{"id":17781,"date":"2023-11-07T04:00:00","date_gmt":"2023-11-07T01:00:00","guid":{"rendered":"https:\/\/rockvell.com\/?p=17781"},"modified":"2023-11-07T08:39:13","modified_gmt":"2023-11-07T05:39:13","slug":"stripedfly","status":"publish","type":"post","link":"https:\/\/rockvell.com\/?p=17781","title":{"rendered":"\u201cStripedFly\u201d"},"content":{"rendered":"\n<p class=\"has-medium-font-size\"><strong>\u201cStripedFly\u201d: m\u00fcr\u0259kk\u0259b koda v\u0259 casusluq imkanlar\u0131na malik m\u0259d\u0259n\u00e7i-qurd<\/strong><\/p>\n\n\n\n<p>\u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri \u201cStripedFly\u201d ad\u0131 veril\u0259n \u0259vv\u0259ll\u0259r m\u0259lum olmayan v\u0259 son d\u0259r\u0259c\u0259 m\u00fcr\u0259kk\u0259b z\u0259r\u0259rli proqram a\u015fkar edibl\u0259r. 2017-ci ild\u0259n b\u0259ri d\u00fcnya \u00fczr\u0259 bir milyondan \u00e7ox istifad\u0259\u00e7i onun qurban\u0131na \u00e7evrilib v\u0259 indi daha az aktiv olsa da, h\u00fccumlara davam edir. Uzun m\u00fcdd\u0259tdir onun adi bir kriptom\u0259d\u0259n\u00e7i oldu\u011fu g\u00fcman edils\u0259 d\u0259 sonradan \u00e7oxfunksiyal\u0131, funksional \u00e7\u0259r\u00e7iv\u0259y\u0259 malik m\u00fcr\u0259kk\u0259b bir proqram oldu\u011fu m\u0259lum olub. \u201cKaspersky\u201d t\u0259dqiqat\u00e7\u0131lar\u0131 bu bar\u0259d\u0259 \u201c<a href=\"https:\/\/thesascon.com\/\">Security Analyst Summit<\/a>\u201d t\u0259dbirind\u0259 dan\u0131\u015f\u0131blar.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2.png\" alt=\"\" class=\"wp-image-8743\" width=\"512\" height=\"341\" srcset=\"https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2.png 1024w, https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2-300x200.png 300w, https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2-768x512.png 768w, https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2-360x240.png 360w\" sizes=\"(max-width: 512px) 100vw, 512px\" \/><\/figure><\/div>\n\n\n<p>2022-ci ild\u0259 \u201cKaspersky\u201dnin Qlobal T\u0259dqiqat v\u0259 Analiz Qrupunun (GReAT) m\u00fct\u0259x\u0259ssisl\u0259ri bu z\u0259r\u0259rli proqram\u0131n i\u015ftirak etdiyi iki yeni insident a\u015fkar edibl\u0259r. Onlar \u201cWindows\u201dda \u201cwininit.exe\u201d sistem prosesi il\u0259 \u0259laq\u0259li olub. Prosesin t\u0259rkib hiss\u0259si kimi \u0259vv\u0259ll\u0259r \u201cEquation\u201d z\u0259r\u0259rli proqram\u0131nda istifad\u0259 edilmi\u015f kod ard\u0131c\u0131ll\u0131\u011f\u0131 a\u015fkar edilib. Tap\u0131lan n\u00fcmun\u0259l\u0259rin f\u0259aliyy\u0259ti \u0259n az\u0131 2017-ci ild\u0259n aktual olsa da, \u0259vv\u0259ll\u0259r adi kriptominatorla s\u0259hv sal\u0131nd\u0131\u011f\u0131 \u00fc\u00e7\u00fcn onun ilkin analiz m\u0259rh\u0259l\u0259sind\u0259 d\u0259rhal h\u0259rt\u0259r\u0259fli \u00f6yr\u0259nilm\u0259si ba\u015f tutmay\u0131b. Geni\u015f ara\u015fd\u0131rmadan sonra m\u0259lum olub ki, kriptom\u0259d\u0259n\u00e7i \u00e7oxlu plaginl\u0259r\u0259 malik m\u00fcr\u0259kk\u0259b multiplatformal\u0131 strukturun yaln\u0131z bir hiss\u0259sidir.