{"id":30679,"date":"2024-11-21T04:00:00","date_gmt":"2024-11-21T01:00:00","guid":{"rendered":"https:\/\/rockvell.com\/?p=30679"},"modified":"2024-11-21T12:09:59","modified_gmt":"2024-11-21T09:09:59","slug":"bacarirsansa-tut-m%c9%99ni-kaspersky-gizli-sifr%c9%99l%c9%99m%c9%99-funskiyalarina-malik-fidy%c9%99-proqrami-askarlayib","status":"publish","type":"post","link":"https:\/\/rockvell.com\/?p=30679","title":{"rendered":"Bacar\u0131rsansa, tut m\u0259ni"},"content":{"rendered":"\n<p class=\"has-medium-font-size\"><strong>Bacar\u0131rsansa, tut m\u0259ni: Kaspersky gizli \u015fifr\u0259l\u0259m\u0259 funskiyalar\u0131na malik fidy\u0259 proqram\u0131 a\u015fkarlay\u0131b<\/strong><\/p>\n\n\n\n<p>Kaspersky Qlobal Kiber \u0130nsidentl\u0259r\u0259 Cavab Qrupu (Kaspersky GERT) qurban se\u00e7ilmi\u015f t\u0259\u015fkilat\u0131n m\u0259lumatlar\u0131n\u0131 a\u015fkarlanmadan yan ke\u00e7\u0259r\u0259k \u015fifr\u0259l\u0259m\u0259k \u00fc\u00e7\u00fcn qabaqc\u0131l mexanizml\u0259rd\u0259n istifad\u0259 ed\u0259n yeni fidy\u0259 proqram\u0131 a\u015fkar edib. Z\u0259r\u0259rli proqram Saturn planetinin nizams\u0131z peykinin \u015f\u0259r\u0259fin\u0259 \u201cYmir\u201d adland\u0131r\u0131l\u0131b. Bu peyk orbitd\u0259 planetin f\u0131rlanmas\u0131na \u0259ks istiqam\u0259td\u0259 h\u0259r\u0259k\u0259t edir. \u201cYmir\u201d ad\u0131 z\u0259r\u0259rli proqram t\u0259r\u0259find\u0259n istifad\u0259 edil\u0259n yadda\u015f idar\u0259etm\u0259 funksiyalar\u0131n\u0131n qeyri-standart birl\u0259\u015fm\u0259sini \u0259ks etdirir.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"650\" height=\"433\" src=\"https:\/\/rockvell.com\/wp-content\/uploads\/2023\/05\/Kaspersky.png\" alt=\"\" class=\"wp-image-11072\" style=\"width:451px;height:auto\" srcset=\"https:\/\/rockvell.com\/wp-content\/uploads\/2023\/05\/Kaspersky.png 650w, https:\/\/rockvell.com\/wp-content\/uploads\/2023\/05\/Kaspersky-300x200.png 300w, https:\/\/rockvell.com\/wp-content\/uploads\/2023\/05\/Kaspersky-360x240.png 360w\" sizes=\"(max-width: 650px) 100vw, 650px\" \/><\/figure><\/div>\n\n\n<p><strong>\u201cYmir\u201d nec\u0259 a\u015fkarlan\u0131b<\/strong>. Kaspersky m\u00fct\u0259x\u0259ssisl\u0259ri Kolumbiyada bir t\u0259\u015fkilata bir ne\u00e7\u0259 m\u0259rh\u0259l\u0259d\u0259 edilmi\u015f h\u00fccumu t\u0259hlil ed\u0259rk\u0259n \u201cYmiri\u201d a\u015fkar edibl\u0259r. Birincisi, t\u0259cav\u00fczkarlar i\u015f\u00e7il\u0259rin korporativ hesab m\u0259lumatlar\u0131n\u0131 o\u011furlamaq \u00fc\u00e7\u00fcn \u201cRustyStealer\u201d stilerind\u0259n istifad\u0259 edibl\u0259r. Bu, onlara sistem\u0259 giri\u015f \u0259ld\u0259 etm\u0259k v\u0259 sonra fidy\u0259 proqram\u0131n\u0131 yeritm\u0259k \u00fc\u00e7\u00fcn kifay\u0259t q\u0259d\u0259r uzun m\u00fcdd\u0259t \u0259rzind\u0259 ona n\u0259zar\u0259t etm\u0259y\u0259 imkan verdi.