{"id":9398,"date":"2021-03-10T12:54:35","date_gmt":"2021-03-10T09:54:35","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=9398"},"modified":"2021-03-10T12:54:35","modified_gmt":"2021-03-10T09:54:35","slug":"rtm-quoter-campaign","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/rtm-quoter-campaign\/9398\/","title":{"rendered":"Fidye yaz\u0131l\u0131mlar\u0131 ve sald\u0131r\u0131lar"},"content":{"rendered":"<p>Uzmanlar\u0131m\u0131z, olduk\u00e7a geni\u015f bir dizi ara\u00e7 i\u00e7eren yeni bir k\u00f6t\u00fc ama\u00e7l\u0131 sald\u0131r\u0131 tespit ettiler. Ara\u00e7lar aras\u0131nda bir bankac\u0131l\u0131k Truva At\u0131, Quoter adl\u0131 fidye yaz\u0131l\u0131m\u0131 (sistemlerimizin daha \u00f6nce kar\u015f\u0131la\u015fmad\u0131\u011f\u0131 yeni bir yaz\u0131l\u0131m) ve yasal uzaktan eri\u015fim programlar\u0131 (LiteManager ve RMS, muhtemelen benzerleri de dahil) bulunuyor. Sald\u0131r\u0131lar\u0131n sorumlusu olan siber su\u00e7lular, RTM grubuyla ili\u015fkilendiriliyor.<\/p>\n<h2>Sald\u0131rganlar nas\u0131l \u00e7al\u0131\u015f\u0131yor?<\/h2>\n<p>Sald\u0131r\u0131 standart kimlik av\u0131yla ba\u015fl\u0131yor: Sald\u0131rganlar bir belge gibi g\u00f6r\u00fcnen ama asl\u0131nda Trojan-Banker.Win32.RTM isimli Turva at\u0131n\u0131 i\u00e7eren bir eki, e-posta ile kurbana g\u00f6nderiyor. Al\u0131c\u0131lar\u0131n eki a\u00e7mas\u0131n\u0131 sa\u011flamak i\u00e7in kurumsal al\u0131c\u0131lar\u0131 hedefleyen dikkat \u00e7ekici e-posta ba\u015fl\u0131klar\u0131 kullan\u0131yorlar. Uzmanlar\u0131m\u0131z a\u015fa\u011f\u0131daki \u00f6rneklerle kar\u015f\u0131la\u015ft\u0131:<\/p>\n<ul>\n<li>Mahkeme celbi,<\/li>\n<li>\u0130ade talebi,<\/li>\n<li>Kapan\u0131\u015f belgeleri<\/li>\n<li>Ge\u00e7en aya ait belgelerin kopyalar\u0131<\/li>\n<\/ul>\n<p><a href=\"https:\/\/securelist.com\/it-threat-evolution-q3-2018-statistics\/88689\/\" target=\"_blank\" rel=\"noopener\">Truva at\u0131n\u0131n kendisi yeni de\u011fil, 2018\u2019den bu yana<\/a> bilinen en yayg\u0131n 10 k\u00f6t\u00fc ama\u00e7l\u0131 bankac\u0131l\u0131k yaz\u0131l\u0131m ailesi raporlar\u0131m\u0131zda s\u00fcrekli olarak yer al\u0131yor. Al\u0131c\u0131 ekteki dosyaya t\u0131klay\u0131p k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 y\u00fcklerse, bilgisayara k\u00f6t\u00fc ama\u00e7l\u0131 ek yaz\u0131l\u0131mlar da inmeye ba\u015fl\u0131yor.<\/p>\n<p>Bu ad\u0131mdan sonra siber su\u00e7lular, muhasebe \u00e7al\u0131\u015fanlar\u0131n\u0131n bilgisayarlar\u0131n\u0131 bulmak i\u00e7in a\u011fda arama yap\u0131yor ve kendi haz\u0131rlad\u0131klar\u0131 bankac\u0131l\u0131k bilgilerini do\u011fru olanlarla de\u011fi\u015ftirerek uzaktan bankac\u0131l\u0131k sistemini manip\u00fcle etmeye \u00e7al\u0131\u015f\u0131yorlar. Bu davran\u0131\u015f, RTM i\u00e7in yeni de\u011fil. \u0130lgin\u00e7 bir \u015fekilde, \u00e7ete, bir yedekleme plan\u0131 olarak Quoter\u2019\u0131 (Trojan-Ransom.Win32.Quoter olarak alg\u0131lanan ba\u015fka bir Truva at\u0131) yay\u0131nlad\u0131. Bu yaz\u0131l\u0131m\u0131 bu isimle anmam\u0131z\u0131n sebebi, \u015fifreledi\u011fi dosyalar\u0131n koduna filmlerden al\u0131nan baz\u0131 c\u00fcmleleri eklemesi.<\/p>\n<p>Modern fidye yaz\u0131l\u0131m\u0131 operat\u00f6rlerinin genellikle yapt\u0131\u011f\u0131 gibi, RTM de bilgileri \u00e7ekiyor ve daha sonra fidyenin \u00f6denmesi gecikirse bunlar\u0131 yay\u0131nlamakla tehdit ediyorlar.<\/p>\n<h2>Hedefler<\/h2>\n<p>Uzmanlar\u0131m\u0131z \u015fimdiye dek, hepsi Rusya\u2019da bulunan, ula\u015f\u0131m veya finansal hizmetler alanlar\u0131nda faaliyet g\u00f6steren yakla\u015f\u0131k bir d\u00fczine kurban oldu\u011funu tespit etti. Ancak, kurban say\u0131s\u0131n\u0131n daha da artmas\u0131 ka\u00e7\u0131n\u0131lmaz g\u00f6z\u00fck\u00fcyor. Sald\u0131r\u0131n\u0131n ya\u015fand\u0131\u011f\u0131, vir\u00fcs\u00fcn ilk bula\u015fma tarihi ile fidye yaz\u0131l\u0131m\u0131n\u0131n etkinle\u015ftirilmesi aras\u0131ndaki s\u00fcre birka\u00e7 ay olabiliyor. Bu s\u00fcre zarf\u0131nda sald\u0131rganlar, kurbanlar\u0131n a\u011flar\u0131n\u0131 ke\u015ffederek uzaktan bankac\u0131l\u0131k sistemlerine eri\u015fime sahip olan bilgisayarlar\u0131 ar\u0131yorlar.