Thursday, August 27, 2026

JanaWare Ransomware Hits Turkish Users via Customized Adwind RAT

A new ransomware campaign dubbed “JanaWare”, leveraging a customized variant of the Adwind remote access Trojan (RAT) to target users in Turkey.

The malware exhibits polymorphic behavior, advanced obfuscation, and strict geofencing controls to restrict activity to Turkish systems, signaling a focused and persistent operation.

The JanaWare ransomware is distributed through phishing emails containing malicious Java archive (JAR) attachments. Once executed, these files initiate a chain reaction leading to data encryption and the display of ransom notes written exclusively in Turkish.

Investigations revealed that victims are primarily home users and small-to-medium businesses, rather than large enterprises.

According to Acronis TRU analysts, the campaign likely began around 2020 and remains active, based on samples compiled as recently as November 2025.

Ransom demands typically range between $200 and $400, aligning with a low-value, high-volume tactic designed for quick, local payouts.

JanaWare Ransomware

Telemetry and EDR data reconstructed by researchers indicate that the attack begins with phishing emails sent via Outlook, containing links to malicious Google Drive downloads.

Once the victim opens the JAR file through Java Runtime (javaw.exe), the malware initiates its payload sequence and downloads the ransomware component.

Ransom note left by the malware (Source : Acronis TRU).
Ransom note left by the malware (Source : Acronis TRU).

The operators also use private communication channels such as qTox or Tor-based .onion sites for negotiation and payment, emphasizing privacy and resistance to tracking.

The customized Adwind RAT variant delivering JanaWare uses multiple layers of obfuscation and polymorphism, making static analysis difficult.

Researchers identified the use of Stringer and Allatori obfuscators, alongside custom class loaders. A class named FilePumper inserts random data into JAR files, ensuring each infection generates a uniquely hashed sample a key factor in evading signature-based detection.

Comparison of the initial and dropped sample (Source : Acronis TRU).
Comparison of the initial and dropped sample (Source : Acronis TRU).

At startup, the malware loads a configuration defining its command-and-control (C2) infrastructure, TOR relays, and persistence settings.

A hard-coded PASSWORD parameter functions both as an authentication key and an encryption key for downloaded payloads, showcasing a modular and adaptable design.

Geographic Targeting

One of JanaWare’s defining traits is its regional exclusivity. The malware checks the system’s locale, language, and IP geolocation, proceeding only if the system corresponds to Turkey (“TR”).


 Settings of the ransomware module (Source : Acronis TRU).
 Settings of the ransomware module (Source : Acronis TRU).

This ensures the ransomware executes solely within Turkish networks, limiting unintended infections and reducing visibility to global security researchers.

Once geolocation checks pass, JanaWare disables Microsoft Defender, deletes shadow copies, and terminates Windows Update before encrypting user files with AES encryption.

Encrypted systems receive a ransom note titled “ONEMLI NOT” (“Important Note” in Turkish), instructing victims to communicate privately with the operators.

JanaWare represents a long-running, regionally focused ransomware operation built atop a flexible Java-based RAT framework. Its selective targeting, modest ransoms, and Turkish-language focus suggest deliberate localization rather than opportunistic spread.

While not as globally disruptive as enterprise ransomware families, JanaWare highlights how smaller, stealthy campaigns can persist for years under the radar through polymorphism, obfuscation, and geofencing.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack...

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised...

CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale

Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today...

Related Articles

Recent News