{"id":8480,"date":"2020-06-18T18:23:19","date_gmt":"2020-06-18T15:23:19","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=8480"},"modified":"2020-06-18T18:23:19","modified_gmt":"2020-06-18T15:23:19","slug":"how-scammers-hook-smb","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/how-scammers-hook-smb\/8480\/","title":{"rendered":"Doland\u0131r\u0131c\u0131lar KOB\u0130&#8217;leri nas\u0131l tuza\u011fa d\u00fc\u015f\u00fcr\u00fcr?"},"content":{"rendered":"<p>\u00c7evrimi\u00e7i doland\u0131r\u0131c\u0131lar, sadece s\u0131radan kullan\u0131c\u0131lar\u0131 de\u011fil, ayn\u0131 zamanda \u015firket \u00e7al\u0131\u015fanlar\u0131n\u0131 da doland\u0131rmaya \u00e7al\u0131\u015f\u0131rlar. Elbette, bir i\u015fletmeyi doland\u0131rmaya \u00e7al\u0131\u015fmak emekli olmu\u015f birisini doland\u0131rmaktan daha zordur, ancak bir i\u015fletmeyi doland\u0131rman\u0131n potansiyel getiri oran\u0131 \u00e7ok daha y\u00fcksektir. Bu nedenle, doland\u0131r\u0131c\u0131lar\u0131n KOB\u0130\u2019leri tuza\u011fa d\u00fc\u015f\u00fcrme \u00e7abalar\u0131 h\u0131z kesmeden devam eder.<\/p>\n<p>Bu konuda \u00e7ok say\u0131da teknik vard\u0131r, ancak doland\u0131r\u0131c\u0131lar genellikle tembel oldu\u011fundan \u00e7o\u011fu durumda test edilmi\u015f ve onaylanm\u0131\u015f teknikleri kullan\u0131rlar. \u0130\u015fte en yayg\u0131n kullan\u0131lan teknikler:<\/p>\n<h2>Tuzak t\u00fcrleri<\/h2>\n<p>Siber su\u00e7lular i\u00e7in sadece mesajlar\u0131n\u0131z\u0131 okuman\u0131z de\u011fil, ayn\u0131 zamanda mesajlar\u0131n\u0131zda istenileni yapman\u0131z da \u00f6nemlidir: Bir ba\u011flant\u0131ya t\u0131klamak, bir ek a\u00e7mak, bir fatura \u00f6demek. Bunu yapmak i\u00e7in siber su\u00e7lular\u0131n dikkatinizi \u00e7ekmeleri gerekiyor.<\/p>\n<h3>Ald\u0131\u011f\u0131n\u0131z vergi hizmetinden bir ihtar<\/h3>\n<p>Vergilerinizi tam \u00f6deme\u011finizi belirten ve faturan\u0131za bir de faizin eklenece\u011fini belirten bir e-posta ald\u0131n\u0131z. Bu karara itiraz etmek isterseniz ekteki formu indirmeniz, doldurman\u0131z ve g\u00f6ndermeniz gerekir. Formun i\u00e7inde bir makro vard\u0131r ve etkinle\u015ftirir etkinle\u015ftirmez (\u00e7o\u011fu kullan\u0131c\u0131 a\u00e7\u0131l\u0131r pencerelerde otomatik olarak \u201cKabul ediyorum\u201d butonuna t\u0131klar), k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 hemen indirir ve \u00e7al\u0131\u015ft\u0131r\u0131r.<\/p>\n<p>Bir\u00e7ok i\u015fletme vergi otoritelerinden \u00e7ekinir, ancak ger\u00e7ek ile sahte e-posta aras\u0131nda fark\u0131 anlamak \u00f6nemlidir. Yerel vergi dairenizin genellikle e-posta m\u0131 yollad\u0131\u011f\u0131n\u0131 veya \u015firketinizi mi arad\u0131\u011f\u0131n\u0131 bilmek sizi istenmeyen durumlardan kurtarabilir.<\/p>\n<h3>Bekleyen \u00f6demelerle ilgili bildirimler<\/h3>\n<p>T\u00fcm vergilerinizi \u00f6dediniz ve t\u00fcm y\u00fcklenicilerle anla\u015ft\u0131n\u0131z m\u0131? Harika, ancak yine de bir \u00f6demenin yap\u0131lamad\u0131\u011f\u0131n\u0131 belirten bir e-posta alabilirsiniz. Yeniden d\u00fczenlenen s\u00f6zde bir faturay\u0131 \u00f6demeniz i\u00e7in g\u00f6nderilen bir talepten sizi bilmedi\u011finiz bir siteye y\u00f6nlendiren bir ba\u011flant\u0131ya kadar bu e-postan\u0131n i\u00e7erisinde her \u015fey olabilir.<\/p>\n<p>Antivir\u00fcs \u015f\u00fcpheli bir ba\u011flant\u0131y\u0131 engelleyebilir, ancak yaln\u0131zca dikkatiniz ayn\u0131 faturay\u0131 iki kez \u00f6demenizi engelleyebilir.<\/p>\n<h3>Gizemli bir y\u00fckleniciden teklif<\/h3>\n<p>Toplu sat\u0131\u015f e-postalar\u0131, en az\u0131ndan bir k\u0131sm\u0131n\u0131n iyi bir hedefin ilgisini \u00e7ekece\u011fi umuduyla genellikle rastgele g\u00f6nderilir. Toplu sat\u0131\u015f e-postalar\u0131na benzeyen ancak \u00fcr\u00fcn veya hizmet ayr\u0131nt\u0131lar\u0131 gibi g\u00f6r\u00fcnen k\u00f6t\u00fc ama\u00e7l\u0131 ekler i\u00e7eren doland\u0131r\u0131c\u0131l\u0131k ama\u00e7l\u0131 e-postalar da ayn\u0131 \u015fekilde g\u00f6nderilir.