logo

Customized Adwind RAT Delivers JanaWare Ransomware To Turkish Victims

ID: e2dcb7a6-705d-5fae-8722-0eb562e12202

STIX ID: report--e2dcb7a6-705d-5fae-8722-0eb562e12202

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-04-15

Date Updated: 2026-04-15

Author: Varshini

...
...

Researchers observed a regionally focused campaign using a customized Adwind Java RAT to deploy JanaWare ransomware against Turkish users and small organizations via phishing-driven Java malware; the loader uses heavy Java obfuscation, a FilePumper to polymorph JARs, DuckDNS-based C2 and Tor tunneling, and drops Turkish ransom notes with AES-encrypted files and keys sent over Tor, making recovery difficult without the attackers. Detection by some EDR/XDR vendors is reported, but the operation remains active and defenders are urged to restrict Java, treat unsolicited Google Drive links cautiously, and deploy behavior-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.