{"id":20207,"date":"2024-01-19T07:00:00","date_gmt":"2024-01-19T04:00:00","guid":{"rendered":"https:\/\/rockvell.com\/?p=20207"},"modified":"2024-01-19T09:35:10","modified_gmt":"2024-01-19T06:35:10","slug":"kaspersky-t%c9%99r%c9%99find%c9%99n-pegasus-casus-proqraminin-iphone-cihazlarinda-askarlanmasi","status":"publish","type":"post","link":"https:\/\/rockvell.com\/?p=20207","title":{"rendered":"\u201cKaspersky\u201d t\u0259r\u0259find\u0259n \u201cPegasus\u201d casus proqram\u0131n\u0131n iPhone cihazlar\u0131nda a\u015fkarlanmas\u0131"},"content":{"rendered":"\n<p class=\"has-medium-font-size\"><strong>\u201cKaspersky\u201d t\u0259r\u0259find\u0259n \u201cPegasus\u201d casus proqram\u0131n\u0131n iPhone cihazlar\u0131nda a\u015fkarlanmas\u0131n\u0131n yeni \u00fcsulu haz\u0131rlan\u0131b<\/strong>.<\/p>\n\n\n\n<p>\u201cKaspersky\u201dnin Qlobal T\u0259hdid T\u0259dqiqat\u0131 v\u0259 T\u0259hlili M\u0259rk\u0259zinin (GReAT) m\u00fct\u0259x\u0259ssisl\u0259ri iOS cihazlar\u0131n\u0131n \u201c<a href=\"https:\/\/citizenlab.ca\/tag\/pegasus\/\" target=\"_blank\" rel=\"noopener\" title=\"\">Pegasus<\/a>\u201d, \u201c<a href=\"https:\/\/citizenlab.ca\/2023\/04\/spyware-vendor-quadream-exploits-victims-customers\/\" target=\"_blank\" rel=\"noopener\" title=\"\">Reign<\/a>\u201d v\u0259 \u201c<a href=\"https:\/\/citizenlab.ca\/2023\/10\/predator-spyware-targets-us-eu-lawmakers-journalists\/\" target=\"_blank\" rel=\"noopener\" title=\"\">Predator<\/a>\u201d kimi m\u00fcr\u0259kk\u0259b casus proqramlar\u0131 il\u0259 yoluxma g\u00f6st\u0259ricil\u0259rini a\u015fkar etm\u0259k \u00fc\u00e7\u00fcn yeni \u00fcsul haz\u0131rlay\u0131blar. Yeni sad\u0259 al\u0259t istifad\u0259\u00e7il\u0259rin \u00f6z iPhone cihazlar\u0131n\u0131 m\u00fcst\u0259qil \u015f\u0259kild\u0259 yoxlaya bilm\u0259l\u0259ri \u00fc\u00e7\u00fcn \u201cShutdown.log\u201dda \u0259vv\u0259ll\u0259r m\u0259lum olmayan izl\u0259ri axtarma\u011fa imkan verir.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2.png\" alt=\"\" class=\"wp-image-8743\" style=\"width:339px;height:auto\" srcset=\"https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2.png 1024w, https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2-300x200.png 300w, https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2-768x512.png 768w, https:\/\/rockvell.com\/wp-content\/uploads\/2023\/03\/Kaspersky-2-360x240.png 360w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n<p>\u201cKaspersky\u201d t\u0259dqiqat\u00e7\u0131lar\u0131 ist\u0259nil\u0259n iOS mobil cihaz\u0131n\u0131n sistem diaqnostikas\u0131 arxivind\u0259 saxlan\u0131lan \u201cShutdown.log\u201d sistem jurnal\u0131nda \u201cPegasus\u201da yoluxman\u0131n yeni \u0259lam\u0259tl\u0259rini a\u015fkar edibl\u0259r. Bu arxiv cihaz\u0131n h\u0259r bir yenid\u0259n ba\u015flad\u0131lma seans\u0131 haqq\u0131nda m\u0259lumatlar\u0131 ehtiva edir. Bu o dem\u0259kdir ki, yoluxmu\u015f cihaz\u0131n sahibi m\u00fct\u0259madi olaraq onu yenid\u0259n i\u015f\u0259 sal\u0131rsa, jurnalda \u201cPegasus\u201d z\u0259r\u0259rli proqram\u0131 il\u0259 \u0259laq\u0259li anomaliyalar meydana \u00e7\u0131x\u0131r.<\/p>\n\n\n\n<p>A\u015fkar edilmi\u015f anomaliyalar aras\u0131nda yenid\u0259n ba\u015flatmalara mane olan \u201cPegasus\u201dla ba\u011fl\u0131 l\u0259ngimi\u015f prosesl\u0259r haqq\u0131nda qeydl\u0259r, h\u0259m\u00e7inin kibert\u0259hl\u00fck\u0259sizlik c\u0259miyy\u0259tind\u0259 ba\u015fqalar\u0131 t\u0259r\u0259find\u0259n m\u00fc\u0259yy\u0259n edilmi\u015f dig\u0259r <a href=\"https:\/\/citizenlab.ca\/2023\/04\/spyware-vendor-quadream-exploits-victims-customers\/\" target=\"_blank\" rel=\"noopener\" title=\"\">yoluxma izl\u0259ri<\/a> var.<\/p>\n\n\n\n<p>\u201cT\u0259hlil al\u0259ti dem\u0259k olar ki, he\u00e7 bir resurs t\u0259l\u0259b etm\u0259d\u0259n sistem artefaktlar\u0131n\u0131 ara\u015fd\u0131rmaq v\u0259 potensial iPhone infeksiyalar\u0131n\u0131 m\u00fc\u0259yy\u0259n etm\u0259y\u0259 imkan verir. Jurnaldak\u0131 g\u00f6st\u0259ricil\u0259rin t\u0259hlili \u0259sas\u0131nda metodumuzla a\u015fkar edil\u0259n infeksiya \u2018Mobile Verification Toolkit (MVT)&#8217;d\u0259n istifad\u0259 ed\u0259r\u0259k dig\u0259r iOS artefaktlar\u0131n\u0131n emal\u0131 il\u0259 t\u0259sdiql\u0259nib. M\u00fcvafiq olaraq, bizim yana\u015fmam\u0131z iOS yoluxmalar\u0131n\u0131n \u00f6yr\u0259nilm\u0259sin\u0259 vahid yana\u015fman\u0131n bir hiss\u0259sin\u0259 \u00e7evrilir. \u00dcst\u0259lik, t\u0259hlil etdiyimiz dig\u0259r \u2018Pegasus&#8217; infeksiyalar\u0131nda bu davran\u0131\u015f\u0131n ard\u0131c\u0131ll\u0131\u011f\u0131n\u0131 t\u0259sdiql\u0259mi\u015fik v\u0259 inan\u0131r\u0131q ki, bu, yoluxma prosesinin sonrak\u0131 t\u0259dqiqi \u00fc\u00e7\u00fcn etibarl\u0131 artefakt rolunu oynayacaq\u201d, &#8211; dey\u0259 \u201cKaspersky\u201cnin Qlobal T\u0259hdid T\u0259dqiqat\u0131 v\u0259 T\u0259hlili M\u0259rk\u0259zinin (GReAT) r\u0259hb\u0259ri \u0130qor Kuznetsov qeyd edir.&nbsp;<\/p>\n\n\n\n<p>Pegasus insidentl\u0259rind\u0259 \u201cShutdown.log\u201du t\u0259hlil etdikd\u0259n sonra \u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri \u201cReign\u201d v\u0259 \u201cPredator\u201d kimi <a href=\"https:\/\/citizenlab.ca\/2023\/04\/spyware-vendor-quadream-exploits-victims-customers\/\" target=\"_blank\" rel=\"noopener\" title=\"\">dig\u0259r z\u0259r\u0259rli proqramlar\u0131n iOS yoluxmalar\u0131nda da