New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments
ID: 273cc8d1-ce52-5aea-91a8-70d57e2ba73d
STIX ID: report--273cc8d1-ce52-5aea-91a8-70d57e2ba73d
Feed Name: The Record from Recorded Future News
Acronis researchers describe JanaWare, a Turkey-focused ransomware campaign active since 2020 that infects home users and small-to-medium businesses primarily through phishing emails and malicious Java archives; the malware leverages an Adwind component with heavy obfuscation and enforces system locale and IP geolocation checks so it executes only on devices configured for Turkey. Ransom notes are in Turkish, demands are low (~$200–$400), and victims are directed to contact operators via qTox, with the campaign's narrow geographic focus helping it remain under the radar.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
