{"id":6860,"date":"2023-01-16T08:00:00","date_gmt":"2023-01-16T05:00:00","guid":{"rendered":"https:\/\/rockvell.com\/?p=6860"},"modified":"2023-01-16T10:41:11","modified_gmt":"2023-01-16T07:41:11","slug":"2022-ci-ilin-4-cu-rubund%c9%99-700-d%c9%99n-cox-sirk%c9%99t-h%c9%99d%c9%99fli-fidy%c9%99-kriptoqraflarinin-hucumuna-m%c9%99ruz-qalib","status":"publish","type":"post","link":"https:\/\/rockvell.com\/?p=6860","title":{"rendered":"2022-ci ilin 4-c\u00fc r\u00fcb\u00fcnd\u0259 700-d\u0259n \u00e7ox \u015firk\u0259t h\u0259d\u0259fli fidy\u0259 kriptoqraflar\u0131n\u0131n h\u00fccumuna m\u0259ruz qal\u0131b"},"content":{"rendered":"\n<p class=\"has-medium-font-size\"><strong>2022-ci ilin 4-c\u00fc r\u00fcb\u00fcnd\u0259 700-d\u0259n \u00e7ox \u015firk\u0259t h\u0259d\u0259fli fidy\u0259 kriptoqraflar\u0131n\u0131n h\u00fccumuna m\u0259ruz qal\u0131b<\/strong><\/p>\n\n\n\n<p>Kaspersky-nin m\u0259lumat\u0131na g\u00f6r\u0259 2022-ci ilin d\u00f6rd\u00fcnc\u00fc r\u00fcb\u00fcnd\u0259 d\u00fcnya \u00fczr\u0259 \u0259n az\u0131 730 t\u0259\u015fkilat h\u0259d\u0259fli fidy\u0259 proqram\u0131 h\u00fccumlar\u0131na m\u0259ruz qal\u0131b. H\u00fccumlar\u0131n yar\u0131s\u0131n\u0131n arxas\u0131nda f\u0259aliyy\u0259tl\u0259ri Kaspersky Threat Intelligence komandas\u0131n\u0131n <a href=\"https:\/\/go.kaspersky.com\/ru-ransomware-report#review\">&#8220;\u0130yr\u0259nc s\u0259kkizlik: Fidy\u0259 Proqram\u0131 H\u00fccumlar\u0131 Qruplar\u0131n\u0131n Texnikalar\u0131, Taktikalar\u0131 v\u0259 Prosedurlar\u0131 (TTP)<\/a>&#8221; adl\u0131 analitik hesabat\u0131nda t\u0259svir edil\u0259n s\u0259kkiz b\u00f6y\u00fck qrup dayan\u0131r,. Hal-haz\u0131rda, Clop (TA 505), Hive, Lockbit, RagnarLocker, BlackByte v\u0259 BlackCat \u0259n aktiv olaraq qal\u0131r, sonuncu ikisi is\u0259 2021-ci ilin pay\u0131z\u0131ndan etibar\u0259n h\u00fccumlarda i\u015ftirak edir.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"650\" height=\"433\" src=\"https:\/\/rockvell.com\/wp-content\/uploads\/2022\/12\/K.png\" alt=\"\" class=\"wp-image-6482\" srcset=\"https:\/\/rockvell.com\/wp-content\/uploads\/2022\/12\/K.png 650w, https:\/\/rockvell.com\/wp-content\/uploads\/2022\/12\/K-300x200.png 300w, https:\/\/rockvell.com\/wp-content\/uploads\/2022\/12\/K-360x240.png 360w\" sizes=\"(max-width: 650px) 100vw, 650px\" \/><\/figure><\/div>\n\n\n<p>\u018fn \u00e7ox h\u00fccum LockBit t\u0259r\u0259find\u0259n h\u0259yata ke\u00e7irilib: fidy\u0259 kriptoqraf\u0131n\u0131n m\u00f6vcud oldu\u011fu b\u00fct\u00fcn d\u00f6vr \u0259rzind\u0259 onun qurbanlar\u0131n\u0131n say\u0131 mini ke\u00e7ib. Qrupun h\u0259d\u0259fl\u0259ri aras\u0131nda aviasiya, enerji, konsaltinq xidm\u0259tl\u0259ri sah\u0259l\u0259rini t\u0259msil ed\u0259n \u015firk\u0259tl\u0259ri var. Qurbanlar\u0131n co\u011frafiyas\u0131 da m\u00fcxt\u0259lifdir: AB\u015e, \u00c7in, Hindistan, \u0130ndoneziya, h\u0259m\u00e7inin M\u0259rk\u0259zi v\u0259 \u015eimal-Q\u0259rbi Avropa \u00f6lk\u0259l\u0259ri. Operatorlar qurban\u0131n infrastrukturunda &#8220;i\u015fl\u0259m\u0259k&#8221; fidy\u0259\u00e7il\u0259r \u00fc\u00e7\u00fcn standart hesab edil\u0259n ilkin n\u00fcfuz vektorlar\u0131ndan v\u0259 utilitl\u0259rd\u0259n istifad\u0259 edirl\u0259r. \u0130lkin giri\u015f \u0259ld\u0259 etm\u0259k \u00fc\u00e7\u00fcn \u0259n \u00e7ox RDP protokollar\u0131 v\u0259 ya z\u0259iflik istismar\u0131 vasit\u0259l\u0259rin\u0259, \u015f\u0259b\u0259k\u0259 daxilind\u0259ki f\u0259aliyy\u0259tl\u0259r \u00fc\u00e7\u00fcn is\u0259 PsExec, Empire, Mimikatz al\u0259tl\u0259rin\u0259 m\u00fcraci\u0259t olunur.