{"id":6434,"date":"2019-09-18T13:37:06","date_gmt":"2019-09-18T10:37:06","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=6434"},"modified":"2019-11-15T14:24:19","modified_gmt":"2019-11-15T11:24:19","slug":"google-play-malware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/google-play-malware\/6434\/","title":{"rendered":"Google Play&#8217;deki t\u00fcm uygulamalar g\u00fcvenlidir: Do\u011fru mu, yanl\u0131\u015f m\u0131?"},"content":{"rendered":"<p>Android uygulamalar\u0131n\u0131 resmi ma\u011fazalar d\u0131\u015f\u0131ndaki yerlerden asla indirmemeniz gerekti\u011fini her f\u0131rsatta s\u00f6yl\u00fcyoruz. Ancak bu, Google Play\u2019de vir\u00fcs olmad\u0131\u011f\u0131 anlam\u0131na gelmiyor. Yine de resmi ma\u011fazada, \u00fc\u00e7\u00fcnc\u00fc taraf sitelerde oldu\u011fundan \u00e7ok daha az say\u0131da vir\u00fcsle kar\u015f\u0131la\u015f\u0131rs\u0131n\u0131z ve d\u00fczenli olarak da temizlenirler.<\/p>\n<h2>Google, Android uygulamalar\u0131n\u0131n g\u00fcvenli\u011fini nas\u0131l izliyor<\/h2>\n<p>Google Play\u2019e girmeyi ba\u015farmak, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar i\u00e7in \u00e7ok da zor de\u011fil. Moderat\u00f6rler uygulamay\u0131 yay\u0131nlamadan \u00f6nce <a href=\"https:\/\/play.google.com\/about\/developer-content-policy\/?hl=TR\" target=\"_blank\" rel=\"noopener nofollow\">kapsaml\u0131 bir gereklilik listesiyle<\/a> uyumlu olup olmad\u0131\u011f\u0131n\u0131 kontrol ediyor. Bir ihlal bulduklar\u0131 takdirde program\u0131 ma\u011fazadan \u00e7\u0131kar\u0131yorlar.<\/p>\n<p>Ancak Google Play\u2019e o kadar fazla say\u0131da yeni uygulama ve mevcut uygulama g\u00fcncellemesi geliyor ki, hepsini takip etmek moderat\u00f6rler i\u00e7in neredeyse imkans\u0131z. Dolay\u0131s\u0131yla zaman zaman k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar g\u00f6zden ka\u00e7abiliyor. En \u00e7arp\u0131c\u0131 \u00f6rneklerden baz\u0131lar\u0131 \u015funlar:<\/p>\n<h3>G\u00f6rmek istemedi\u011finiz reklamlar<\/h3>\n<p>Ara\u015ft\u0131rmac\u0131lar\u0131m\u0131z yak\u0131n zaman \u00f6nce belge dijitalle\u015ftirme uygulamas\u0131 <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/camscanner-malicious-android-app\/6373\/\" target=\"_blank\" rel=\"noopener\">CamScanner\u2019da k\u00f6t\u00fc ama\u00e7l\u0131 bir kod tespit etti<\/a>. Uygulama yaln\u0131zca Google Play\u2019de yer almakla kalm\u0131yor, ma\u011fazaya g\u00f6re 100 milyondan fazla kullan\u0131c\u0131n\u0131n cihaz\u0131nda kurulu bulunuyordu.<\/p>\n<p>Ne yanl\u0131\u015f gitti? Anla\u015f\u0131lan, belirli bir noktaya kadar CamScanner s\u00f6yledi\u011fi i\u015flevleri yerine getiren normal bir uygulamayd\u0131. Geli\u015ftiricileri reklamlar ve \u00fccretli \u00f6zelliklerden gelir elde ediyordu. Buraya kadar s\u0131ra d\u0131\u015f\u0131 bir durum yoktu. Fakat uygulamaya k\u00f6t\u00fc ama\u00e7l\u0131 bir \u00f6zellik eklendikten sonra bu durum de\u011fi\u015fti.<\/p>\n<p>Necro.n Truva At\u0131 dosya y\u00fckleyici \u015feklinde bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, reklam mod\u00fcllerinden birinin i\u00e7ine yerle\u015ferek kullan\u0131c\u0131n\u0131n izni olmaks\u0131z\u0131n cihaza reklam uygulamalar\u0131 ve \u00fc\u00e7\u00fcnc\u00fc taraf hizmetlere \u00fccretli abonelik alan programlar gibi di\u011fer k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 y\u00fcklemekle g\u00f6revli ba\u015fka bir Truva At\u0131 kurmaya ba\u015flad\u0131.