{"id":9291,"date":"2021-02-05T15:28:35","date_gmt":"2021-02-05T12:28:35","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=9291"},"modified":"2021-02-05T15:28:35","modified_gmt":"2021-02-05T12:28:35","slug":"fonix-decryptor","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/fonix-decryptor\/9291\/","title":{"rendered":"Fonix fidye yaz\u0131l\u0131m\u0131na y\u00f6nelik \u00fccretsiz bir \u015fifre \u00e7\u00f6z\u00fcc\u00fc edinin"},"content":{"rendered":"<p>Fonix fidye yaz\u0131l\u0131m\u0131 grubu aniden faaliyetlerinin sona erdi\u011fini <a href=\"https:\/\/twitter.com\/fnx67482837\/status\/1355249547824521216\" target=\"_blank\" rel=\"noopener nofollow\">duyurup<\/a> \u015fifrelenmi\u015f dosyalar\u0131n kodunu \u00e7\u00f6zmek i\u00e7in <a href=\"https:\/\/twitter.com\/fnx67482837\/status\/1355255873581539333?s=20\" target=\"_blank\" rel=\"noopener nofollow\">bir ana kod yay\u0131nlad\u0131\u011f\u0131nda<\/a>, uzmanlar\u0131m\u0131z i\u015flemi otomatikle\u015ftirmek i\u00e7in Rakhni Decryptor arac\u0131n\u0131 hemen g\u00fcncelledi. Arac\u0131 <a href=\"https:\/\/noransom.kaspersky.com\/\" target=\"_blank\" rel=\"noopener\">buradan<\/a> indirebilirsiniz.<\/p>\n<p>Fonix \u00f6rne\u011fi, fidyeyi \u00f6demeyi planlamasan\u0131z bile (ak\u0131ll\u0131ca bir se\u00e7im) neden \u015fifrelenmi\u015f verilere ba\u011fl\u0131 kalman\u0131z gerekti\u011fini bir kez daha g\u00f6stermektedir. Siber su\u00e7lular\u0131n hepsi pi\u015fmanl\u0131k duyup kodlar\u0131n\u0131 yay\u0131nlamaz (veya yakalan\u0131r ve sunucular\u0131na el konulur). Ancak kodlar bir noktada kullan\u0131labilir hale gelirse, bunlar\u0131 bilgilerinize yeniden eri\u015fmek i\u00e7in kullanabilirsiniz \u2014 tabi bu sadece, kodu saklam\u0131\u015f olursan\u0131z m\u00fcmk\u00fcn.<\/p>\n<h2>Fonix neden tehlikeliydi?<\/h2>\n<p>Fonix fidye yaz\u0131l\u0131m\u0131, Xinof olarak da biliniyordu. Siber su\u00e7lular bahsi ge\u00e7en iki ad\u0131 da kulland\u0131lar. \u015eifrelenmi\u015f dosyalar, .xinof veya .fonix uzant\u0131s\u0131yla yeniden adland\u0131r\u0131ld\u0131. Analistler, fidye yaz\u0131l\u0131m\u0131n\u0131 olduk\u00e7a agresif olarak nitelendirdi: K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, hedef sistemlerdeki dosyalar\u0131 \u015fifrelemenin yan\u0131 s\u0131ra, onu kald\u0131rma \u00e7abalar\u0131n\u0131 engellemek i\u00e7in de i\u015fletim sistemine m\u00fcdahale etti. Ayr\u0131ca, hedef bilgisayardaki hemen hemen t\u00fcm dosyalar\u0131 \u015fifreleyerek yaln\u0131zca i\u015fletim sistemi i\u00e7in kritik \u00f6nemi olanlar\u0131 b\u0131rakt\u0131.<\/p>\n<p>K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m yazarlar\u0131, Fonix\u2019i hizmet olarak fidye yaz\u0131l\u0131m\u0131 (<a href=\"https:\/\/encyclopedia.kaspersky.ru\/glossary\/ransomware-as-a-service-raas\/\" target=\"_blank\" rel=\"noopener\">RaaS<\/a>) modeliyle kiralayarak istemcilerin ger\u00e7ek sald\u0131r\u0131lar\u0131 ger\u00e7ekle\u015ftirmesini sa\u011flad\u0131. 2020 yaz\u0131ndan itibaren, hacker forumlar\u0131nda k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m reklamlar\u0131nda yo\u011fun bir art\u0131\u015f vard\u0131. Ba\u015flang\u0131\u00e7ta operat\u00f6rlere, arac\u0131 \u00fccretsiz kullanma hakk\u0131 verildi ve Fonix\u2019e rekabet avantaj\u0131 sa\u011flad\u0131. Yazarlar toplanan herhangi bir fidyenin yaln\u0131zca belirli bir y\u00fczdesini ald\u0131.