logo

New JanaWare ransomware targets Turkey via Adwind RAT

ID: bc1563a5-82a7-5e59-adff-c5cfb0b3f084

STIX ID: report--bc1563a5-82a7-5e59-adff-c5cfb0b3f084

Feed Name: TRU Security by Acronis

Threat Score
70/100

Date Published: 2026-04-14

Date Updated: 2026-07-24

...
...

Acronis TRU identified a persistent, Turkey-focused ransomware operation dubbed "JanaWare" that leverages a customized Adwind Java RAT to deliver a Java-based ransomware module. The campaign uses phishing-driven distribution (malicious JARs), heavy obfuscation, polymorphism (self-modifying JARs), and layered geofencing (locale and IP checks) to restrict execution to Turkish environments; it communicates over Tor and low-value ransom demands target home users and SMBs. The report includes technical analysis, infection chain telemetry, defensive impact (disabling Defender, VSS removal), sample hash IoCs and C2 endpoints, and notes active infrastructure as recently as 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.