<\/p>\n\n\n\n<p>A\u015fkar edilmi\u015f z\u0259r\u0259rli proqram\u0131n bir \u00e7ox modullar\u0131 t\u0259cav\u00fczkarlara ondan APT h\u00fccumlar\u0131n\u0131n bir hiss\u0259si, h\u0259m\u00e7inin kriptom\u0259d\u0259n\u00e7i v\u0259 ya h\u0259tta fidy\u0259 proqram\u0131 kimi istifad\u0259 etm\u0259y\u0259 imkan verir. M\u00fcvafiq olaraq, t\u0259cav\u00fczkarlar\u0131n m\u00fcmk\u00fcn motivl\u0259rinin siyah\u0131s\u0131 maddi qazancdan casuslu\u011fa q\u0259d\u0259r \u0259h\u0259miyy\u0259tli d\u0259r\u0259c\u0259d\u0259 geni\u015fl\u0259nir. Maraql\u0131d\u0131r ki, z\u0259r\u0259rli modul vasit\u0259sil\u0259 \u00e7\u0131xar\u0131lm\u0131\u015f \u201cMonero\u201d kriptovalyutas\u0131n\u0131n d\u0259y\u0259ri 2018-ci il yanvar\u0131n 9-da \u0259n y\u00fcks\u0259k h\u0259dd\u0259, y\u0259ni 542,33 dollara \u00e7at\u0131b. M\u00fcqayis\u0259 \u00fc\u00e7\u00fcn qeyd ed\u0259k ki, 2017-ci ild\u0259 onun qiym\u0259ti t\u0259xmin\u0259n 10 dollar olub. Haz\u0131rda bu kriptovalyutan\u0131n d\u0259y\u0259ri 150 dollard\u0131r. \u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri vur\u011fulay\u0131rlar ki, m\u0259d\u0259n\u00e7ilik \u00fc\u00e7\u00fcn n\u0259z\u0259rd\u0259 tutulan modul z\u0259r\u0259rli proqramlar\u0131n uzun m\u00fcdd\u0259t \u0259rzind\u0259 tam a\u015fkara \u00e7\u0131xar\u0131la bilm\u0259m\u0259sins\u0259 s\u0259b\u0259b olan \u0259sas amildir.<\/p>\n\n\n\n<p>T\u0259cav\u00fczkarlar\u0131n qurbanlara qar\u015f\u0131 gizli casusluq etm\u0259k \u00fc\u00e7\u00fcn \u00e7oxlu imkanlar\u0131 var. Z\u0259r\u0259rli proqram h\u0259r iki saatdan bir hesab m\u0259lumatlar\u0131n\u0131 toplay\u0131r. M\u0259lumatlar aras\u0131nda vebsayta daxil olmaq v\u0259 ya Wi-Fi-ya qo\u015fulmaq \u00fc\u00e7\u00fcn login v\u0259 \u015fifr\u0259l\u0259r v\u0259 ya \u015f\u0259xsin ad\u0131, \u00fcnvan\u0131, telefon n\u00f6mr\u0259si, i\u015f yeri v\u0259 v\u0259zif\u0259si daxil olmaqla \u015f\u0259xsi m\u0259lumatlar yer al\u0131r. Bundan \u0259lav\u0259, z\u0259r\u0259rli proqram qurban\u0131n cihaz\u0131ndan gizlin \u015f\u0259kild\u0259 ekran g\u00f6r\u00fcnt\u00fcs\u00fc \u00e7\u0259k\u0259, cihaza tam n\u0259zar\u0259t ed\u0259 v\u0259 h\u0259tta mikrofondan s\u0259s m\u0259lumatlar\u0131n\u0131 yaza bil\u0259r.<\/p>\n\n\n\n<p>Komp\u00fcterin yoluxmas\u0131n\u0131n ilkin m\u0259nb\u0259yi uzun m\u00fcdd\u0259t nam\u0259lum olaraq qal\u0131b. \u201cKaspersky\u201d t\u0259r\u0259find\u0259n apar\u0131lan sonrak\u0131 ara\u015fd\u0131rmalar t\u0259cav\u00fczkarlar\u0131n bu m\u0259qs\u0259dl\u0259 \u00f6z \u201cEternalBlue \u201cSMBv1\u201d istismar\u0131ndan istifad\u0259 etdiyini m\u00fc\u0259yy\u0259n edib. \u201cEternalBlue\u201d z\u0259ifliyi h\u0259l\u0259 2017-ci ild\u0259 a\u015fkar edilib, bundan sonra \u201cMicrosoft\u201d d\u00fcz\u0259li\u015f yama\u011f\u0131 (MS17-010) burax\u0131b. Bununla bel\u0259, t\u0259hl\u00fck\u0259 h\u0259l\u0259 d\u0259 aktuald\u0131r, \u00e7\u00fcnki b\u00fct\u00fcn istifad\u0259\u00e7il\u0259r sistemi yenil\u0259mir.