{"id":8475,"date":"2020-06-17T13:30:09","date_gmt":"2020-06-17T10:30:09","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=8475"},"modified":"2020-06-17T13:30:09","modified_gmt":"2020-06-17T10:30:09","slug":"gaming-password-stealers","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/gaming-password-stealers\/8475\/","title":{"rendered":"Truva atlar\u0131 oyun hesaplar\u0131n\u0131 nas\u0131l \u00e7alar?"},"content":{"rendered":"<p>Oyun i\u00e7i \u00f6\u011feleri sat\u0131n al\u0131rken veya de\u011fi\u015ftirirken oyuncular\u0131n kar\u015f\u0131la\u015ft\u0131\u011f\u0131 kimlik av\u0131 ve her t\u00fcrl\u00fc doland\u0131r\u0131c\u0131l\u0131k yan\u0131 s\u0131ra korsan kopyalar, modlar ve hilelerdeki k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar da dahil \u00e7evrimi\u00e7i <a href=\"https:\/\/www.kaspersky.com\/blog\/steam-scam\/11317\/\" target=\"_blank\" rel=\"noopener nofollow\">tehditlerden s\u0131k s\u0131k bahsediyoruz<\/a>. K\u0131sa zaman \u00f6nce <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/whats-wrong-with-cheap-game-keys\/8372\/\" target=\"_blank\" rel=\"noopener\">hesap sat\u0131n alma ile ilgili sorunlar<\/a>a de\u011finmi\u015ftik. Neyse ki, bu tehditleri biliyorsan\u0131z bunlardan ka\u00e7\u0131nmak kolayd\u0131r.<\/p>\n<p>Ancak burada bilmeniz ve kar\u015f\u0131 koyman\u0131z gereken ba\u015fka bir sorun var: \u015eifre \u00e7al\u0131c\u0131lar. G\u00fcvenlik \u00e7\u00f6z\u00fcmlerimiz bunlar\u0131 yakalad\u0131\u011f\u0131nda, genellikle Trojan-PSW (veya benzeri) olarak adland\u0131r\u0131l\u0131yorlar. \u015eifre \u00e7al\u0131c\u0131lar, kullan\u0131c\u0131 ad\u0131\/\u015fifre kombinasyonlar\u0131 veya oturum belirte\u00e7leri gibi hesaplar\u0131 \u00e7almak i\u00e7in tasarlanm\u0131\u015f Truva atlar\u0131d\u0131r.<\/p>\n<p>D\u00fcnyan\u0131n en pop\u00fcler oyun servisi <a href=\"https:\/\/www.kaspersky.com\/blog\/stealing-steam-accounts\/11560\/\" target=\"_blank\" rel=\"noopener nofollow\">Steam\u2019deki hesaplar\u0131 \u00e7alan Truva atlar\u0131<\/a> hakk\u0131nda bir \u015feyler okumu\u015f olabilirsiniz. Ancak bu durumdan etkilenen Battle.net, Origin, Uplay ve Epic Games Store gibi bir\u00e7ok platform var. B\u00fct\u00fcn oyun platformlar\u0131n\u0131n milyonlarca dolara sahip olan bir kitlesi var, bu y\u00fczden do\u011fal olarak sald\u0131rganlar bu platformlarla ilgileniyorlar ve hesaplar\u0131 \u00e7almak i\u00e7in \u015fifre \u00e7al\u0131c\u0131lar \u00fcretiyorlar.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksc-gaming\">\n<h2>\u015eifre \u00e7al\u0131c\u0131 nedir?<\/h2>\n<p>\u015eifre \u00e7al\u0131c\u0131lar, hesap bilgilerini \u00e7alan bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m t\u00fcr\u00fcd\u00fcr. \u015eifre \u00e7al\u0131c\u0131lar temelde bankac\u0131l\u0131k Truva At\u0131\u2019na benzer. Ancak girilen verileri yakalamak veya de\u011fi\u015ftirmek yerine, genellikle bilgisayarda depolanm\u0131\u015f bilgileri \u00e7alar: <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/browser-data-theft\/6326\/\" target=\"_blank\" rel=\"noopener\">Taray\u0131c\u0131da kaydedilen<\/a> kullan\u0131c\u0131 adlar\u0131 ve \u015fifreler, \u00e7erezler ve vir\u00fcs bula\u015fm\u0131\u015f cihaz\u0131n sabit diskinde olan di\u011fer dosyalar. Dahas\u0131, bazen oyun hesaplar\u0131, h\u0131rs\u0131zlar\u0131n hedeflerinden sadece biridir. Baz\u0131 sald\u0131rganlar \u00e7evrimi\u00e7i bankac\u0131l\u0131k kimlik bilgilerinizle ilgilendi\u011fi kadar oyun hesaplar\u0131n\u0131z\u0131n kimlik bilgileriyle de ilgili olabilir.