{"id":6547,"date":"2019-10-15T14:09:04","date_gmt":"2019-10-15T11:09:04","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=6547"},"modified":"2019-11-15T14:22:57","modified_gmt":"2019-11-15T11:22:57","slug":"performance-appraisal-spam","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/performance-appraisal-spam\/6547\/","title":{"rendered":"Performans de\u011ferlendirme kisvesi alt\u0131nda kurumsal kimlik av\u0131"},"content":{"rendered":"<p>Kurumsal hesaplar\u0131n kimlik bilgilerini ele ge\u00e7irmek isteyen siber su\u00e7lular, \u00e7al\u0131\u015fanlar\u0131 kimlik av\u0131 sitelerine \u00e7ekmek i\u00e7in yeni yollar buluyor. \u00d6nceki doland\u0131r\u0131c\u0131l\u0131k giri\u015fimleri, yem olarak <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/sharepoint-phishing-attack\/5668\/\" target=\"_blank\" rel=\"noopener\">SharePoint davetiyelerini<\/a> ve <a href=\"https:\/\/www.kaspersky.co.uk\/blog\/fake-voicemail-spam\/16756\/\" target=\"_blank\" rel=\"noopener\">sesli mesajlar\u0131<\/a> kullanm\u0131\u015ft\u0131.<\/p>\n<p>Uzmanlar\u0131m\u0131z son olarak siber su\u00e7lular\u0131n hedefteki \u015firketin performans de\u011ferlendirme s\u00fcrecini taklit etmeye \u00e7al\u0131\u015ft\u0131\u011f\u0131 bir kimlik av\u0131 doland\u0131r\u0131c\u0131l\u0131\u011f\u0131n\u0131 ortaya \u00e7\u0131kard\u0131. Sald\u0131r\u0131 iki \u015fekilde ilerliyor: Al\u0131c\u0131lar, de\u011ferlendirmenin (a) zorunlu oldu\u011funu ya da (b) maa\u015f art\u0131\u015f\u0131na yol a\u00e7aca\u011f\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcyorlar. Bu tarz de\u011ferlendirmelerin baz\u0131 \u015firketlerde \u00fccret revizyonu s\u00fcrecinin rutin bir par\u00e7as\u0131 oldu\u011funu not d\u00fc\u015felim; bu y\u00fczden bu talep \u015f\u00fcphe uyand\u0131rm\u0131yor.<\/p>\n<p>Sald\u0131r\u0131 her zamanki gibi bir e-posta ile ba\u015fl\u0131yor. \u00c7al\u0131\u015fanlar, \u0130K\u2019dan geliyormu\u015f gibi g\u00f6r\u00fcnen bir performans de\u011ferlendirme daveti al\u0131yorlar. Mesaj\u0131n i\u00e7indeki metin, doldurulmas\u0131 gereken \u201cperformans de\u011ferlendirmesinin\u201d yer ald\u0131\u011f\u0131 web sitesinin ba\u011flant\u0131s\u0131n\u0131 i\u00e7eriyor.<\/p>\n<h2>Konuya yabanc\u0131 olanlar hedefleniyor<\/h2>\n<p>Talimatlara g\u00f6re kullan\u0131c\u0131n\u0131n ba\u011flant\u0131ya t\u0131klayarak oturum a\u00e7mas\u0131, di\u011fer detaylar\u0131 i\u00e7eren bir e-posta g\u00f6nderilmesini beklemesi ve \u00fc\u00e7 se\u00e7enekten birini tercih etmesi gerekiyor. \u015eirkette yeni olanlar ve de\u011ferlendirme s\u00fcre\u00e7lerine \u00e7ok hakim olmayanlar i\u00e7in bu ad\u0131mlar ikna edici g\u00f6r\u00fcnebiliyor. Yaln\u0131zca (kurumsal kaynaklarla ilgisi olmayan) web sitesi adresi \u015f\u00fcphe uyand\u0131rabiliyor.<\/p>\n<p>\u00c7al\u0131\u015fanlar ba\u011flant\u0131ya t\u0131klad\u0131klar\u0131nda bir \u201c\u0130K portal\u0131n\u0131n\u201d giri\u015f sayfas\u0131n\u0131 g\u00f6r\u00fcyorlar. Kurumsal hizmetlerin giri\u015f sayfalar\u0131 gibi g\u00f6r\u00fcnmeye \u00e7al\u0131\u015fan bir\u00e7ok kimlik av\u0131 kayna\u011f\u0131n\u0131n aksine, parlak, tek renkli veya renk ge\u00e7i\u015fli bir arka plan \u00fczerinde sayfay\u0131 kaplayan veri giri\u015fi alanlar\u0131na sahip bu sayfa olduk\u00e7a ilkel g\u00f6r\u00fcn\u00fcyor. Doland\u0131r\u0131c\u0131lar orijinal g\u00f6r\u00fcnmek i\u00e7in kullan\u0131c\u0131dan gizlilik politikas\u0131n\u0131 kabul etmesini de istiyor (b\u00f6yle bir belgeye y\u00f6nlendiren herhangi bir ba\u011flant\u0131 sunmadan).