logo

New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT

ID: 8441fa85-26bd-5811-9538-fc3b245a9577

STIX ID: report--8441fa85-26bd-5811-9538-fc3b245a9577

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-04-20

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

JanaWare is a Turkey-focused ransomware campaign delivered via malicious JAR files (hosted on Google Drive) that deploys a heavily modified Adwind Java RAT as a multi-stage loader; it uses geofencing (locale and IP checks), Java obfuscators, a polymorphic self-pumping JAR, and Tor-based C2 to evade detection and restrict execution to Turkish hosts. The malware disables defenses, removes VSS backups, encrypts files with AES while exfiltrating keys over Tor, and leaves Turkish-language ransom notes ("ONEMLI NOT") demanding $200–$400; recommended mitigations include disabling unnecessary JRE execution, blocking JARs from untrusted sources, email gateway filtering for Drive links, network monitoring for known C2 (elementsplugin.duckdns.org / 151.243.109.115 on ports 49152–49153), and offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.