<\/p>\n<p>Uzmanlar\u0131m\u0131z bulgular\u0131n\u0131 Google\u2019a bildirdi; y\u00f6neticiler de uygulamay\u0131 ma\u011fazadan kald\u0131rd\u0131. CamScanner\u2019\u0131n geli\u015ftiricileri de uygulamay\u0131 tekrar ma\u011fazaya sokabilmek i\u00e7in hemen k\u00f6t\u00fc ama\u00e7l\u0131 mod\u00fclleri uygulamadan \u00e7\u0131kard\u0131. Ancak sonu\u00e7ta vir\u00fcsl\u00fc versiyon olduk\u00e7a uzun bir s\u00fcre boyunca indirilmeye a\u00e7\u0131k kald\u0131.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"android-malware\">\n<h3>H\u0131rs\u0131z oynat\u0131c\u0131<\/h3>\n<p>CamScanner, Google Play ma\u011fazas\u0131nda sunulmas\u0131n\u0131n ard\u0131ndan k\u00f6t\u00fc ama\u00e7l\u0131 \u00f6zellikler benimseyen uygulamalar\u0131n tek \u00f6rne\u011fi de\u011fil. VKontakte (VK) uygulamas\u0131nda m\u00fczik dinlemek i\u00e7in olu\u015fturulmu\u015f bir oynat\u0131c\u0131 g\u00f6r\u00fcn\u00fcm\u00fcndeki Truva At\u0131\u2019n\u0131n yarat\u0131c\u0131lar\u0131, birka\u00e7 y\u0131l boyunca moderat\u00f6rleri ayn\u0131 y\u00f6ntemle atlatmay\u0131 ba\u015fard\u0131.<\/p>\n<p>Google Play\u2019e ilk ba\u015fta temiz bir s\u00fcr\u00fcm y\u00fcklenmi\u015fti; ard\u0131ndan birka\u00e7 zarars\u0131z g\u00fcncelleme geldi. Fakat birka\u00e7 g\u00fcncellemeden sonra uygulama VK hesaplar\u0131n\u0131n oturum a\u00e7ma bilgilerini ve \u015fifrelerini \u00e7almaya ba\u015flad\u0131. Dahas\u0131, kurbanlar\u0131n \u00e7o\u011funlukla bundan haberi yoktu; hesaplar\u0131 VK gruplar\u0131n\u0131n gizlice reklam\u0131n\u0131 yapmak i\u00e7in kullan\u0131ld\u0131.<\/p>\n<p>Oynat\u0131c\u0131n\u0131n g\u00fcncel s\u00fcr\u00fcm\u00fcn\u00fcn foyas\u0131 meydana \u00e7\u0131k\u0131p ma\u011fazadan silinince yarat\u0131c\u0131lar\u0131 ma\u011fazaya hemen yeni s\u00fcr\u00fcmlerini y\u00fcklediler. 2015\u2019te Google Play\u2019den k\u00f6t\u00fc ama\u00e7l\u0131 program\u0131n en az yedi farkl\u0131 s\u00fcr\u00fcm\u00fc <a href=\"https:\/\/securelist.com\/stealing-to-the-sound-of-music\/72458\/\" target=\"_blank\" rel=\"noopener\">kald\u0131r\u0131ld\u0131<\/a>. 2016\u2019da birka\u00e7 farkl\u0131 s\u00fcr\u00fcm daha kald\u0131r\u0131ld\u0131. Analistlerimiz 2017\u2019deki iki ayl\u0131k bir d\u00f6nem i\u00e7erisinde Google Play\u2019de bu \u015fekilde <a href=\"https:\/\/securelist.com\/still-stealing\/83343\/\" target=\"_blank\" rel=\"noopener\">85 uygulama tespit etti<\/a>. Ayr\u0131ca, ma\u011fazada ayn\u0131 geli\u015ftiriciler taraf\u0131nda geli\u015ftirilen sahte Telegram s\u00fcr\u00fcmleri de bulundu: Bu uygulamalar \u015fifre \u00e7alm\u0131yordu, fakat kurban\u0131 siber su\u00e7lular\u0131n \u00e7\u0131kar\u0131 do\u011frultusunda gruplara ve sohbetlere ekliyordu.<\/p>\n<h3>Google Play\u2019deki k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m ordusu<\/h3>\n<p>Ne yaz\u0131k ki tek bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n 85 farkl\u0131 kopyas\u0131, hikayenin sonu de\u011fildi. Uzmanlar 2016\u2019da Google Play\u2019de DressCode Truva At\u0131 ile donat\u0131lm\u0131\u015f <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/dresscode-android-trojan\/2523\/\" target=\"_blank\" rel=\"noopener\">400\u2019den fazla oyun ve ba\u015fka uygulama<\/a> buldu.