m\u00fc\u0259yy\u0259n edilmi\u015f<\/a> b\u0259nz\u0259r standart yoluxma yollar\u0131n\u0131, y\u0259ni \u201c\/private\/var\/db\/\u201d a\u015fkar edibl\u0259r. \u015eirk\u0259t m\u00fct\u0259x\u0259ssisl\u0259ri ehtimal edir ki, h\u0259min jurnal fayl\u0131 bu z\u0259r\u0259rli proqram ail\u0259l\u0259ri il\u0259 \u0259laq\u0259li yoluxmalar\u0131 m\u00fc\u0259yy\u0259n etm\u0259y\u0259 k\u00f6m\u0259k ed\u0259c\u0259k.<\/p>\n\n\n\n<p>Cihazlarda casus proqram\u0131n\u0131n tap\u0131lmas\u0131n\u0131 asanla\u015fd\u0131rmaq \u00fc\u00e7\u00fcn \u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri \u201cShutdown.log\u201d artefaktlar\u0131n\u0131 a\u015fkar v\u0259 t\u0259hlil etm\u0259yi asanla\u015fd\u0131ran x\u00fcsusi <a href=\"https:\/\/github.com\/KasperskyLab\/iShutdown\" target=\"_blank\" rel=\"noopener\" title=\"\">al\u0259t (utility)<\/a> haz\u0131rlay\u0131blar.<\/p>\n\n\n\n<p>Pegasus kimi iOS casus proqramlar\u0131 \u00f6z m\u00fcr\u0259kk\u0259bliyi il\u0259 se\u00e7ilir. Cihazlar\u0131 bu c\u00fcr z\u0259r\u0259rli proqramlardan qorumaq \u00fc\u00e7\u00fcn \u201cKaspersky\u201d m\u00fct\u0259x\u0259ssisl\u0259ri t\u00f6vsiy\u0259 edirl\u0259r:<\/p>\n\n\n\n<ul>\n<li><strong>Cihaz\u0131n\u0131z\u0131 h\u0259r g\u00fcn yenid\u0259n ba\u015flad\u0131n (restart edin)<\/strong>. \u201cAmnesty International\u201d v\u0259 \u201cCitizen Lab\u201da g\u00f6r\u0259, \u201cPegasus\u201d tez-tez s\u0131f\u0131r g\u00fcn z\u0259iflikl\u0259rind\u0259n istifad\u0259 edir. G\u00fcnd\u0259lik yenid\u0259n ba\u015flatma cihaz\u0131n yadda\u015f\u0131n\u0131 t\u0259mizl\u0259m\u0259y\u0259 k\u00f6m\u0259k ed\u0259 bil\u0259r ki, n\u0259tic\u0259d\u0259 t\u0259cav\u00fczkarlar eyni yoluxdurman\u0131 t\u0259krar\u0259n i\u015f\u0259 salma\u011fa m\u0259cbur qal\u0131r v\u0259 zaman ke\u00e7dikc\u0259 onlar\u0131n a\u015fkarlanma \u015fans\u0131 art\u0131r.<\/li>\n\n\n\n<li><strong>\u201cLockdown\u201d rejimini aktivl\u0259\u015fdirin<\/strong>. H\u0259d\u0259fli kiberh\u00fccumlara qar\u015f\u0131 \u201cApple\u201d \u015firk\u0259ti t\u0259r\u0259find\u0259n bu yax\u0131nlarda \u0259lav\u0259 edilmi\u015f ekstremal m\u00fcdafi\u0259 rejimind\u0259n istifad\u0259nin u\u011furu haqq\u0131nda art\u0131q ictimai hesabatlar var.<\/li>\n\n\n\n<li><strong>iMessage v\u0259 Facetime funksiyalar\u0131n\u0131 s\u00f6nd\u00fcr\u00fcn<\/strong>. T\u0259cav\u00fczkarlar defolt olaraq aktivl\u0259\u015fdiril\u0259n bu funksiyalardan istifad\u0259 ed\u0259 bil\u0259rl\u0259r. Onlar\u0131 s\u00f6nd\u00fcrm\u0259kl\u0259, s\u0131f\u0131r klik h\u00fccum silsil\u0259sinin qurban\u0131 olmaq riski xeyli azal\u0131r.