Threat reportRansomwareTL-2026-0368
JanaWare Ransomware: Polymorphic Java RAT Campaign Targeting Turkey via Customized Adwind
JanaWare Ransomware (TL-2026-0368), also tracked as JanaWare, is a high-severity ransomware operation, first published 2026-04-15. It is attributed to JanaWare Operators (Russia) with low confidence, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1020, T1027, T1027.002), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1JanaWare Operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-0368
- Threat ID
- TL-2026-0368
- Also known as
- JanaWare
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- JanaWare Operators
- Attribution confidence
- LOW
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- small-medium-business, consumer, retail, services
- Target regions
- Turkey
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in JanaWare Ransomware
Malware and tooling: AdWind, JanaWare, Adwind RAT v3.0+, Allatori Java Obfuscator, Stringer Java Obfuscator
How JanaWare Ransomware works
New ransomware module tracked as JanaWare, delivered via a customized Adwind Java RAT with polymorphic characteristics. The campaign uses Stringer and Allatori obfuscators with a FilePumper class that generates unique file hashes per infection. Geofenced exclusively to Turkey via locale and IP checks, employing AES encryption with keys exfiltrated over Tor, and demanding $200-$400 ransoms via qTox.
JanaWare is a ransomware module deployed through a customized variant of the Adwind (jRAT) remote access trojan, specifically targeting Turkish users and small-to-medium businesses. The campaign has been active since at least 2020, with the most recent compiled samples dating to November 2025 and continued infrastructure activity confirmed through April 2026.
The infection chain begins with phishing emails crafted in Turkish, directing victims to Google Drive links hosting malicious Java Archive (JAR) files. Upon execution via javaw.exe (Java Runtime Environment 1.8.0_451), the Adwind RAT establishes command-and-control communication with elementsplugin.duckdns.org on TCP ports 49152 and 49153. The C2 handshake uses the distinctive prefix 'JANAWARE', from which the ransomware derives its name.
A defining characteristic of this campaign is its polymorphic evasion capability. The malware contains a class named FilePumper that performs self-modification by injecting random content into the JAR archive during installation, inflating the file size by tens of megabytes. This ensures each deployed instance produces a unique file hash (MD5, SHA256), effectively defeating signature-based detection at scale.
The malware employs strict geofencing controls before proceeding with encryption. It verifies: (1) the system locale matches Turkish language/region settings, and (2) the external IP geolocation confirms the country code begins with 'TR'. Only systems passing both checks receive the ransomware payload.
Prior to encryption, JanaWare executes a series of defense-weakening actions via PowerShell and registry commands: disabling Microsoft Defender real-time protection, deleting Volume Shadow Copy Service (VSS) snapshots to prevent recovery, terminating Windows Update services, and enumerating installed antivirus products to identify additional security tools to neutralize.
The ransomware module uses AES encryption for file encryption, with encryption keys transmitted to the C2 server over Tor infrastructure, making decryption impossible without access to the operator's key server. Ransom notes follow the naming pattern '_ONEMLI_NOT_' (Turkish for 'Important Notice') followed by randomized hex strings (e.g., '_ONEMLI_NOT_F3E4CFA185D1AEAE.TXT'). Victims are instructed to contact operators via qTox peer-to-peer messaging or Tor Browser .onion sites, with ransom demands in the $200-$400 range.
The Adwind RAT component provides extensive post-compromise capabilities including keylogging, screen and webcam capture, audio recording, clipboard monitoring, credential harvesting from browsers and files, and arbitrary file download/execution. Persistence is achieved through registry Run key modification at HKCU\Software\Microsoft\Windows\CurrentVersion\Run, ensuring the malware survives system reboots.
The campaign reflects a broader trend of ransomware ecosystem fragmentation following high-profile gang disruptions, with smaller operators adopting commodity RATs and targeting specific geographic regions with low-value, high-volume monetization strategies. The use of Adwind as a malware-as-a-service platform significantly lowers the barrier to entry for the threat actors behind JanaWare.