<\/p>\n<p>Di\u011fer b\u00f6lgelerde faaliyet g\u00f6steren \u015firketlere y\u00f6nelik benzer sald\u0131r\u0131lar da olabilir (Quoter \u0130ngilizce al\u0131nt\u0131lar da kullan\u0131yor, bu kesin bir g\u00f6sterge olmasa da, \u00e7etenin global kurumlar\u0131 hedefledi\u011fi \u015feklinde yorumlanabilir). Zararl\u0131 kod ve IOCs snippet\u2019leri de dahil olmak \u00fczere, bu olaya dair biraz daha teknik bir bak\u0131\u015f i\u00e7in Securelist <a href=\"https:\/\/securelist.ru\/new-targeted-attacks-rtm\/100720\/\" target=\"_blank\" rel=\"noopener\">yay\u0131n\u0131n\u0131<\/a> inceleyebilirsiniz.<\/p>\n<h2>Bu t\u00fcr siber tehditlere kar\u015f\u0131 koruma<\/h2>\n<p>Her zamanki gibi etkili koruma, \u00e7al\u0131\u015fanlar\u0131n e\u011fitimiyle ba\u015fl\u0131yor: Bu t\u00fcr sald\u0131r\u0131lar\u0131n \u00e7o\u011fu kimlik av\u0131 e-postalar\u0131yla tetiklenir. Tehlikenin ve standart davetsiz misafir numaralar\u0131n\u0131n fark\u0131nda olan i\u015f arkada\u015flar\u0131n\u0131z\u0131n bu t\u00fcr tuzaklara d\u00fc\u015fmesi ve \u015firketinizi tehlikeye atmas\u0131 olas\u0131l\u0131\u011f\u0131 daha d\u00fc\u015f\u00fckt\u00fcr. Bu konuya odaklanan \u00f6zel bir <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">online platformu<\/a> kullanarak uzaktan bir e\u011fitim organize edebilirsiniz.<\/p>\n<p>Kurumsal a\u011flar \u00fczerinden yay\u0131lan davetsiz misafirlerin t\u00fcm hareketlerini zaman\u0131nda tespit etmek ve me\u015fru ara\u00e7lar\u0131n k\u00f6t\u00fc ama\u00e7lar i\u00e7in kullan\u0131lmas\u0131n\u0131 engellemek \u00fczere <a href=\"https:\/\/www.kaspersky.com.tr\/enterprise-security\/threat-management-defense-solution?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____tmd___\" target=\"_blank\" rel=\"noopener\">karma\u015f\u0131k tehditleri belirleyecek geli\u015fmi\u015f ara\u00e7lar<\/a> devreye al\u0131n.<\/p>\n<p>Ayr\u0131ca t\u00fcm \u00e7al\u0131\u015fan bilgisayarlar\u0131n\u0131n, \u00f6zellikle bankac\u0131l\u0131k sistemleriyle \u00e7al\u0131\u015fanlar\u0131n, hem bilinen hem de tamamen yeni t\u00fcm tehditleri tespit edebilecek g\u00fcvenlik \u00e7\u00f6z\u00fcmlerine sahip olmalar\u0131 gerekir.<\/p>\n<p><a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">\u00dcr\u00fcnlerimiz<\/a> hem RTM bankac\u0131l\u0131k Truva at\u0131n\u0131, hem de Quoter fidye yaz\u0131l\u0131m\u0131n\u0131 alg\u0131lar.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-ransomware\">\n","protected":false},"excerpt":{"rendered":"<p>RTM grubu kurbanlara fidye yaz\u0131l\u0131m\u0131, bankac\u0131l\u0131k Truva At\u0131 ve uzaktan eri\u015fim ara\u00e7lar\u0131yla sald\u0131r\u0131yor.<\/p>\n","protected":false},"author":2581,"featured_media":9399,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[2089,591],"class_list":{"0":"post-9398","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-bankacilik-truva-atlari","10":"tag-fidye-yazilimi"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/rtm-quoter-campaign\/9398\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/rtm-quoter-campaign\/21225\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/rtm-quoter-campaign\/24812\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/rtm-quoter-campaign\/24068\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/rtm-quoter-campaign\/30195\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/rtm-quoter-campaign\/38931\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/rtm-quoter-campaign\/16490\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/rtm-quoter-campaign\/17094\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/rtm-quoter-campaign\/14540\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/rtm-quoter-campaign\/26306\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/rtm-quoter-campaign\/30157\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/rtm-quoter-campaign\/26758\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/rtm-quoter-campaign\/23610\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimi\/","name":"Fidye Yaz\u0131l\u0131m\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=9398"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9398\/revisions"}],"predecessor-version":[{"id":9400,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9398\/revisions\/9400"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/9399"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=9398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=9398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=9398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}