<\/p>\n<p>H\u0131rs\u0131zlar bir\u00e7ok \u015fekilde hesap alabilirler. \u015eifre \u00e7al\u0131c\u0131 Truva At\u0131 Kpot\u2019u (di\u011fer ad\u0131yla Trojan-PSW.Win32.Kpot) \u00f6rnek olarak al\u0131n. As\u0131l k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 bilgisayara indirmek i\u00e7in g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 (\u00f6rne\u011fin, Microsoft Office\u2019te olan bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131) kullanan e-posta spamlerindeki ekler arac\u0131l\u0131\u011f\u0131yla yay\u0131l\u0131r.<\/p>\n<p>Ard\u0131ndan, \u00e7al\u0131c\u0131lar bilgisayarda y\u00fckl\u00fc programlar hakk\u0131ndaki bilgileri komut ve kontrol sunucusuna aktar\u0131r ve komutlar\u0131n ilerlemesini bekler. Olas\u0131 komutlar aras\u0131nda \u00e7erezleri, Telegram ve Skype hesaplar\u0131n\u0131 \u00e7almak ve \u00e7ok daha fazlas\u0131 vard\u0131r.<\/p>\n<p>Tahmin edebilece\u011finiz gibi Blizzard\u2019\u0131n kendi oyun ba\u015flat\u0131c\u0131s\u0131 uygulamas\u0131 olan Battle.net\u2019e ba\u011fl\u0131 olan %APPDATA%\\Battle.net klas\u00f6r\u00fcndeki .config uzant\u0131l\u0131 dosyalar\u0131 \u00e7alabilir. Di\u011fer \u015feylerin yan\u0131 s\u0131ra, bu dosyalar oyuncunun oturum belirtecini i\u00e7erir. Siber su\u00e7lular, sadece kullan\u0131c\u0131 ad\u0131n\u0131 ve \u015fifreyi alamazlar, ancak bu belirte\u00e7leri hesap sahibi gibi davranmak i\u00e7in de kullanabilirler.<\/p>\n<p>Neden bunu yap\u0131yorlar? Basit: Ma\u011fdurun t\u00fcm oyun i\u00e7i e\u015fyalar\u0131n\u0131 h\u0131zl\u0131 bir \u015fekilde satabilir ve bazen bunu yaparak iyi para kazanabilirler. Bu, <em>World of Warcraft<\/em> ve <em>Diablo 3<\/em> dahil olmak \u00fczere \u00e7e\u015fitli Blizzard oyunlar\u0131nda uygulanabilir bir senaryodur.<\/p>\n<p>Ubisoft\u2019un oyun ba\u015flat\u0131c\u0131s\u0131 uygulamas\u0131 Uplay\u2019\u0131 hedefleyen di\u011fer k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar, Okasidis ad\u0131yla tan\u0131n\u0131yor ve \u00e7\u00f6z\u00fcmlerimiz buna Trojan-Banker.MSIL.Evital.gen ad\u0131n\u0131 veriyor. Oyun hesaplar\u0131 a\u00e7\u0131s\u0131ndan, iki belirli dosyay\u0131 \u00e7almas\u0131 d\u0131\u015f\u0131nda tam olarak Kpot Truva at\u0131 gibi davran\u0131r. Bu dosyalar: %LOCALAPPDATA%\\Ubisoft Game Launcher\\users.dat ve %LOCALAPPDATA%\\Ubisoft Game Launcher\\settings.yml.<\/p>\n<p>Uplay ayr\u0131ca %LOCALAPPDATA%\\Ubisoft Game Launcher\\ klas\u00f6r\u00fcndeki t\u00fcm dosyalar\u0131 \u00e7alan Thief Stealer (HEUR:Trojan.Win32.Generic olarak tespit edildi) olarak adland\u0131r\u0131lan bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m taraf\u0131ndan da hedef al\u0131n\u0131yor.