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6549\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2019\/10\/15135908\/performance-appraisal-spam-screen-1.png\" alt=\"\" width=\"768\" height=\"517\"><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6550\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2019\/10\/15140006\/performance-appraisal-spam-screen-2.png\" alt=\"\" width=\"792\" height=\"523\"><\/p>\n<p>Kurbandan kullan\u0131c\u0131 ad\u0131n\u0131, parolas\u0131n\u0131 ve e-posta adresini girmesi isteniyor. Baz\u0131 durumlarda doland\u0131r\u0131c\u0131lar i\u015f adresinin girilmesini de isteyebiliyor. \u00c7al\u0131\u015fan, Oturum A\u00e7 veya De\u011ferlendirme d\u00fc\u011fmesine bast\u0131\u011f\u0131nda asl\u0131nda bu verileri siber su\u00e7lulara g\u00f6ndermi\u015f oluyor.<\/p>\n<p>Bu noktada \u201cde\u011ferlendirme\u201d \u00e7o\u011funlukla bir anda sonlan\u0131yor. \u00c7al\u0131\u015fan bir s\u00fcre bahsedilen ayr\u0131nt\u0131lar\u0131 i\u00e7eren e-postan\u0131n gelmesini bekliyor. En iyi olas\u0131l\u0131kla bir terslik oldu\u011fundan \u015f\u00fcpheleniyorlar ya da ger\u00e7ek \u0130K departman\u0131na bir hat\u0131rlatma mesaj\u0131 g\u00f6nderiyorlar; \u0130K da b\u00f6ylece BT g\u00fcvenli\u011fini konudan haberdar ediyor. Aksi durumlarda ise \u015firket, kimlik h\u0131rs\u0131zl\u0131\u011f\u0131 ya\u015fand\u0131\u011f\u0131n\u0131 aylarca tespit edemeyebiliyor.<\/p>\n<h3>Kurumsal hesaplar\u0131n \u00e7al\u0131nmas\u0131n\u0131n tehlikeleri<\/h3>\n<p>T\u00fcm bunlar elbette s\u00f6z konusu \u015firketin hangi teknolojileri kulland\u0131\u011f\u0131na ba\u011fl\u0131. \u00c7al\u0131\u015fanlar\u0131n kimlik bilgilerini ele ge\u00e7iren siber su\u00e7lular, \u00f6rne\u011fin di\u011fer \u015firketlerin \u00e7al\u0131\u015fanlar\u0131na, ortaklar\u0131na ya da m\u00fc\u015fterilerine kurban\u0131n ad\u0131yla hedef g\u00f6zeten kimlik av\u0131 e-postalar\u0131 g\u00f6ndererek zarara sebep olabilirler.<\/p>\n<p>Sald\u0131rgan, yaz\u0131\u015fmalara veya \u015firket i\u00e7i gizli belgelere de eri\u015febilir; bu da sald\u0131r\u0131n\u0131n ba\u015far\u0131l\u0131 olma \u015fans\u0131n\u0131 art\u0131r\u0131r: Kurbandan geliyormu\u015f gibi g\u00f6r\u00fcnen mesajlar\u0131n hem istenmeyen e-posta filtrelerini a\u015fmas\u0131 hem de al\u0131c\u0131lar\u0131 g\u00fcvenli hissettirerek kand\u0131rmas\u0131 olas\u0131l\u0131\u011f\u0131 daha y\u00fcksektir. \u00c7al\u0131nan bilgiler daha sonra kurumsal e-postalar\u0131n ele ge\u00e7irilmesi (BEC) sald\u0131r\u0131lar\u0131 da dahil olmak \u00fczere \u015firketi hedef alan \u00e7e\u015fitli sald\u0131r\u0131lar i\u00e7in de kullan\u0131labilir.<\/p>\n<p>Dahas\u0131, \u015firket i\u00e7i belgeler ve \u00e7al\u0131\u015fan mesajlar\u0131, \u015fantaj veya rakiplere satma gibi farkl\u0131 su\u00e7lar i\u00e7in de kullan\u0131labilir.<\/p>\n<h3>Kimlik av\u0131 sald\u0131r\u0131lar\u0131na kar\u015f\u0131 nas\u0131l korunabilirsiniz?<\/h3>\n<p>B\u00f6yle sald\u0131r\u0131lar her \u015feyden \u00f6nce insan fakt\u00f6r\u00fcn\u00fc hedef al\u0131r. Bu y\u00fczden, \u00e7al\u0131\u015fanlar\u0131n \u015firketin siber g\u00fcvenlik prosed\u00fcrlerine ve s\u00fcre\u00e7lerine a\u015fina olmas\u0131n\u0131 sa\u011flamak hayati \u00f6nem ta\u015f\u0131r.