<\/p>\n\n\n\n<p>Kampaniyan\u0131n texniki t\u0259hlili zaman\u0131 \u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri \u201cEquation\u201d z\u0259r\u0259rli proqram\u0131 il\u0259 ox\u015farl\u0131qlar a\u015fkar edibl\u0259r. Buraya texniki g\u00f6st\u0259ricil\u0259r, o c\u00fcml\u0259d\u0259n imzalar, proqramla\u015fd\u0131rma \u00fcslubu v\u0259 \u201cStraitBizzare\u201d (SBZ) z\u0259r\u0259rli proqram\u0131nda istifad\u0259 edil\u0259nl\u0259r\u0259 ox\u015far \u00fcsullar daxildir. Endirm\u0259 say\u011fac\u0131 m\u0259lumatlar\u0131na \u0259sas\u0259n \u201cStripedFly\u201d\u0131n d\u00fcnya \u00fczr\u0259 bir milyondan \u00e7ox istifad\u0259\u00e7ini h\u0259d\u0259f\u0259 ald\u0131\u011f\u0131 m\u00fc\u0259yy\u0259n edilib.<\/p>\n\n\n\n<p>\u201cBu \u00e7\u0259r\u00e7iv\u0259ni yaratmaq \u00fc\u00e7\u00fcn s\u0259rf olunan s\u0259yl\u0259r h\u0259qiq\u0259t\u0259n t\u0259\u0259cc\u00fcbl\u0259ndirir. Kibert\u0259hl\u00fck\u0259sizlik m\u00fct\u0259x\u0259ssisl\u0259ri \u00fc\u00e7\u00fcn \u0259sas problem t\u0259cav\u00fczkarlar\u0131n daim d\u0259yi\u015f\u0259n \u015f\u0259rtl\u0259r\u0259 uy\u011funla\u015fmas\u0131d\u0131r. Buna g\u00f6r\u0259 d\u0259, biz t\u0259dqiqat\u00e7\u0131lar \u00fc\u00e7\u00fcn m\u00fcr\u0259kk\u0259b kibert\u0259hl\u00fck\u0259l\u0259ri m\u00fc\u0259yy\u0259n etm\u0259k \u00fc\u00e7\u00fcn g\u00fcc\u00fcm\u00fcz\u00fc bir araya g\u0259tirm\u0259yimiz v\u0259 m\u00fc\u015ft\u0259ril\u0259rin kiberh\u00fccumlardan h\u0259rt\u0259r\u0259fli m\u00fcdafi\u0259ni yaddan \u00e7\u0131xarmamas\u0131 vacibdir\u201d, &#8211; dey\u0259 \u201cKaspersky\u201dnin kibert\u0259hl\u00fck\u0259sizlik \u00fczr\u0259 eksperti Sergey Lojkin qeyd edir.<\/p>\n\n\n\n<p>Kibercinay\u0259tkarlar\u0131n m\u0259qs\u0259dy\u00f6nl\u00fc h\u00fccumlar\u0131ndan qorunmaq \u00fc\u00e7\u00fcn \u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri t\u00f6vsiy\u0259 edirl\u0259r:<\/p>\n\n\n\n<ul>\n<li>bo\u015fluqlar\u0131 vaxt\u0131nda aradan qald\u0131rmaq \u00fc\u00e7\u00fcn \u0259m\u0259liyyat sistemini, t\u0259tbiql\u0259ri v\u0259 antivirus proqramlar\u0131n\u0131 m\u00fct\u0259madi olaraq yenil\u0259yin;<\/li>\n\n\n\n<li>m\u0259xfi m\u0259lumatlar\u0131n\u0131z\u0131 t\u0259qdim etm\u0259yinizi t\u0259l\u0259b ed\u0259n e-po\u00e7t, mesaj v\u0259 ya z\u0259ngl\u0259r\u0259 qar\u015f\u0131 ehtiyatl\u0131 olun; m\u0259lumatlar\u0131n\u0131z\u0131 onlara \u00f6t\u00fcrm\u0259zd\u0259n v\u0259 ya \u015f\u00fcbh\u0259li ke\u00e7idl\u0259r\u0259 klikl\u0259m\u0259zd\u0259n \u0259vv\u0259l