<\/p>\n<p>Ayr\u0131ca, Uplay, Origin ve Battle.net de BetaBot k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n\u0131n (Trojan.Win32.Neurevt olarak tespit edildi) hedefidir. Ancak bu Truva At\u0131\u2019n\u0131n farkl\u0131 bir \u00e7al\u0131\u015fma \u015fekli var. Kullan\u0131c\u0131 belirli anahtar kelimeleri i\u00e7eren bir URL\u2019yi (\u00f6rne\u011fin, i\u00e7erisinde \u201cuplay\u201d veya \u201corigin\u201d kelimesi olan adresler) ziyaret ederse k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m bu sayfalardaki formlardan veri toplanmas\u0131n\u0131 sa\u011flar. Yani, bu sayfalara girilen hesap kullan\u0131c\u0131 adlar\u0131 ve \u015fifreler do\u011frudan sald\u0131rganlara gider.<\/p>\n<p>Her \u00fc\u00e7 durumda da, kullan\u0131c\u0131n\u0131n bir \u015fey fark etmesi pek m\u00fcmk\u00fcn de\u011fildir. Truva at\u0131, bilgisayarda hi\u00e7bir \u015fekilde kendini g\u00f6stermez, istek pencereleri g\u00f6r\u00fcnt\u00fclemez, sadece kurnazca dosyalar\u0131 ve\/veya verileri \u00e7alar.<\/p>\n<h2>Oyun hesaplar\u0131n\u0131 \u00e7almak isteyen Truva atlar\u0131na kar\u015f\u0131 nas\u0131l korunuruz?<\/h2>\n<p>Temelde, oyun hesaplar\u0131n\u0131n h\u0131rs\u0131zlara kar\u015f\u0131 da dahil olmak \u00fczere korudu\u011fumuz her \u015feyle ayn\u0131 \u015fekilde korunmas\u0131 gerekir. Truva at\u0131 h\u0131rs\u0131zlar\u0131n\u0131 engellemek i\u00e7in a\u015fa\u011f\u0131daki \u00f6nerileri izleyin:<\/p>\n<ul>\n<li>Hesab\u0131n\u0131z\u0131 iki fakt\u00f6rl\u00fc kimlik do\u011frulamayla koruyun. Steam\u2019in Steam Guard, Battle.net\u2019in Blizzard Authenticator uygulamalar\u0131 var. Epic Games Store ise kimlik do\u011frulay\u0131c\u0131 uygulamas\u0131 ile mesaj veya e-posta arac\u0131l\u0131\u011f\u0131yla kimlik do\u011frulamas\u0131 aras\u0131nda bir se\u00e7im sunuyor. Hesab\u0131n\u0131z <a href=\"https:\/\/www.kaspersky.com\/blog\/2fa-practical-guide\/24219\/\" target=\"_blank\" rel=\"noopener nofollow\">iki fakt\u00f6rl\u00fc kimlik do\u011frulama<\/a> ile korunuyorsa siber su\u00e7lular\u0131n hesaplar\u0131n\u0131za girmek i\u00e7in bir kullan\u0131c\u0131 ad\u0131 ve \u015fifreden daha fazlas\u0131na ihtiyac\u0131 olacakt\u0131r.<\/li>\n<li>\u015e\u00fcpheli sitelerden veya korsan yaz\u0131l\u0131mlardan modlar indirmeyin. Sald\u0131rganlar, insanlar\u0131n \u00fccretsiz olan oyunlar ve modlar\u0131 \u00e7ok sevdiklerinin fark\u0131ndad\u0131r ve crack\u2019lere, hilelere ve modlara gizlenmi\u015f k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlardan yararlan\u0131rlar.<\/li>\n<li>G\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc kullan\u0131n. \u00d6rne\u011fin, <a href=\"https:\/\/www.kaspersky.com.tr\/security-cloud?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_post____ksc___\" target=\"_blank\" rel=\"noopener\">Kaspersky Security Cloud<\/a> t\u00fcm bu h\u0131rs\u0131zlar\u0131 yakalar ve herhangi bir \u015feyi \u00e7almalar\u0131n\u0131 engeller.<\/li>\n<li>Oyun oynarken antivir\u00fcs\u00fcn\u00fcz\u00fc kapatmay\u0131n. Bunu yaparsan\u0131z bir \u015fifre \u00e7al\u0131c\u0131 aniden devreye girebilir. <a href=\"https:\/\/www.kaspersky.com.tr\/security-cloud?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_post____ksc___\" target=\"_blank\" rel=\"noopener\">Kaspersky Security Cloud<\/a> \u00e7\u00f6z\u00fcm\u00fcm\u00fcz\u00fcn oyun modu, antivir\u00fcs\u00fcn oyun s\u0131ras\u0131nda \u00e7ok fazla sistem kayna\u011f\u0131 t\u00fcketmesini \u00f6nler. \u00c7\u00f6z\u00fcm\u00fcm\u00fcz\u00fcn performans veya kare h\u0131z\u0131 \u00fczerinde hi\u00e7bir etkisi yoktur, siz oyun oynarken sadece g\u00fcvenlikle ilgilenir.