<\/p>\n<p>Sonu\u00e7 olarak, ba\u011flant\u0131s\u0131 olmayan \u00e7e\u015fitli kampanyalar, genellikle spam postalar yoluyla k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n yay\u0131lmas\u0131na yard\u0131mc\u0131 oldu. Bu nedenle Fonix hem bireysel kullan\u0131c\u0131lar\u0131 hem de \u015firketleri etkiledi. Neyse ki, fidye yaz\u0131l\u0131m\u0131 \u00e7ok yay\u0131lmad\u0131, bu nedenle kurban say\u0131s\u0131 \u00e7ok de\u011fildi.<\/p>\n<h2>Siber su\u00e7un i\u00e7inde bir ba\u015fka siber su\u00e7<\/h2>\n<p>Fonix grubu yapt\u0131\u011f\u0131 a\u00e7\u0131klamada, t\u00fcm \u00fcyelerin operasyonu sonland\u0131rma karar\u0131na kat\u0131lmad\u0131\u011f\u0131n\u0131 belirtti. \u00d6rne\u011fin Fonix Telegram kanal\u0131n\u0131n y\u00f6neticisi, fidye yaz\u0131l\u0131m\u0131 kaynak kodunu ve di\u011fer verileri satmaya \u00e7al\u0131\u015f\u0131yor. Ancak en az\u0131ndan Fonix grubunun Twitter hesab\u0131na g\u00f6re, bu kod ger\u00e7ek de\u011fil. Yani, asl\u0131nda k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m al\u0131c\u0131lar\u0131n\u0131 hedefleyen bir aldatmaca. Buradaki tek potansiyel kurbanlar di\u011fer siber su\u00e7lular olsa da, doland\u0131r\u0131c\u0131l\u0131k hala doland\u0131r\u0131c\u0131l\u0131kt\u0131r.<\/p>\n<h2>Motivasyon<\/h2>\n<p>FonixCrypter projesinin y\u00f6neticisi, hi\u00e7bir zaman su\u00e7 faaliyetlerinde bulunma niyetinde olmad\u0131\u011f\u0131n\u0131, ancak ekonomik krizin fidye yaz\u0131l\u0131m\u0131n\u0131 olu\u015fturmas\u0131na neden oldu\u011funu s\u00f6yledi. Daha sonra vicdan azab\u0131yla kaynak kodunu silip ma\u011fdurlardan \u00f6z\u00fcr diledi ve ana kodu yay\u0131nlad\u0131. \u0130leride k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m analizi konusundaki bilgilerini daha iyi ama\u00e7larla kullanmay\u0131 planlad\u0131\u011f\u0131n\u0131 ve bu giri\u015fiminde meslekta\u015flar\u0131n\u0131n deste\u011fini bekledi\u011fini s\u00f6yledi.<\/p>\n<h2>Fidye yaz\u0131l\u0131mlara kar\u015f\u0131 koruma<\/h2>\n<p>Fonix art\u0131k bir sorun te\u015fkil etmiyor. Ancak di\u011fer fidye yaz\u0131l\u0131m\u0131 t\u00fcrleri, 2021\u2019de her zamankinden daha aktif. G\u00fcvende kalma konusundaki tavsiyemiz hala ayn\u0131:<\/p>\n<ul>\n<li>Ek dosya i\u00e7eren e-postalara kar\u015f\u0131 tetikte olun;<\/li>\n<li>Do\u011frulanmam\u0131\u015f kaynaklardan gelen dosyalar\u0131 a\u00e7may\u0131n;<\/li>\n<li>\u0130nternet eri\u015fimi olan t\u00fcm ev ve i\u015f cihazlar\u0131nda g\u00fcvenlik \u00e7\u00f6z\u00fcmlerini kullan\u0131n;<\/li>\n<li>T\u00fcm kritik verilerin yedek kopyalar\u0131n\u0131 al\u0131n ve bunlar\u0131 a\u011f\u0131n\u0131za ba\u011fl\u0131 olmayan cihazlarda saklay\u0131n.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.kaspersky.com.tr\/internet-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kismd___\" target=\"_blank\" rel=\"noopener\">Ev kullan\u0131c\u0131lar\u0131<\/a> ve <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">i\u015fletmeler<\/a> i\u00e7in \u00fcr\u00fcnlerimiz, Fonix\u2019i ve di\u011fer fidye yaz\u0131l\u0131mlar\u0131n\u0131 proaktif bir yakla\u015f\u0131mla alg\u0131lar. Ayr\u0131ca, dosya taray\u0131c\u0131lar\u0131m\u0131z Fonix\u2019e \u00e7al\u0131\u015fma \u015fans\u0131 vermeden onu tan\u0131mlar.