MITRE ATT&CK techniques used in TL-2026-0368
Exfiltration
Defense Evasion
T1027 Obfuscated Files or Information; T1027.002 Obfuscated Files or Information: Software Packing; T1070.004 Indicator Removal: File Deletion
Collection
T1056.001 Input Capture: Keylogging; T1113 Screen Capture; T1115 Clipboard Data
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File
Discovery
T1082 System Information Discovery; T1518.001 Software Discovery: Security Software Discovery; T1614.001 System Location Discovery: System Language Discovery
Command and Control
T1105 Ingress Tool Transfer; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1571 Non-Standard Port; T1572 Protocol Tunneling
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Credential Access
T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Initial Access
T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link
defense-impairment
Affected products and versions in JanaWare Ransomware
Remediation for JanaWare Ransomware
Immediate actions
- Block elementsplugin.duckdns.org at DNS and proxy level
- Block IP 151.243.109.115 at perimeter firewall
- Block TCP ports 49152-49153 for outbound connections to unknown destinations
- Block execution of JAR files from user-writable directories via application control policies
- Scan endpoints for presence of javaw.exe running from AppData directories
- Search for registry Run keys referencing javaw.exe with -jar parameters
- Quarantine any endpoints with _ONEMLI_NOT_ ransom notes
Workarounds
- Restrict Java Runtime Environment installation to systems that require it
- Configure Windows Firewall to block outbound javaw.exe connections
- Disable Java Web Start and JAR file associations on endpoints that do not require Java applications
- Block Tor exit node IPs at the network perimeter
Longer-term hardening
- Deploy EDR with behavioral detection for Java-based malware and ransomware pre-encryption activity
- Implement email gateway filtering for JAR file attachments and Google Drive phishing lures
- Enable tamper protection for Microsoft Defender to prevent programmatic disabling
- Configure Volume Shadow Copy protection to prevent unauthorized deletion
- Implement network segmentation to limit lateral movement from compromised endpoints
- Deploy DNS filtering to block dynamic DNS services (duckdns.org) used for C2
- Enable PowerShell script block logging and constrained language mode
- Maintain offline backups with regular testing of restoration procedures
Timeline of JanaWare Ransomware
- Earliest observed JanaWare campaign activity based on telemetry and sample compilation dates
- Check Point Research publishes analysis of Turkish Adwind campaign with similar geofencing and targeting patterns, indicating established Adwind abuse ecosystem targeting Turkey
- Most recent JanaWare/Adwind samples compiled, confirming continued development and active operations
- CYFIRMA includes JanaWare activity in monthly ransomware tracking report for January 2026
- Multiple cybersecurity news outlets including The Record, GBHackers, Cyber Security News, and The Cyber Express publish coverage of JanaWare threat
- Acronis Threat Research Unit publishes comprehensive technical analysis of JanaWare ransomware campaign with detailed IOCs and kill chain analysis
- Threadlinqs Intelligence Platform publishes threat intelligence report TL-2026-0368 with full MITRE mapping, IOCs, and detection coverage
- As of 2026-05-29, JanaWare remains an active, undisrupted ransomware campaign: Acronis TRU's April 2026 disclosure and follow-on reporting confirm samples compiled through Nov 2025 and live C2 (DuckDNS/Tor), with no takedown, arrests, or decryptor. As a phishing-delivered Adwind/jRAT threat with no CVE, there is no patch and the tooling/technique stay fully viable.
Sources cited for JanaWare Ransomware
- Acronis TRU: New JanaWare ransomware targets Turkey via Adwind RAT
- Cyber Security News: New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT
- GBHackers: JanaWare Ransomware Hits Turkish Users via Customized Adwind RAT
- The Record: New JanaWare ransomware targeting Turkish citizens as cybercriminal ecosystem fragments
- The Cyber Express: JanaWare Ransomware Hits Turkish Users In Phishing Attack
- CyberPress: Customized Adwind RAT Delivers JanaWare Ransomware To Turkish Victims
- MITRE ATT&CK: jRAT (S0283)
- Malpedia: AdWind Malware Family
- Check Point Research: The Turkish Rat - Evolved Adwind in a Massive Ongoing Phishing Campaign
- CYFIRMA: Tracking Ransomware January 2026
Detection coverage for TL-2026-0368
As of 2026-04-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0368 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.