g\u00f6nd\u0259r\u0259nl\u0259rin kimliyini yoxlay\u0131n;<\/li>\n\n\n\n<li>T\u0259hl\u00fck\u0259sizlik \u018fm\u0259liyyatlar\u0131 M\u0259rk\u0259zinin (SOC) m\u00fct\u0259x\u0259ssisl\u0259rin\u0259 t\u0259hdidl\u0259r haqq\u0131nda m\u0259lumat bazas\u0131na (TI) giri\u015f t\u0259min edin. M\u0259s\u0259l\u0259n, <a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/threat-intelligence\">Kaspersky Threat Intelligence<\/a> \u015firk\u0259t t\u0259r\u0259find\u0259n 20 ild\u0259n art\u0131q m\u00fcdd\u0259td\u0259 toplanm\u0131\u015f h\u00fccum m\u0259lumatlar\u0131n\u0131 ehtiva edir;<\/li>\n\n\n\n<li>komandan\u0131n kibert\u0259hl\u00fck\u0259sizlik, x\u00fcsusil\u0259 d\u0259 \u0259n son h\u0259d\u0259fli t\u0259hdidl\u0259r haqq\u0131nda bilikl\u0259rini art\u0131r\u0131n. Bu i\u015fd\u0259 \u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri t\u0259r\u0259find\u0259n haz\u0131rlanm\u0131\u015f onlayn t\u0259lim k\u00f6m\u0259y\u0259 \u00e7ata bil\u0259r;<\/li>\n\n\n\n<li><a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/endpoint-detection-response-edr\">Kaspersky Endpoint Detection and Response<\/a> kimi son cihaz s\u0259viyy\u0259sind\u0259 insidentl\u0259rin vaxt\u0131nda a\u015fkarlanmas\u0131 v\u0259 cavabland\u0131r\u0131lmas\u0131n\u0131 t\u0259min ed\u0259n EDR h\u0259ll\u0259rind\u0259n istifad\u0259 edin.<\/li>\n<\/ul>\n\n\n\n<p>&nbsp;\u201cStripedFly\u201d haqq\u0131nda \u201cKaspersky\u201dnin hesabat\u0131ndan \u00f6yr\u0259n\u0259 bil\u0259rsiniz: <a href=\"https:\/\/securelist.com\/stripedfly-perennially-flying-under-the-radar\/110903\/\">https:\/\/securelist.com\/stripedfly-perennially-flying-under-the-radar\/110903\/<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cStripedFly\u201d: m\u00fcr\u0259kk\u0259b koda v\u0259 casusluq imkanlar\u0131na malik m\u0259d\u0259n\u00e7i-qurd \u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri \u201cStripedFly\u201d ad\u0131 veril\u0259n \u0259vv\u0259ll\u0259r m\u0259lum olmayan v\u0259 son d\u0259r\u0259c\u0259 m\u00fcr\u0259kk\u0259b z\u0259r\u0259rli proqram a\u015fkar edibl\u0259r. 2017-ci ild\u0259n b\u0259ri d\u00fcnya \u00fczr\u0259 bir milyondan \u00e7ox istifad\u0259\u00e7i onun qurban\u0131na&#8230;<\/p>\n","protected":false},"author":2,"featured_media":8743,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/17781"}],"collection":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17781"}],"version-history":[{"count":1,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/17781\/revisions"}],"predecessor-version":[{"id":17782,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/17781\/revisions\/17782"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/media\/8743"}],"wp:attachment":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17781"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17781"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}