<\/p>\n<h2>G\u00fcvenlik hizmeti bildirimi<\/h2>\n<p>Bu doland\u0131r\u0131c\u0131l\u0131k, genel olarak farkl\u0131 lokasyonlarda ofisleri olan \u015firketler \u00fczerinde \u00e7al\u0131\u015f\u0131r. B\u00f6lge ofis \u00e7al\u0131\u015fanlar\u0131 genellikle Genel Merkez personelinin neye benzedi\u011fine ve ne yapt\u0131\u011f\u0131na dair net bir fikre sahip de\u011fildir. \u201cG\u00fcvenlik m\u00fcd\u00fcr\u00fc\u201d ad\u0131yla bir g\u00fcvenlik sertifikas\u0131 y\u00fcklemelerini s\u00f6ylenen bir e-posta ald\u0131\u011f\u0131nda \u00e7o\u011fu ki\u015fi iletinin sahte bir adresten geldi\u011fini fark etmeden s\u00f6ylenenleri yapacakt\u0131r. Sertifikay\u0131 y\u00fcklerseniz sizi en ince detaylar\u0131n\u0131za kadar takip edebilirler.<\/p>\n<h3>Tuza\u011fa d\u00fc\u015f\u00fcr\u00fclmenin sonu\u00e7lar\u0131<\/h3>\n<p>Kimlik av\u0131 kavramsal olarak basittir. Amac\u0131 kimlik bilgilerinizi \u00e7almakt\u0131r, ancak e-posta k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131n\u0131n ama\u00e7lar\u0131 farkl\u0131d\u0131r. En yayg\u0131n t\u00fcrler, a\u015fa\u011f\u0131daki listede yer alan t\u00fcrlerdir.<\/p>\n<h3>Bilgisayardaki bir RAT (Uzaktan Eri\u015fim Truva Atlar\u0131)<\/h3>\n<p>Siber su\u00e7lular, sald\u0131rganlar\u0131n zarar verebilecekleri bir kurumsal a\u011fa girmelerini sa\u011flayan uzaktan eri\u015fim ara\u00e7lar\u0131n\u0131 (RAT) severler. \u00d6rne\u011fin, bir RAT kullanmak bir yabanc\u0131n\u0131n ek k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m y\u00fcklemesini, \u00f6nemli belgeleri \u00e7almas\u0131n\u0131, finans y\u00f6neticisinin bilgisayar\u0131n\u0131n yerini bulmas\u0131n\u0131, \u00f6deme sistemi eri\u015fim verilerini kesmesini ve ard\u0131ndan kendi hesaplar\u0131na para aktarmas\u0131n\u0131 sa\u011flayabilir.<\/p>\n<h3>Fidye yaz\u0131l\u0131m<\/h3>\n<p>Fidye yaz\u0131l\u0131m, dosyalar\u0131 kullan\u0131lamayacaklar\u0131 \u015fekilde \u015fifreler. Bu, art\u0131k \u00f6nemli belgelerinize ula\u015famaman\u0131z ve hatta bir sunum yapamaman\u0131z anlam\u0131na gelir. Baz\u0131 fidye yaz\u0131l\u0131mlar\u0131 yerel bir a\u011fa yay\u0131larak ba\u015flang\u0131\u00e7ta bir bilgisayara n\u00fcfuz eder, ancak Truva At\u0131\u2019n\u0131n ula\u015ft\u0131\u011f\u0131 her makinedeki verileri \u015fifreler. Dosyalar\u0131 geri alabilmeniz i\u00e7in sald\u0131rganlar bir fidye (ad\u0131ndan da anla\u015f\u0131laca\u011f\u0131 \u00fczere) talep eder. \u00d6rne\u011fin, k\u0131sa bir s\u00fcre \u00f6nce <a href=\"https:\/\/www.kaspersky.com\/blog\/baltimore-encrypted\/27150\/\" target=\"_blank\" rel=\"noopener nofollow\">Maryland, Baltimore\u2019daki belediye bilgisayarlar\u0131<\/a>, baz\u0131 hizmetleri tamamen devre d\u0131\u015f\u0131 b\u0131rakan fidye yaz\u0131l\u0131mlar\u0131 sald\u0131r\u0131s\u0131na u\u011frad\u0131. Sald\u0131rganlar t\u00fcm dosyalar\u0131 geri vermek i\u00e7in 100.000 dolardan fazla talep ettiler.<\/p>\n<h3>Casus yaz\u0131l\u0131m<\/h3>\n<p>Siber su\u00e7lular, \u015firketlere s\u0131zmak i\u00e7in maksimum bilgi toplayan k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar olan casus yaz\u0131l\u0131m Truva atlar\u0131n\u0131 kullanmay\u0131 sever. Casus yaz\u0131l\u0131m, kendini belli etmeden kal\u0131r, kullan\u0131c\u0131 adlar\u0131n\u0131, parolalar\u0131 ve adresleri g\u00fcnl\u00fc\u011fe kaydeder ve e-postalar\u0131 ve dosya eklerini toplar. Teknoloji \u015firketleri i\u00e7in, buradaki ana tehlike \u00f6zel bilgiler veya planlar rakiplere s\u0131zabilir. Di\u011fer i\u015fletmeler i\u00e7in ise casus yaz\u0131l\u0131mlar\u0131n ana tehdidi, sald\u0131rganlar finansal sisteme girip para \u00e7alabilirler. Bu durum, b\u00fcy\u00fck kurulu\u015flarda da ger\u00e7ekle\u015febilir. \u00d6rne\u011fin, <a href=\"https:\/\/www.kaspersky.com\/blog\/lazarus-modus-operandi-and-countermeasures\/6716\/\" target=\"_blank\" rel=\"noopener nofollow\">Banglade\u015f Merkez Bankas\u0131 81 milyon dolarl\u0131k bir sald\u0131r\u0131n\u0131n hedefi oldu<\/a>.