<\/p>\n\n\n\n<p>T\u0259cav\u00fczkarlar\u0131n bu c\u00fcr davran\u0131\u015f\u0131, y\u0259ni sistem\u0259 n\u00fcfuz edib v\u0259 bir m\u00fcdd\u0259t orada qalmaq, qondarma \u201cilkin giri\u015f brokerl\u0259ri\u201d \u00fc\u00e7\u00fcn xarakterikdir. Onlar ad\u0259t\u0259n h\u00fccuma m\u0259ruz qalan sistem\u0259 giri\u015f m\u0259lumatlar\u0131n\u0131 qaranl\u0131q internetd\u0259 dig\u0259r t\u0259cav\u00fczkarlara sat\u0131rlar. Lakin, bu halda, t\u0259cav\u00fczkarlar \u00e7ox g\u00fcman ki, bunu etm\u0259yib v\u0259 fidy\u0259 proqram\u0131n\u0131 i\u015f\u0259 sal\u0131blar.<\/p>\n\n\n\n<p>&#8220;\u018fg\u0259r qondarma &#8220;brokerl\u0259r&#8221; v\u0259 fidy\u0259 proqram\u0131n\u0131 sistem\u0259 yerid\u0259nl\u0259r eyni insanlard\u0131rsa, \u0259sas tendensiyadan k\u0259nara \u00e7\u0131xma haqq\u0131nda dan\u0131\u015fmaq olar: t\u0259cav\u00fczkarlar\u0131n \u015fifr\u0259l\u0259m\u0259ni xidm\u0259t kimi ( RaaS) t\u0259klif ed\u0259n \u0259n\u0259n\u0259vi qruplara etibar etm\u0259d\u0259n hakerlik etm\u0259k \u00fc\u00e7\u00fcn \u0259lav\u0259 imkanlar\u0131 var\u201d, &#8211; dey\u0259 Kaspersky-nin Qlobal komp\u00fcter insidentl\u0259rin\u0259 reaksiya qrupunun r\u0259hb\u0259ri Konstantin Sapronov qeyd edir.<\/p>\n\n\n\n<p>T\u0259cav\u00fczkarlar z\u0259r\u0259rli kodu bilavasit\u0259 yadda\u015fda icra etm\u0259k \u00fc\u00e7\u00fcn <a href=\"https:\/\/learn.microsoft.com\/ru-ru\/cpp\/c-runtime-library\/reference\/malloc?view=msvc-170\" target=\"_blank\" rel=\"noopener\" title=\"\">malloc<\/a>, <a href=\"https:\/\/learn.microsoft.com\/ru-ru\/cpp\/c-runtime-library\/reference\/memmove-wmemmove?view=msvc-170\">memmove<\/a> v\u0259\u00a0<a href=\"https:\/\/learn.microsoft.com\/ru-ru\/cpp\/c-runtime-library\/reference\/memcmp-wmemcmp?view=msvc-170\" target=\"_blank\" rel=\"noopener\" title=\"\">memcmp<\/a> funksiyalar\u0131n\u0131n qeyri-standart kombinasiyas\u0131ndan istifad\u0259 edibl\u0259r. Bu yana\u015fma \u00fcmumi fidy\u0259 proqramlar\u0131nda istifad\u0259 olunan tipik ard\u0131c\u0131l icraetm\u0259 ax\u0131n\u0131ndan f\u0259rql\u0259nir v\u0259 a\u015fkarlanmadan daha effektiv \u015f\u0259kild\u0259 yay\u0131nma\u011fa imkan verir.