Cyber Security News

JanaWare Ransomware Hits Turkish Users via Customized Adwind RAT

A new ransomware campaign dubbed “JanaWare”, leveraging a customized variant of the Adwind remote access Trojan (RAT) to target users in Turkey.

The malware exhibits polymorphic behavior, advanced obfuscation, and strict geofencing controls to restrict activity to Turkish systems, signaling a focused and persistent operation.

The JanaWare ransomware is distributed through phishing emails containing malicious Java archive (JAR) attachments. Once executed, these files initiate a chain reaction leading to data encryption and the display of ransom notes written exclusively in Turkish.

Investigations revealed that victims are primarily home users and small-to-medium businesses, rather than large enterprises.

According to Acronis TRU analysts, the campaign likely began around 2020 and remains active, based on samples compiled as recently as November 2025.

Ransom demands typically range between $200 and $400, aligning with a low-value, high-volume tactic designed for quick, local payouts.

JanaWare Ransomware

Telemetry and EDR data reconstructed by researchers indicate that the attack begins with phishing emails sent via Outlook, containing links to malicious Google Drive downloads.

Once the victim opens the JAR file through Java Runtime (javaw.exe), the malware initiates its payload sequence and downloads the ransomware component.

Ransom note left by the malware (Source : Acronis TRU).

The operators also use private communication channels such as qTox or Tor-based .onion sites for negotiation and payment, emphasizing privacy and resistance to tracking.

The customized Adwind RAT variant delivering JanaWare uses multiple layers of obfuscation and polymorphism, making static analysis difficult.

Researchers identified the use of Stringer and Allatori obfuscators, alongside custom class loaders. A class named FilePumper inserts random data into JAR files, ensuring each infection generates a uniquely hashed sample a key factor in evading signature-based detection.

Comparison of the initial and dropped sample (Source : Acronis TRU).

At startup, the malware loads a configuration defining its command-and-control (C2) infrastructure, TOR relays, and persistence settings.

A hard-coded PASSWORD parameter functions both as an authentication key and an encryption key for downloaded payloads, showcasing a modular and adaptable design.

Geographic Targeting

One of JanaWare’s defining traits is its regional exclusivity. The malware checks the system’s locale, language, and IP geolocation, proceeding only if the system corresponds to Turkey (“TR”).

Settings of the ransomware module (Source : Acronis TRU).

This ensures the ransomware executes solely within Turkish networks, limiting unintended infections and reducing visibility to global security researchers.

Once geolocation checks pass, JanaWare disables Microsoft Defender, deletes shadow copies, and terminates Windows Update before encrypting user files with AES encryption.

Encrypted systems receive a ransom note titled “ONEMLI NOT” (“Important Note” in Turkish), instructing victims to communicate privately with the operators.

JanaWare represents a long-running, regionally focused ransomware operation built atop a flexible Java-based RAT framework. Its selective targeting, modest ransoms, and Turkish-language focus suggest deliberate localization rather than opportunistic spread.

While not as globally disruptive as enterprise ransomware families, JanaWare highlights how smaller, stealthy campaigns can persist for years under the radar through polymorphism, obfuscation, and geofencing.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

AWS Security Teams Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Attacks

AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail…

3 hours ago

Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency

Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research…

3 hours ago

CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix…

5 hours ago

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways,…

5 hours ago

TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices

TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an…

5 hours ago

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine…

6 hours ago