<\/p>\n<p>Yinelemek i\u00e7in: Fonix ransomware kurban\u0131 olursan\u0131z, <a href=\"https:\/\/noransom.kaspersky.com\/tr\/\" target=\"_blank\" rel=\"noopener\">NoRansom.kaspersky.com<\/a> sitesinden indirebilece\u011finiz RakhniDecryptor 1.27.0.0 arac\u0131m\u0131z\u0131 kullanarak verilerinizi kurtarabilirsiniz.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-ransomware\">\n","protected":false},"excerpt":{"rendered":"<p>Fonix fidye yaz\u0131l\u0131m\u0131n\u0131n geli\u015ftiricileri k\u00f6t\u00fc ama\u00e7l\u0131 y\u00f6ntemlerini b\u0131rak\u0131p ana kodu yay\u0131nlad\u0131\u011f\u0131nda, biz onu kullanarak bir \u015fifre \u00e7\u00f6z\u00fcc\u00fc geli\u015ftirdik. <\/p>\n","protected":false},"author":2581,"featured_media":9292,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194,1351],"tags":[591,1763,2362],"class_list":{"0":"post-9291","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"category-threats","10":"tag-fidye-yazilimi","11":"tag-fidye-yazilimlari","12":"tag-para-sizdirma"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/fonix-decryptor\/9291\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/fonix-decryptor\/22485\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/fonix-decryptor\/17976\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/fonix-decryptor\/8919\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/fonix-decryptor\/24190\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/fonix-decryptor\/22268\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/fonix-decryptor\/20979\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/fonix-decryptor\/24648\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/fonix-decryptor\/23864\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/fonix-decryptor\/30071\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/fonix-decryptor\/38646\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/fonix-decryptor\/16363\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/fonix-decryptor\/14453\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/fonix-decryptor\/26185\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/fonix-decryptor\/29982\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/fonix-decryptor\/26671\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/fonix-decryptor\/23522\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/fonix-decryptor\/28865\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/fonix-decryptor\/28671\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimlari\/","name":"fidye yaz\u0131l\u0131mlar\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=9291"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9291\/revisions"}],"predecessor-version":[{"id":9293,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9291\/revisions\/9293"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/9292"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=9291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=9291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=9291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}