<\/p>\n\n\n\n<p>Bundan \u0259lav\u0259, \u201cYmir\u201d t\u0259cav\u00fczkarlara fayllar\u0131 ist\u0259y\u0259 uy\u011fun \u015fifr\u0259l\u0259m\u0259y\u0259 imkan verir ki, bu da onlara v\u0259ziyy\u0259t\u0259 daha \u00e7ox n\u0259zar\u0259t etm\u0259k f\u00fcrs\u0259ti yarad\u0131r. \u201cPath\u201d \u0259mrind\u0259n istifad\u0259 ed\u0259r\u0259k t\u0259cav\u00fczkarlar fidy\u0259 proqram\u0131n\u0131n m\u0259lumat axtarmal\u0131 oldu\u011fu qovlu\u011fu t\u0259yin ed\u0259 bil\u0259rl\u0259r. Fayl a\u011f siyah\u0131dad\u0131rsa, z\u0259r\u0259rli proqram ondan yan ke\u00e7\u0259c\u0259k v\u0259 \u015fifrl\u0259m\u0259y\u0259c\u0259k.<\/p>\n\n\n\n<p><strong>Qabaqc\u0131l \u015fifr\u0259l\u0259m\u0259 alqoritmi<\/strong>. Fidy\u0259 proqram\u0131 y\u00fcks\u0259k s\u00fcr\u0259t v\u0259 t\u0259hl\u00fck\u0259sizliy\u0259 malik m\u00fcasir ax\u0131n \u015fifr\u0259si olan \u201cChaCha20\u201dd\u0259n istifad\u0259 edir. Onun performans\u0131 \u201cAdvanced Encryption Standard\u201d (AES) \u015fifr\u0259l\u0259m\u0259 alqoritmind\u0259n \u00fcst\u00fcnd\u00fcr.<\/p>\n\n\n\n<p>T\u0259cav\u00fczkarlar m\u0259lumat o\u011furlu\u011fu bar\u0259d\u0259 ictimaiyy\u0259t\u0259 m\u0259lumat verm\u0259s\u0259l\u0259r d\u0259 v\u0259 ya h\u0259r hans\u0131 t\u0259l\u0259b ir\u0259li s\u00fcrm\u0259s\u0259l\u0259r d\u0259, ekspertl\u0259r h\u0259r hans\u0131 yeni f\u0259aliyy\u0259ti yax\u0131ndan izl\u0259m\u0259y\u0259 davam edirl\u0259r. \u201c\u0130ndiy\u0259 q\u0259d\u0259r biz fidy\u0259 proqram\u0131 il\u0259 h\u00fccum ed\u0259n yeni qruplar\u0131n meydana \u00e7\u0131xd\u0131\u011f\u0131n\u0131 g\u00f6rm\u0259mi\u015fik. Tipik olaraq, t\u0259cav\u00fczkarlar qurbanlardan fidy\u0259 t\u0259l\u0259b etm\u0259k \u00fc\u00e7\u00fcn qaranl\u0131q internetd\u0259 forumlarda v\u0259 ya portallarda m\u0259lumat s\u0131zmas\u0131 haqq\u0131nda m\u0259lumat d\u0259rc edirl\u0259r. Lakin \u201cYmir\u201d m\u0259s\u0259l\u0259sind\u0259 bu h\u0259l\u0259 ba\u015f verm\u0259yib. Buna g\u00f6r\u0259 d\u0259 yeni fidy\u0259 proqram\u0131n\u0131n arxas\u0131nda kimin dayand\u0131\u011f\u0131 sual\u0131 a\u00e7\u0131q qal\u0131r. \u0130nan\u0131r\u0131q ki, bu, yeni kampaniya ola bil\u0259r\u201d, &#8211; dey\u0259 Konstantin izah edib.<\/p>\n\n\n\n<p>Kaspersky-nin h\u0259ll\u0259ri yeni proqram\u0131 \u201cTrojan-Ransom.Win64.Ymir.gen\u201d olaraq a\u015fkar edir. T\u0259f\u0259rr\u00fcatlar \u00fc\u00e7\u00fcn <a href=\"https:\/\/securelist.ru\/new-ymir-ransomware-found-in-colombia\/110995\/\">Securelist<\/a> x\u00fclas\u0259sin\u0259 baxa bil\u0259rsiniz.