logo

6-Year Ransomware Campaign Targets Turkish Homes & SMBs

ID: dc5b37d4-1279-5048-aa26-5663cf82e9fd

STIX ID: report--dc5b37d4-1279-5048-aa26-5663cf82e9fd

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2026-04-16

Date Updated: 2026-04-22

Author: Nate Nelson

...
...

Researchers identified a long-running, Turkey-focused ransomware campaign that uses phishing to distribute a modified Adwind Java RAT which performs locale/geofence checks, disables Windows security features, achieves persistence, and deploys a ransomware plug-in called JanaWare; attackers demand small ransoms ($200–$400) at scale targeting individuals and SMBs, allowing the operation to remain under the mainstream radar while generating steady revenue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.