"tag-exe","13":"tag-firewall","14":"tag-macos","15":"tag-reklam-virusleri","16":"tag-spyware"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/macos-exe-malware\/5847\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/macos-exe-malware\/15574\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/macos-exe-malware\/13118\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/macos-exe-malware\/17495\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/macos-exe-malware\/15643\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/macos-exe-malware\/14327\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/macos-exe-malware\/18208\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/macos-exe-malware\/17143\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/macos-exe-malware\/22564\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/macos-exe-malware\/26343\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/macos-exe-malware\/11615\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/macos-exe-malware\/11658\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/macos-exe-malware\/10576\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/macos-exe-malware\/18972\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/macos-exe-malware\/22857\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/macos-exe-malware\/18219\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/macos-exe-malware\/22426\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/macos-exe-malware\/22362\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/macos\/","name":"macOS"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/5847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2484"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=5847"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/5847\/revisions"}],"predecessor-version":[{"id":6809,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/5847\/revisions\/6809"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/5848"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=5847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=5847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=5847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}