<\/p>\n\n\n\n<p>Riskl\u0259ri azaltmaq \u00fc\u00e7\u00fcn Kaspersky m\u00fct\u0259x\u0259ssisl\u0259ri t\u00f6vsiy\u0259 edirl\u0259r:<\/p>\n\n\n\n<ul>\n<li>m\u0259lumatlar\u0131n ehtiyat n\u00fcsx\u0259sini m\u00fcnt\u0259z\u0259m sur\u0259td\u0259 \u00e7\u0131xar\u0131n v\u0259 laz\u0131m olduqda onlara s\u00fcr\u0259tli giri\u015fi t\u0259min etm\u0259k \u00fc\u00e7\u00fcn m\u00fcnt\u0259z\u0259m yoxlamalar apar\u0131n;<\/li>\n\n\n\n<li>i\u015f\u00e7il\u0259r\u0259 kibert\u0259hdidl\u0259rl\u0259 ba\u011fl\u0131 m\u0259lumatl\u0131l\u0131\u011f\u0131n art\u0131r\u0131lmas\u0131 v\u0259 kibergigiyenan\u0131n \u00f6yr\u0259dilm\u0259si \u00fc\u00e7\u00fcn t\u0259liml\u0259r ke\u00e7in;<\/li>\n\n\n\n<li>cihazdak\u0131 m\u0259lumat \u015fifr\u0259l\u0259nibs\u0259 v\u0259 onun \u00fc\u00e7\u00fcn h\u0259l\u0259 ki, de\u015fifr\u0259\u00e7i yoxdursa, vacib \u015fifr\u0259l\u0259nmi\u015f fayllar\u0131 saxlamal\u0131s\u0131n\u0131z. Daha sonra t\u0259hdid ara\u015fd\u0131rmas\u0131 zaman\u0131 \u015fifr\u0259nin a\u00e7\u0131lmas\u0131 \u00fc\u00e7\u00fcn a\u00e7ar yarad\u0131la bil\u0259r;<\/li>\n\n\n\n<li>fidy\u0259 \u00f6d\u0259m\u0259yin, \u00e7\u00fcnki bu, z\u0259r\u0259rli proqram\u0131n yarad\u0131c\u0131lar\u0131n\u0131 h\u00fccumlar\u0131n\u0131 davam etdirm\u0259y\u0259 t\u0259\u015fviq edir. \u00d6d\u0259s\u0259niz bel\u0259, m\u0259lumatlar\u0131n b\u0259rpas\u0131 \u00fc\u00e7\u00fcn he\u00e7 bir z\u0259man\u0259t yoxdur;<\/li>\n\n\n\n<li>effektivliyi m\u00fct\u0259madi olaraq <a href=\"https:\/\/www.kaspersky.ru\/about\/press-releases\/93-raza-v-2023-godu-zanyali-pervye-mesta-v-nezavisimyh-testah-resheniya-laboratorii-kasperskogo\">m\u00fcst\u0259qil s\u0131naqlarla t\u0259sdiql\u0259n\u0259n<\/a> etibarl\u0131 t\u0259hl\u00fck\u0259sizlik h\u0259ll\u0259rind\u0259n istifad\u0259 edin;<\/li>\n\n\n\n<li>\u015firk\u0259tl\u0259r \u00fc\u00e7\u00fcn \u201c<a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/symphony?srsltid=AfmBOopEhIetxiyJBjgHUmYW25TPgwUx1qb0cu6NRNAKE4E83pDtbESv\">Kaspersky Symphony<\/a>\u201d kimi kibert\u0259hdidl\u0259r\u0259 qar\u015f\u0131 h\u0259rt\u0259r\u0259fli m\u00fcdafi\u0259d\u0259n istifad\u0259 edin. Bu m\u0259hsul x\u0259tti h\u0259rt\u0259r\u0259fli t\u0259hl\u00fck\u0259nin g\u00f6r\u00fcnm\u0259sini v\u0259 real vaxt rejimind\u0259 m\u00fcdafi\u0259ni t\u0259min edir. \u0130st\u0259nil\u0259n \u00f6l\u00e7\u00fcd\u0259 v\u0259 s\u0259nayed\u0259 olan t\u0259\u015fkilatlar \u00fc\u00e7\u00fcn uy\u011fundur, \u00e7\u00fcnki