<\/p>\n<p>Bu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, kurban\u0131n cihaz\u0131na ula\u015ft\u0131ktan sonra komuta ve kontrol sunucular\u0131yla ileti\u015fim kurup \u201cuykuya dal\u0131yordu\u201d. Ard\u0131ndan siber su\u00e7lular vir\u00fcs bula\u015fan ve uyumakta olan bu cihazlar\u0131 DDoS sald\u0131r\u0131lar\u0131 i\u00e7in, reklam t\u0131klamalar\u0131n\u0131 art\u0131rmak i\u00e7in ya da ev a\u011f\u0131 veya \u015firket altyap\u0131s\u0131 gibi cihaz\u0131n ba\u011fl\u0131 oldu\u011fu yerel a\u011flara s\u0131zmak i\u00e7in kullanabiliyordu.<\/p>\n<p>Adil olmak gerekirse bunu g\u00f6zden ka\u00e7\u0131rd\u0131klar\u0131 i\u00e7in Google Play moderat\u00f6rlerini su\u00e7layamay\u0131z; DressCode tespit edilmesi \u00e7ok zor bir yaz\u0131l\u0131md\u0131. Kodu o kadar k\u00fc\u00e7\u00fckt\u00fc ki, medya uygulamas\u0131n\u0131n kodu i\u00e7inde kayboluyordu. Ayr\u0131ca, \u00fc\u00e7\u00fcnc\u00fc taraf sitelerde Google Play\u2019de oldu\u011fundan \u00e7ok daha fazla vir\u00fcsl\u00fc uygulama tespit edildi: Ara\u015ft\u0131rmac\u0131lar DressCode Truva At\u0131\u2019n\u0131n i\u00e7eren toplamda yakla\u015f\u0131k 3000 oyun, d\u0131\u015f g\u00f6r\u00fcn\u00fcm uygulamas\u0131 ve ak\u0131ll\u0131 telefon temizleme uygulamas\u0131 buldu. Yine de 400 \u00e7ok y\u00fcksek bir say\u0131.<\/p>\n<h2>Google Play\u2019den k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m kapmaman\u0131n yollar\u0131<\/h2>\n<p>G\u00f6rd\u00fc\u011f\u00fcn\u00fcz gibi, bir uygulaman\u0131n yaln\u0131zca resmi Android ma\u011fazas\u0131na girebilmi\u015f olmas\u0131, g\u00fcvenli oldu\u011fu anlam\u0131na gelmiyor. K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar bazen aradan s\u0131zabiliyor. Vir\u00fcs kapmay\u0131 \u00f6nlemek i\u00e7in Google Play\u2019dekiler de dahil t\u00fcm programlara tedbirli yakla\u015f\u0131n ve birka\u00e7 dijital hijyen kural\u0131n\u0131 g\u00f6zetin.<\/p>\n<ul>\n<li>Uygulamalar\u0131 ak\u0131ll\u0131 telefonunuza hemen indirmeyin. Uygulaman\u0131n kullan\u0131c\u0131 de\u011ferlendirmelerini okuyun: Bu de\u011ferlendirmeler, uygulaman\u0131n davran\u0131\u015flar\u0131 hakk\u0131nda de\u011ferli bilgiler i\u00e7erebilir. Geli\u015ftirici hakk\u0131nda bilgi aray\u0131n; geli\u015ftirdi\u011fi \u00f6nceki uygulamalar ma\u011fazadan kald\u0131r\u0131lm\u0131\u015f ya da baz\u0131 \u015f\u00fcpheli hikayelerle ili\u015fkilendirilmi\u015f olabilir.<\/li>\n<li>Kullan\u0131c\u0131 de\u011ferlendirmelerini dikkatle okuyun. Baz\u0131 \u015f\u00fcpheli geli\u015ftiricilerin sayfalar\u0131n\u0131 <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/dont-believe-google-play-ratings\/2393\/\" target=\"_blank\" rel=\"noopener\">olumlu de\u011ferlendirmelerle<\/a> doldurabilece\u011fini unutmay\u0131n; do\u011fal bir dile sahip, ger\u00e7ek g\u00f6r\u00fcnen, belirli bir uzunluka (yaln\u0131zca \u201cHarika bir uygulama!\u201d yazmayan) de\u011ferlendirmelere bak\u0131n.<\/li>\n<li>Birka\u00e7 ayda bir Android ak\u0131ll\u0131 telefonunuzdan veya tabletinizden gereksiz programlar\u0131 silmeyi al\u0131\u015fkanl\u0131k haline getirin. Cihaz\u0131n\u0131zda ne kadar az uygulama olursa bunlar\u0131 kontrol ve g\u00f6zetim alt\u0131nda tutmak o kadar kolay olacakt\u0131r.<\/li>\n<li><a href=\"https:\/\/kas.pr\/kisatr\" target=\"_blank\" rel=\"noopener\">G\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> kullan\u0131n; bu sizi Google Play moderat\u00f6rlerinin g\u00f6zden ka\u00e7\u0131rd\u0131\u011f\u0131 tehditlerden koruyacakt\u0131r.