<\/p>\n\n\n\n<p>\u201cFidy\u0259 proqramlar\u0131 \u0259sas t\u0259hl\u00fck\u0259l\u0259rd\u0259n biri olmaqda davam edir. Biz bu tip z\u0259r\u0259rli proqramlar \u00fcz\u0259rind\u0259 \u00e7oxlu analitik i\u015f aparm\u0131\u015f\u0131q v\u0259 onlar\u0131n texnika v\u0259 taktikalar\u0131n\u0131n \u0259sas\u0259n eyni oldu\u011funu v\u0259 uzun m\u00fcdd\u0259t \u0259rzind\u0259 d\u0259yi\u015film\u0259diyini a\u015fkar etmi\u015fik. Hesabat\u0131m\u0131z \u015firk\u0259tl\u0259r\u0259 bu t\u0259hl\u00fck\u0259 il\u0259 m\u00fcbariz\u0259 aparma\u011fa k\u00f6m\u0259k ed\u0259c\u0259k faydal\u0131 m\u0259lumatlarla z\u0259ngindir\u201d, &#8211; dey\u0259 Kaspersky-nin geni\u015fl\u0259ndirilmi\u015f t\u0259hdid ara\u015fd\u0131rmalar\u0131 \u015f\u00f6b\u0259sinin r\u0259hb\u0259ri Nikita Nazarov bildirir.<\/p>\n\n\n\n<p>Hesabat\u0131n rus dilind\u0259ki tam versiyas\u0131n\u0131 buradan oxuya bil\u0259rsiniz: <a href=\"https:\/\/go.kaspersky.com\/ru-ransomware-report\">https:\/\/go.kaspersky.com\/ru-ransomware-report<\/a>.<\/p>\n\n\n\n<p>Biznesi fidy\u0259 proqram\u0131 h\u00fccumlar\u0131ndan qorumaq \u00fc\u00e7\u00fcn Kaspersky \u015firk\u0259tl\u0259r\u0259 a\u015fa\u011f\u0131dak\u0131 t\u0259birl\u0259r\u0259 \u0259m\u0259l etm\u0259yi xat\u0131rlad\u0131r:<\/p>\n\n\n\n<ul><li>ictimai \u015f\u0259b\u0259k\u0259l\u0259rd\u0259n uzaq i\u015f masas\u0131 xidm\u0259tl\u0259r\u0259 (m\u0259s\u0259l\u0259n, RDP) qo\u015fulma imkan\u0131n\u0131n qar\u015f\u0131s\u0131n\u0131 almaq; bu xidm\u0259tl\u0259r \u00fc\u00e7\u00fcn g\u00fccl\u00fc \u015fifr\u0259l\u0259rd\u0259n istifad\u0259 etm\u0259k \u00fc\u00e7\u00fcn t\u0259hl\u00fck\u0259sizlik siyas\u0259tl\u0259rini qura\u015fd\u0131r\u0131n v\u0259 t\u0259nziml\u0259yin;<\/li><li>distant rejimd\u0259 \u00e7al\u0131\u015fan i\u015f\u00e7il\u0259ri birl\u0259\u015fdir\u0259n v\u0259 korporativ \u015f\u0259b\u0259k\u0259d\u0259 \u015fl\u00fcz rolunu oynayan kommersiya VPN h\u0259ll\u0259ri \u00fc\u00e7\u00fcn yenil\u0259m\u0259l\u0259ri t\u0259xir\u0259 salmadan qura\u015fd\u0131rmaq;<\/li><li>t\u0259\u015fkilatda t\u0259tbiq edil\u0259n proses\u0259 uy\u011fun olaraq, z\u0259iflikl\u0259rd\u0259n istifad\u0259nin qar\u015f\u0131s\u0131n\u0131 almaq \u00fc\u00e7\u00fcn istifad\u0259 olunan b\u00fct\u00fcn cihazlarda proqram t\u0259minat\u0131n\u0131 operativ \u015f\u0259kild\u0259 yenil\u0259m\u0259k;<\/li><li>\u015f\u0259b\u0259k\u0259d\u0259ki h\u0259r\u0259k\u0259tl\u0259ri v\u0259 m\u0259lumatlar\u0131n \u0130nternet\u0259 \u00f6t\u00fcr\u00fclm\u0259sini izl\u0259m\u0259k; t\u0259cav\u00fczkarlar\u0131n \u00fcnsiyy\u0259tini a\u015fkar etm\u0259k \u00fc\u00e7\u00fcn \u00e7\u0131x\u0131\u015f trafikin\u0259 x\u00fcsusi diqq\u0259t yetirm\u0259k<\/li><li>m\u0259lumatlar\u0131n m\u00fcnt\u0259z\u0259m ehtiyat n\u00fcsx\u0259l\u0259rini \u00e7\u0131xarmaq v\u0259 f\u00f6vq\u0259lad\u0259 hallarda onlara tez giri\u015f imkan\u0131na