New JanaWare ransomware targets Turkey via Adwind RAT
ID: bc1563a5-82a7-5e59-adff-c5cfb0b3f084
STIX ID: report--bc1563a5-82a7-5e59-adff-c5cfb0b3f084
Feed Name: TRU Security by Acronis
Acronis TRU identified a persistent, Turkey-focused ransomware operation dubbed "JanaWare" that leverages a customized Adwind Java RAT to deliver a Java-based ransomware module. The campaign uses phishing-driven distribution (malicious JARs), heavy obfuscation, polymorphism (self-modifying JARs), and layered geofencing (locale and IP checks) to restrict execution to Turkish environments; it communicates over Tor and low-value ransom demands target home users and SMBs. The report includes technical analysis, infection chain telemetry, defensive impact (disabling Defender, VSS removal), sample hash IoCs and C2 endpoints, and notes active infrastructure as recently as 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
