logo

JanaWare Ransomware Targets Turkish Users via Adwind RAT

ID: 32c39248-7ead-5579-9df0-772d0431e670

STIX ID: report--32c39248-7ead-5579-9df0-772d0431e670

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-04-20

Date Updated: 2026-04-20

Author: Varshini

...
...

Researchers uncovered a targeted, lower-profile ransomware campaign aimed at Turkish users that leverages a customized Adwind RAT to deploy a Java-based JanaWare ransomware module. The malware uses heavy obfuscation (Stringer, Allatori, custom class loaders, FilePumper), checks system language and IP geolocation before payload execution, weakens Windows defenses via PowerShell and registry changes, communicates over Tor to send AES encryption keys to C2, and drops Turkish-language ransom notes named with the fixed phrase "ONEMLI_NOT."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.