A new ransomware campaign dubbed “JanaWare”, leveraging a customized variant of the Adwind remote access Trojan (RAT) to target users in Turkey.
The malware exhibits polymorphic behavior, advanced obfuscation, and strict geofencing controls to restrict activity to Turkish systems, signaling a focused and persistent operation.
The JanaWare ransomware is distributed through phishing emails containing malicious Java archive (JAR) attachments. Once executed, these files initiate a chain reaction leading to data encryption and the display of ransom notes written exclusively in Turkish.
Investigations revealed that victims are primarily home users and small-to-medium businesses, rather than large enterprises.
According to Acronis TRU analysts, the campaign likely began around 2020 and remains active, based on samples compiled as recently as November 2025.
Ransom demands typically range between $200 and $400, aligning with a low-value, high-volume tactic designed for quick, local payouts.
JanaWare Ransomware
Telemetry and EDR data reconstructed by researchers indicate that the attack begins with phishing emails sent via Outlook, containing links to malicious Google Drive downloads.
Once the victim opens the JAR file through Java Runtime (javaw.exe), the malware initiates its payload sequence and downloads the ransomware component.

The operators also use private communication channels such as qTox or Tor-based .onion sites for negotiation and payment, emphasizing privacy and resistance to tracking.
The customized Adwind RAT variant delivering JanaWare uses multiple layers of obfuscation and polymorphism, making static analysis difficult.
Researchers identified the use of Stringer and Allatori obfuscators, alongside custom class loaders. A class named FilePumper inserts random data into JAR files, ensuring each infection generates a uniquely hashed sample a key factor in evading signature-based detection.

At startup, the malware loads a configuration defining its command-and-control (C2) infrastructure, TOR relays, and persistence settings.
A hard-coded PASSWORD parameter functions both as an authentication key and an encryption key for downloaded payloads, showcasing a modular and adaptable design.
Geographic Targeting
One of JanaWare’s defining traits is its regional exclusivity. The malware checks the system’s locale, language, and IP geolocation, proceeding only if the system corresponds to Turkey (“TR”).

This ensures the ransomware executes solely within Turkish networks, limiting unintended infections and reducing visibility to global security researchers.
Once geolocation checks pass, JanaWare disables Microsoft Defender, deletes shadow copies, and terminates Windows Update before encrypting user files with AES encryption.
Encrypted systems receive a ransom note titled “ONEMLI NOT” (“Important Note” in Turkish), instructing victims to communicate privately with the operators.
JanaWare represents a long-running, regionally focused ransomware operation built atop a flexible Java-based RAT framework. Its selective targeting, modest ransoms, and Turkish-language focus suggest deliberate localization rather than opportunistic spread.
While not as globally disruptive as enterprise ransomware families, JanaWare highlights how smaller, stealthy campaigns can persist for years under the radar through polymorphism, obfuscation, and geofencing.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