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksc-gaming\">\n","protected":false},"excerpt":{"rendered":"<p>Belirli bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m t\u00fcr\u00fc, Origin, Battle.net ve Uplay gibi oyun hizmetleri hesaplar\u0131 dahil olmak \u00fczere bu hesaplar\u0131n kullan\u0131c\u0131 kimlik bilgilerini arar.<\/p>\n","protected":false},"author":2555,"featured_media":8478,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[585,586,2216,164,537,1986],"class_list":{"0":"post-8475","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-oyuncular","9":"tag-oyunlar","10":"tag-sifre-calicilar","11":"tag-steam","12":"tag-tehditler","13":"tag-truva-atlari"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/gaming-password-stealers\/8475\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/gaming-password-stealers\/21463\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/gaming-password-stealers\/16932\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/gaming-password-stealers\/8355\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/gaming-password-stealers\/22621\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/gaming-password-stealers\/20743\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/gaming-password-stealers\/19098\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/gaming-password-stealers\/22972\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/gaming-password-stealers\/21976\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/gaming-password-stealers\/28605\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/gaming-password-stealers\/35895\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/gaming-password-stealers\/15127\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/gaming-password-stealers\/15622\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/gaming-password-stealers\/13605\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/gaming-password-stealers\/24282\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/gaming-password-stealers\/11612\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/gaming-password-stealers\/28674\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/gaming-password-stealers\/25573\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/gaming-password-stealers\/22502\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/gaming-password-stealers\/27746\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/gaming-password-stealers\/27587\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/oyuncular\/","name":"oyuncular"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2555"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=8475"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8475\/revisions"}],"predecessor-version":[{"id":8479,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8475\/revisions\/8479"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/8478"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=8475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=8475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=8475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}