<\/li>\n<\/ul>\n<p><strong>Peki, Google Play\u2019de k\u00f6t\u00fc ama\u00e7l\u0131 uygulama bulunmad\u0131\u011f\u0131 do\u011fru mu, yanl\u0131\u015f m\u0131?<\/strong><\/p>\n<p><strong> Yanl\u0131\u015f. Google Play\u2019e de zaman zaman k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m s\u0131zabiliyor. Resmi Android ma\u011fazas\u0131ndan vir\u00fcs kapma riski, \u00fc\u00e7\u00fcnc\u00fc taraf sitelerde oldu\u011fundan \u00e7ok daha az olsa da, hala mevcut. <\/strong><\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"android-malware\">\n","protected":false},"excerpt":{"rendered":"<p>Resmi Android ma\u011fazas\u0131nda k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar yok, de\u011fil mi? Bu iddian\u0131n temeline iniyoruz.<\/p>\n","protected":false},"author":2484,"featured_media":6435,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[555,105,2010,183,744,519,537],"class_list":{"0":"post-6434","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-akilli-telefonlar","9":"tag-android","10":"tag-dogru-mu-yanlis-mi","11":"tag-google-play","12":"tag-guvenlik","13":"tag-ipuclari-2","14":"tag-tehditler"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/google-play-malware\/6434\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/google-play-malware\/16636\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/google-play-malware\/14028\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/google-play-malware\/6503\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/google-play-malware\/18602\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/google-play-malware\/16674\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/google-play-malware\/15428\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/google-play-malware\/19299\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/google-play-malware\/17997\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/google-play-malware\/23629\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/google-play-malware\/28604\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/google-play-malware\/12310\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/google-play-malware\/12318\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/google-play-malware\/11181\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/google-play-malware\/20199\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/google-play-malware\/24133\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/google-play-malware\/24283\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/google-play-malware\/19072\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/google-play-malware\/23358\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/google-play-malware\/23268\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/android\/","name":"android"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2484"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=6434"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6434\/revisions"}],"predecessor-version":[{"id":6728,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6434\/revisions\/6728"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/6435"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=6434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=6434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=6434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}