<\/p>\n<ul>\n<li>\u00c7al\u0131\u015fanlar\u0131n e-postalarda yer alan ba\u011flant\u0131lara dikkatle yakla\u015fmas\u0131 ve yaln\u0131zca do\u011frulu\u011fundan emin olduklar\u0131 ba\u011flant\u0131lar\u0131 a\u00e7mas\u0131 gerekti\u011fine dair d\u00fczenli hat\u0131rlatmalar yay\u0131nlay\u0131n;<\/li>\n<li>\u00c7al\u0131\u015fanlara i\u015f hesab\u0131 bilgilerini \u015firket d\u0131\u015f\u0131ndaki sitelere girmemeleri gerekti\u011fini hat\u0131rlat\u0131n;<\/li>\n<li>Kimlik av\u0131 e-postalar\u0131n\u0131, kimsenin gelen kutusuna d\u00fc\u015fmeden \u00f6nce engelleyin. Bunun i\u00e7in e-posta sunucusu seviyesinde bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc kurun. <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security\/mail-server\" target=\"_blank\" rel=\"noopener\">Kaspersky Security for Mail Server<\/a> veya <a href=\"https:\/\/kas.pr\/kdkesbtr\" target=\"_blank\" rel=\"noopener\">Kaspersky Endpoint Security for Business Advanced<\/a> bu i\u015f i\u00e7in bi\u00e7ilmi\u015f kaftand\u0131r.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-b2b\">\n","protected":false},"excerpt":{"rendered":"<p>Doland\u0131r\u0131c\u0131lar, \u00e7al\u0131\u015fanlar\u0131 performans de\u011ferlendirmesine kat\u0131lmaya te\u015fvik ederken asl\u0131nda i\u015f hesab\u0131 parolalar\u0131n\u0131 \u00e7al\u0131yorlar.<\/p>\n","protected":false},"author":2481,"featured_media":6548,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[1920,1074,537],"class_list":{"0":"post-6547","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-istenmeyen-e-posta","10":"tag-kimlik-avi","11":"tag-tehditler"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/performance-appraisal-spam\/6547\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/performance-appraisal-spam\/16774\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/performance-appraisal-spam\/14163\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/performance-appraisal-spam\/18761\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/performance-appraisal-spam\/16808\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/performance-appraisal-spam\/15553\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/performance-appraisal-spam\/19459\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/performance-appraisal-spam\/18118\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/performance-appraisal-spam\/23764\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/performance-appraisal-spam\/28924\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/performance-appraisal-spam\/12406\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/performance-appraisal-spam\/12486\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/performance-appraisal-spam\/11339\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/performance-appraisal-spam\/20406\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/performance-appraisal-spam\/24344\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/performance-appraisal-spam\/24319\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/performance-appraisal-spam\/19227\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/performance-appraisal-spam\/23543\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/performance-appraisal-spam\/23393\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/istenmeyen-e-posta\/","name":"istenmeyen e-posta"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6547","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2481"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=6547"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6547\/revisions"}],"predecessor-version":[{"id":6712,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6547\/revisions\/6712"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/6548"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=6547"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=6547"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=6547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}