logo

New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments

ID: 273cc8d1-ce52-5aea-91a8-70d57e2ba73d

STIX ID: report--273cc8d1-ce52-5aea-91a8-70d57e2ba73d

Feed Name: The Record from Recorded Future News

Threat Score
65/100

Date Published: 2026-04-14

Date Updated: 2026-05-01

...
...

Acronis researchers describe JanaWare, a Turkey-focused ransomware campaign active since 2020 that infects home users and small-to-medium businesses primarily through phishing emails and malicious Java archives; the malware leverages an Adwind component with heavy obfuscation and enforces system locale and IP geolocation checks so it executes only on devices configured for Turkey. Ransom notes are in Turkish, demands are low (~$200–$400), and victims are directed to contact operators via qTox, with the campaign's narrow geographic focus helping it remain under the radar.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.