logo

JanaWare Ransomware Targets Turkish Users Through Adwind RAT Campaign

ID: 722204ae-72d6-54d3-800b-86e4a81f049f

STIX ID: report--722204ae-72d6-54d3-800b-86e4a81f049f

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Samiksha Jain

...
...

Researchers at Acronis TRU identified a sustained JanaWare ransomware campaign (active since at least 2020) targeting Turkish users via phishing that delivers a modified Adwind RAT in Java archives; the threat employs geofencing to restrict execution to Turkish systems, uses obfuscation and polymorphism to evade detection, disables security controls before deploying an AES-based encryption module that communicates over Tor, and demands modest ransoms to focus on volume rather than high-value extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.