<\/li>\n\n\n\n<li><strong>Cihaz\u0131n\u0131z\u0131 m\u00fcnt\u0259z\u0259m olaraq yenil\u0259yin<\/strong>. iOS yamaqlar\u0131n\u0131 burax\u0131lan kimi qura\u015fd\u0131r\u0131n, \u00e7\u00fcnki bir \u00e7ox iOS istismar d\u0259stl\u0259ri art\u0131q yamaqlar\u0131 m\u00f6vcud olan z\u0259iflikl\u0259rd\u0259n istifad\u0259 edir. T\u0259cav\u00fczkarlar\u0131 qabaqlamaq \u00fc\u00e7\u00fcn cihaz\u0131n\u0131z\u0131n yenil\u0259nm\u0259sini t\u0259xir\u0259 salmamaq vacibdir.<\/li>\n\n\n\n<li><strong>M\u00fcnt\u0259z\u0259m olaraq ehtiyat n\u00fcsx\u0259l\u0259rini yoxlay\u0131n v\u0259 sistem diaqnostikas\u0131n\u0131 apar\u0131n<\/strong>. MVT d\u0259stind\u0259n, h\u0259m\u00e7inin <a href=\"https:\/\/github.com\/kasperskylab\" target=\"_blank\" rel=\"noopener\" title=\"\">\u201cKaspersky\u201d al\u0259tl\u0259rind\u0259n<\/a> istifad\u0259 etm\u0259kl\u0259 \u015fifr\u0259l\u0259nmi\u015f ehtiyat n\u00fcsx\u0259l\u0259rin v\u0259 systemin diaqnostik arxivl\u0259rinin emal\u0131 z\u0259r\u0259rli proqram\u0131n a\u015fkarlanmas\u0131na k\u00f6m\u0259k ed\u0259 bil\u0259r.<\/li>\n<\/ul>\n\n\n\n<p>M\u00fcr\u0259kk\u0259b casus proqram il\u0259 iOS cihazlar\u0131n\u0131n yoluxma g\u00f6st\u0259ricil\u0259rinin a\u015fkarlanmas\u0131n\u0131n yeni \u00fcsullar\u0131 haqq\u0131nda daha \u0259trafl\u0131 m\u0259lumat\u0131 buradan \u0259ld\u0259 ed\u0259 bil\u0259riniz: <a href=\"https:\/\/securelist.com\/shutdown-log-lightweight-ios-malware-detection-method\/111734\/\" target=\"_blank\" rel=\"noopener\" title=\"\">https:\/\/securelist.com\/shutdown-log-lightweight-ios-malware-detection-method\/111734\/<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cKaspersky\u201d t\u0259r\u0259find\u0259n \u201cPegasus\u201d casus proqram\u0131n\u0131n iPhone cihazlar\u0131nda a\u015fkarlanmas\u0131n\u0131n yeni \u00fcsulu haz\u0131rlan\u0131b. \u201cKaspersky\u201dnin Qlobal T\u0259hdid T\u0259dqiqat\u0131 v\u0259 T\u0259hlili M\u0259rk\u0259zinin (GReAT) m\u00fct\u0259x\u0259ssisl\u0259ri iOS cihazlar\u0131n\u0131n \u201cPegasus\u201d, \u201cReign\u201d v\u0259 \u201cPredator\u201d kimi m\u00fcr\u0259kk\u0259b casus proqramlar\u0131 il\u0259 yoluxma g\u00f6st\u0259ricil\u0259rini a\u015fkar etm\u0259k&#8230;<\/p>\n","protected":false},"author":2,"featured_media":8743,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/20207"}],"collection":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20207"}],"version-history":[{"count":1,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/20207\/revisions"}],"predecessor-version":[{"id":20208,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/20207\/revisions\/20208"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/media\/8743"}],"wp:attachment":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}