malik olmaq;<\/li><li>i\u015f\u00e7il\u0259r\u0259, m\u0259s\u0259l\u0259n, m\u0259s\u0259l\u0259n, <a href=\"https:\/\/www.kaspersky.ru\/small-to-medium-business-security\/security-awareness-platform\">Kaspersky Automated Security Awareness Platform<\/a>-dan istifad\u0259 etm\u0259kl\u0259, kibert\u0259hl\u00fck\u0259sizlik qaydalar\u0131 \u00fczr\u0259 t\u0259lim ke\u00e7m\u0259k;<\/li><li>i\u015f yerl\u0259rinin etibarl\u0131 m\u00fchafiz\u0259sini t\u0259min etm\u0259k, ist\u0259nil\u0259n m\u00fcr\u0259kk\u0259blikd\u0259 olan h\u00fccumlar\u0131 ilkin m\u0259rh\u0259l\u0259d\u0259 m\u00fc\u0259yy\u0259n etm\u0259k v\u0259 dayand\u0131rmaq, d\u00fcnyada kiberh\u00fccumlara dair \u0259n aktual m\u0259lumatlar\u0131n toplanmas\u0131 daxil olmaqla, \u00e7evik v\u0259 effektiv t\u0259hl\u00fck\u0259sizlik sistemi qurma\u011fa imkan ver\u0259c\u0259k kompleks t\u0259hl\u00fck\u0259sizlik h\u0259ll\u0259rini t\u0259tbiq etm\u0259k v\u0259 i\u015f\u00e7il\u0259r\u0259 \u0259sas r\u0259q\u0259msal savadl\u0131l\u0131q bacar\u0131qlar\u0131n\u0131 \u00f6yr\u0259tm\u0259k. \u0130st\u0259nil\u0259n \u00f6l\u00e7\u00fcd\u0259 \u015firk\u0259tin ehtiyaclar\u0131na uy\u011fun olaraq bu c\u00fcr h\u0259ll\u0259rin kombinasiyas\u0131 <a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/symphony\">Kaspersky Symphony<\/a> biznesin m\u00fchafiz\u0259si m\u0259hsullar\u0131n\u0131n yeni x\u0259ttinin s\u0259viyy\u0259l\u0259rind\u0259 yer al\u0131r;<\/li><li>SOC m\u00fct\u0259x\u0259ssisl\u0259rin\u0259 <a href=\"https:\/\/www.kaspersky.ru\/enterprise-security\/threat-intelligence\">Kaspersky Threat Intelligence Portal<\/a> kimi \u0259n son t\u0259hl\u00fck\u0259 m\u0259lumatlar\u0131n\u0131 ehtiva ed\u0259n m\u0259nb\u0259l\u0259r\u0259 \u00e7\u0131x\u0131\u015f t\u0259min etm\u0259k. \u018fsas funksiyalara pulsuz giri\u015f burada m\u00f6vcuddur: <a href=\"https:\/\/opentip.kaspersky.com\/\">https:\/\/opentip.kaspersky.com \/<\/a>.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>2022-ci ilin 4-c\u00fc r\u00fcb\u00fcnd\u0259 700-d\u0259n \u00e7ox \u015firk\u0259t h\u0259d\u0259fli fidy\u0259 kriptoqraflar\u0131n\u0131n h\u00fccumuna m\u0259ruz qal\u0131b Kaspersky-nin m\u0259lumat\u0131na g\u00f6r\u0259 2022-ci ilin d\u00f6rd\u00fcnc\u00fc r\u00fcb\u00fcnd\u0259 d\u00fcnya \u00fczr\u0259 \u0259n az\u0131 730 t\u0259\u015fkilat h\u0259d\u0259fli fidy\u0259 proqram\u0131 h\u00fccumlar\u0131na m\u0259ruz qal\u0131b. H\u00fccumlar\u0131n yar\u0131s\u0131n\u0131n arxas\u0131nda&#8230;<\/p>\n","protected":false},"author":2,"featured_media":6482,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/6860"}],"collection":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6860"}],"version-history":[{"count":1,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/6860\/revisions"}],"predecessor-version":[{"id":6861,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/posts\/6860\/revisions\/6861"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=\/wp\/v2\/media\/6482"}],"wp:attachment":[{"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6860"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6860"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rockvell.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}