<\/p>\n<h3>Genel KOB\u0130 doland\u0131r\u0131c\u0131l\u0131klar\u0131ndan nas\u0131l korunulur<\/h3>\n<p>Doland\u0131r\u0131c\u0131lar\u0131n KOB\u0130 tuzaklar\u0131ndan uzak durmak i\u00e7in bu genel g\u00fcvenlik ipu\u00e7lar\u0131n\u0131 izleyin:<\/p>\n<ul>\n<li>Dikkatli olun;<\/li>\n<li>\u0130\u00e7inde bulundu\u011funuz yarg\u0131 d\u00fczeninin yasalar\u0131n\u0131 bilin ve h\u00fck\u00fcmetin ve d\u00fczenleyicilerin nas\u0131l \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131 anlay\u0131n;<\/li>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/blog\/top4-dangerous-attachments-2019\/6047\/\" target=\"_blank\" rel=\"noopener\">Hangi dosya t\u00fcrlerinin di\u011ferlerinden daha tehlikeli oldu\u011funun fark\u0131nda olun;<\/a><\/li>\n<li>T\u00fcm \u00e7al\u0131\u015fma cihazlar\u0131na, <a href=\"https:\/\/www.kaspersky.com.tr\/small-business-security\/small-office-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_banner____ksos___\" target=\"_blank\" rel=\"noopener\">tercihen spam ve kimlik av\u0131na kar\u015f\u0131 korumal\u0131 bir vir\u00fcsten koruma \u00e7\u00f6z\u00fcm\u00fc<\/a> y\u00fckleyin.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksos\">\n","protected":false},"excerpt":{"rendered":"<p>KOB\u0130 \u00e7al\u0131\u015fanlar\u0131n\u0131 hedefleyen yayg\u0131n sald\u0131r\u0131 planlar\u0131. <\/p>\n","protected":false},"author":2581,"featured_media":8481,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194,1727],"tags":[1921,1074,1753,1986],"class_list":{"0":"post-8480","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"category-smb","10":"tag-e-posta","11":"tag-kimlik-avi","12":"tag-rat","13":"tag-truva-atlari"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/how-scammers-hook-smb\/8480\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/how-scammers-hook-smb\/21465\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/how-scammers-hook-smb\/16934\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/how-scammers-hook-smb\/22633\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/how-scammers-hook-smb\/20748\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/how-scammers-hook-smb\/19121\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/how-scammers-hook-smb\/22940\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/how-scammers-hook-smb\/22016\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/how-scammers-hook-smb\/28613\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/how-scammers-hook-smb\/35943\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/how-scammers-hook-smb\/15132\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/how-scammers-hook-smb\/15684\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/how-scammers-hook-smb\/13601\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/how-scammers-hook-smb\/24307\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/how-scammers-hook-smb\/28694\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/how-scammers-hook-smb\/25581\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/how-scammers-hook-smb\/22504\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/how-scammers-hook-smb\/27748\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/how-scammers-hook-smb\/27589\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/e-posta\/","name":"e-posta"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=8480"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8480\/revisions"}],"predecessor-version":[{"id":8489,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8480\/revisions\/8489"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/8481"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=8480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=8480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=8480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}