{"id":8649,"date":"2020-08-06T15:41:31","date_gmt":"2020-08-06T12:41:31","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=8649"},"modified":"2022-05-05T14:26:41","modified_gmt":"2022-05-05T11:26:41","slug":"wastedlocker-garmin-incident","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/wastedlocker-garmin-incident\/8649\/","title":{"rendered":"Hedefli fidye yaz\u0131l\u0131m WastedLocker analizi"},"content":{"rendered":"<p>Temmuz 2020\u2019de internetteki teknoloji siteleri, Garmin\u2019e yap\u0131lan sald\u0131r\u0131lar\u0131 anlatan makalelerle dolup ta\u015ft\u0131. Bulut ortam\u0131 ile senkronize etme ve pilotlar\u0131n kulland\u0131\u011f\u0131 cihazlar gibi \u00e7e\u015fitli Garmin hizmetleri devre d\u0131\u015f\u0131 b\u0131rak\u0131ld\u0131. Konu hakk\u0131ndaki do\u011fru bilginin k\u0131s\u0131tl\u0131 olmas\u0131 nedeniyle insanlar \u00e7\u0131lg\u0131nca teoriler \u00fcretmeye ba\u015flad\u0131. Biz ise durumu de\u011ferlendirmeden \u00f6nce somut verileri beklemeye karar verdik.<\/p>\n<p>Garmin, <a href=\"https:\/\/www.garmin.com\/en-US\/outage\/\" target=\"_blank\" rel=\"noopener nofollow\">resmi a\u00e7\u0131klamas\u0131nda<\/a> \u00e7evrimi\u00e7i hizmetlerini engelleyen ve baz\u0131 dahili sistemlerini \u015fifreleyen bir siber sald\u0131r\u0131ya maruz kald\u0131\u011f\u0131n\u0131 do\u011frulad\u0131. Bu a\u00e7\u0131klaman\u0131n yay\u0131nland\u0131\u011f\u0131 s\u0131rada elimizde olan bilgiler, sald\u0131rganlar\u0131n WastedLocker fidye yaz\u0131l\u0131m\u0131n\u0131 kulland\u0131\u011f\u0131n\u0131 g\u00f6steriyor. Uzmanlar\u0131m\u0131z k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n detayl\u0131 teknik analizini yapt\u0131; i\u015fte ana bulgular:<\/p>\n<h2>WastedLocker fidye yaz\u0131l\u0131m\u0131<\/h2>\n<p>WastedLocker, hedefli fidye yaz\u0131l\u0131mlar\u0131na bir \u00f6rnektir. Bu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar belirli \u015firketleri hedef almak i\u00e7in kullan\u0131l\u0131r. Fidye mesaj\u0131 kurbana ismiyle hitap eder ve t\u00fcm \u015fifrelenmi\u015f dosyalar\u0131n sonunda <strong>.garminwasted<\/strong> uzant\u0131s\u0131 yer al\u0131r.<\/p>\n<p>Siber su\u00e7lular\u0131n kriptografik \u015femalar\u0131 da ayn\u0131 sonucu g\u00f6steriyor. Dosyalar, fidye yaz\u0131l\u0131m yarat\u0131c\u0131lar\u0131n\u0131n birlikte kulland\u0131\u011f\u0131 AES ve RSA algoritmalar\u0131 kullan\u0131larak \u015fifrelenmi\u015f. Ancak, her bir bula\u015fma i\u00e7in benzersiz olarak \u00fcretmek yerine dosyalar\u0131 \u015fifrelemek i\u00e7in bir RSA anahtar\u0131 kullan\u0131l\u0131r. Ba\u015fka bir deyi\u015fle, \u00e7oklu hedefler i\u00e7in fidye yaz\u0131l\u0131m modifikasyonu kullan\u0131l\u0131rsa tek bir \u015fifre olaca\u011f\u0131ndan veri \u015fifre \u00e7\u00f6zme program\u0131 \u00e7ok ama\u00e7l\u0131 olur.<\/p>\n<p>Buna ek olarak, fidye yaz\u0131l\u0131m\u0131 a\u015fa\u011f\u0131daki \u00f6zellikleri ta\u015f\u0131r:<\/p>\n<ul>\n<li>Veri \u015fifrelemenin \u00f6nceliklendirilmesi. Bu \u00f6zellik, siber su\u00e7lular belirli bir dosya grubunu sizden \u00f6nce \u015fifreleyebilece\u011fi anlam\u0131na gelir. Bu durum, g\u00fcvenlik mekanizmalar\u0131n\u0131n tamamlanmadan \u00f6nce veri \u015fifrelemesini durdurmas\u0131 durumunda verilecek hasar\u0131 artt\u0131r\u0131r.<\/li>\n<li>Uzaktan a\u011f kaynaklar\u0131 \u00fczerinden dosya \u015fifreleme deste\u011fi;<\/li>\n<li>Ayr\u0131cal\u0131kl\u0131 kontrol ve Ayr\u0131cal\u0131klar\u0131n y\u00fckseltilmesi i\u00e7in DLL ele ge\u00e7irmesi kullan\u0131m\u0131<\/li>\n<\/ul>\n<p>Securelist\u2019de yer alan <a href=\"https:\/\/securelist.com\/wastedlocker-technical-analysis\/97944\/\" target=\"_blank\" rel=\"noopener\">WastedLocker: technical analysis<\/a> yaz\u0131s\u0131nda bu fidye yaz\u0131l\u0131m program\u0131n\u0131n detayl\u0131 analizini bulabilirsiniz.<\/p>\n<h2>Peki Garmin ne durumda?<\/h2>\n<p>\u015eirketin g\u00fcncelledi\u011fi a\u00e7\u0131klamaya g\u00f6re, veri senkronizasyonu yava\u015f ve baz\u0131 durumlarda da h\u00e2l\u00e2 s\u0131n\u0131rl\u0131 olsa bile hizmetler tekrar \u00e7al\u0131\u015f\u0131r durumdad\u0131r. Bu anla\u015f\u0131labilir, \u00e7\u00fcnk\u00fc birka\u00e7 g\u00fcn boyunca bulut hizmetleriyle senkronize olamayan cihazlar \u015firket sunucular\u0131 ile tek seferde ileti\u015fim kurdu\u011fundan sunucunun y\u00fck\u00fc artar.<\/p>\n<p>Garmin, olay s\u0131ras\u0131nda yetkisiz ki\u015filerin kullan\u0131c\u0131 verilerine eri\u015fim sa\u011flad\u0131\u011f\u0131na dair herhangi bir kan\u0131t bulunmad\u0131\u011f\u0131n\u0131 belirtti.