o, biznesin ehtiyaclar\u0131ndan v\u0259 resurslar\u0131ndan as\u0131l\u0131 olaraq bir ne\u00e7\u0259 s\u0259viyy\u0259li m\u00fcdafi\u0259 t\u0259klif edir;<\/li>\n\n\n\n<li>idar\u0259 olunan m\u00fcdafi\u0259 \u00fc\u00e7\u00fcn <a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/compromise-assessment?srsltid=AfmBOoqwy9eTgRDYS20JA2TpCCZ-59ShdUyVzUG7XgBvh_ygaCkPjIFp\">Kaspersky Compromise Assessment<\/a>, <a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/managed-detection-and-response?srsltid=AfmBOoreW8vE0pJp-4IoTWYftrb_Lz2tCu_KcdoKgIDe0eMCfAWbY8H2\">Kaspersky Managed Detection and Response<\/a> v\u0259\/v\u0259 ya <a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/incident-response?srsltid=AfmBOopvx4WIKCIuLVQ3RW0N6iz--FCA-5VXFIRyVXUoa9Q6OkZgVfA-\">Kaspersky Incident Response<\/a> kimi insidentl\u0259rin a\u015fkarlanms\u0131ndan tutmu\u015f aradan qald\u0131r\u0131lmas\u0131na q\u0259d\u0259r b\u00fct\u00f6v cavab d\u00f6vr\u00fcn\u00fc \u0259hat\u0259 ed\u0259n h\u0259ll\u0259rd\u0259n istifad\u0259 edin. Onlar gizli kiberh\u00fccumlara m\u00fcqavim\u0259t g\u00f6st\u0259rm\u0259y\u0259, insidentl\u0259ri t\u0259hlil etm\u0259y\u0259 v\u0259 ekspert d\u0259st\u0259yi alma\u011fa k\u00f6m\u0259k ed\u0259c\u0259k.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Bacar\u0131rsansa, tut m\u0259ni: Kaspersky gizli \u015fifr\u0259l\u0259m\u0259 funskiyalar\u0131na malik fidy\u0259 proqram\u0131 a\u015fkarlay\u0131b Kaspersky Qlobal Kiber \u0130nsidentl\u0259r\u0259 Cavab Qrupu (Kaspersky GERT) qurban se\u00e7ilmi\u015f t\u0259\u015fkilat\u0131n m\u0259lumatlar\u0131n\u0131 a\u015fkarlanmadan yan ke\u00e7\u0259r\u0259k \u015fifr\u0259l\u0259m\u0259k \u00fc\u00e7\u00fcn qabaqc\u0131l mexanizml\u0259rd\u0259n istifad\u0259 ed\u0259n yeni fidy\u0259 proqram\u0131&#8230;<\/p>\n","protected":false},"author":2,"featured_media":11072,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/30679"}],"collection":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=30679"}],"version-history":[{"count":2,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/30679\/revisions"}],"predecessor-version":[{"id":30681,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/30679\/revisions\/30681"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/media\/11072"}],"wp:attachment":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=30679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=30679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=30679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}