<\/p>\n<h2>Bu t\u00fcr sald\u0131r\u0131lara kar\u015f\u0131 nas\u0131l korunulur?<\/h2>\n<p>\u015eirketlere y\u00f6nelik hedefli fidye yaz\u0131l\u0131m sald\u0131r\u0131lar\u0131 hep vard\u0131 ve var olmaya devam edecek. Bununla birlikte bu sald\u0131r\u0131lara kar\u015f\u0131 korunmak i\u00e7in tavsiyelerimiz olduk\u00e7a basit:<\/p>\n<ul>\n<li>\u00d6zellikle i\u015fletim sistemleri olmak \u00fczere yaz\u0131l\u0131mlar\u0131n\u0131z daima g\u00fcncel tutun. \u00c7o\u011fu Truva at\u0131 zaten bilinen a\u00e7\u0131klar\u0131 kullan\u0131yor.<\/li>\n<li>\u015eirket sistemlerine genel eri\u015fimi engellemek i\u00e7in RDP kullan\u0131n (veya gerekli olmas\u0131 durumunda VPN kullan\u0131n);<\/li>\n<li>\u00c7al\u0131\u015fanlar\u0131 siber g\u00fcvenli\u011fin temelleri konusunda e\u011fitin. \u00c7o\u011funlukla, \u00e7al\u0131\u015fanlar \u00fczerinde uygulanan sosyal m\u00fchendislik, fidye yaz\u0131l\u0131m\u0131 Truva atlar\u0131n\u0131n kurumsal a\u011flara s\u0131zmas\u0131na neden olur;<\/li>\n<li>Geli\u015fmi\u015f fidye yaz\u0131l\u0131m\u0131 kar\u015f\u0131t\u0131 teknojileri olan son teknoloji g\u00fcvenlik \u00e7\u00f6z\u00fcmleri kullan\u0131n. <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">\u00dcr\u00fcnlerimiz<\/a> WastedLocker fidye yaz\u0131l\u0131m\u0131n\u0131 tespit eder ve bunlar\u0131n s\u0131zmas\u0131n\u0131 engeller.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial-leadgen\">\n","protected":false},"excerpt":{"rendered":"<p>Garmin \u015firketine yap\u0131lan fidye yaz\u0131l\u0131m sald\u0131r\u0131s\u0131n\u0131n ba\u015f \u015f\u00fcphelisi hakk\u0131nda uzmanlar\u0131m\u0131z detayl\u0131 teknik bir rapor haz\u0131rlad\u0131.<\/p>\n","protected":false},"author":2706,"featured_media":8650,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[2022,820],"class_list":{"0":"post-8649","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-fidye-yazilim","10":"tag-tehdit"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/wastedlocker-garmin-incident\/8649\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/wastedlocker-garmin-incident\/21644\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/wastedlocker-garmin-incident\/17107\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/wastedlocker-garmin-incident\/8467\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/wastedlocker-garmin-incident\/22971\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/wastedlocker-garmin-incident\/21158\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/wastedlocker-garmin-incident\/19791\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/wastedlocker-garmin-incident\/23590\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/wastedlocker-garmin-incident\/22464\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/wastedlocker-garmin-incident\/28840\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/wastedlocker-garmin-incident\/36626\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/wastedlocker-garmin-incident\/15400\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/wastedlocker-garmin-incident\/15808\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/wastedlocker-garmin-incident\/13743\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/wastedlocker-garmin-incident\/24829\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/wastedlocker-garmin-incident\/11780\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/wastedlocker-garmin-incident\/28927\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/wastedlocker-garmin-incident\/25760\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/wastedlocker-garmin-incident\/22688\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/wastedlocker-garmin-incident\/27934\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/wastedlocker-garmin-incident\/27764\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilim\/","name":"fidye yaz\u0131l\u0131m"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8649","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2706"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=8649"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8649\/revisions"}],"predecessor-version":[{"id":8651,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8649\/revisions\/8651"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/8650"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=8649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=8649"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=8649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}