Threat reportRansomwareTL-2026-0368

JanaWare Ransomware: Polymorphic Java RAT Campaign Targeting Turkey via Customized Adwind

highACTIVE

JanaWare Ransomware (TL-2026-0368), also tracked as JanaWare, is a high-severity ransomware operation, first published 2026-04-15. It is attributed to JanaWare Operators (Russia) with low confidence, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1020, T1027, T1027.002), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
1JanaWare Operators
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-0368

Threat ID
TL-2026-0368
Also known as
JanaWare
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
JanaWare Operators
Attribution confidence
LOW
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
small-medium-business, consumer, retail, services
Target regions
Turkey
Detection rules
9
Indicators of compromise
18

Malware and tooling in JanaWare Ransomware

Malware and tooling: AdWind, JanaWare, Adwind RAT v3.0+, Allatori Java Obfuscator, Stringer Java Obfuscator

How JanaWare Ransomware works

New ransomware module tracked as JanaWare, delivered via a customized Adwind Java RAT with polymorphic characteristics. The campaign uses Stringer and Allatori obfuscators with a FilePumper class that generates unique file hashes per infection. Geofenced exclusively to Turkey via locale and IP checks, employing AES encryption with keys exfiltrated over Tor, and demanding $200-$400 ransoms via qTox.

JanaWare is a ransomware module deployed through a customized variant of the Adwind (jRAT) remote access trojan, specifically targeting Turkish users and small-to-medium businesses. The campaign has been active since at least 2020, with the most recent compiled samples dating to November 2025 and continued infrastructure activity confirmed through April 2026.

The infection chain begins with phishing emails crafted in Turkish, directing victims to Google Drive links hosting malicious Java Archive (JAR) files. Upon execution via javaw.exe (Java Runtime Environment 1.8.0_451), the Adwind RAT establishes command-and-control communication with elementsplugin.duckdns.org on TCP ports 49152 and 49153. The C2 handshake uses the distinctive prefix 'JANAWARE', from which the ransomware derives its name.

A defining characteristic of this campaign is its polymorphic evasion capability. The malware contains a class named FilePumper that performs self-modification by injecting random content into the JAR archive during installation, inflating the file size by tens of megabytes. This ensures each deployed instance produces a unique file hash (MD5, SHA256), effectively defeating signature-based detection at scale.

The malware employs strict geofencing controls before proceeding with encryption. It verifies: (1) the system locale matches Turkish language/region settings, and (2) the external IP geolocation confirms the country code begins with 'TR'. Only systems passing both checks receive the ransomware payload.

Prior to encryption, JanaWare executes a series of defense-weakening actions via PowerShell and registry commands: disabling Microsoft Defender real-time protection, deleting Volume Shadow Copy Service (VSS) snapshots to prevent recovery, terminating Windows Update services, and enumerating installed antivirus products to identify additional security tools to neutralize.

The ransomware module uses AES encryption for file encryption, with encryption keys transmitted to the C2 server over Tor infrastructure, making decryption impossible without access to the operator's key server. Ransom notes follow the naming pattern '_ONEMLI_NOT_' (Turkish for 'Important Notice') followed by randomized hex strings (e.g., '_ONEMLI_NOT_F3E4CFA185D1AEAE.TXT'). Victims are instructed to contact operators via qTox peer-to-peer messaging or Tor Browser .onion sites, with ransom demands in the $200-$400 range.

The Adwind RAT component provides extensive post-compromise capabilities including keylogging, screen and webcam capture, audio recording, clipboard monitoring, credential harvesting from browsers and files, and arbitrary file download/execution. Persistence is achieved through registry Run key modification at HKCU\Software\Microsoft\Windows\CurrentVersion\Run, ensuring the malware survives system reboots.

The campaign reflects a broader trend of ransomware ecosystem fragmentation following high-profile gang disruptions, with smaller operators adopting commodity RATs and targeting specific geographic regions with low-value, high-volume monetization strategies. The use of Adwind as a malware-as-a-service platform significantly lowers the barrier to entry for the threat actors behind JanaWare.

MITRE ATT&CK techniques used in TL-2026-0368

Exfiltration

T1020 Automated Exfiltration

Defense Evasion

T1027 Obfuscated Files or Information; T1027.002 Obfuscated Files or Information: Software Packing; T1070.004 Indicator Removal: File Deletion

Collection

T1056.001 Input Capture: Keylogging; T1113 Screen Capture; T1115 Clipboard Data

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File

Discovery

T1082 System Information Discovery; T1518.001 Software Discovery: Security Software Discovery; T1614.001 System Location Discovery: System Language Discovery

Command and Control

T1105 Ingress Tool Transfer; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1571 Non-Standard Port; T1572 Protocol Tunneling

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Credential Access

T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Initial Access

T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in JanaWare Ransomware

  • Microsoft — Windows
    Vulnerable versions: Windows 7; Windows 8.1; Windows 10; Windows 11
  • Oracle — Java Runtime Environment
    Vulnerable versions: 1.8.0_451 and earlier

Remediation for JanaWare Ransomware

Immediate actions

  • Block elementsplugin.duckdns.org at DNS and proxy level
  • Block IP 151.243.109.115 at perimeter firewall
  • Block TCP ports 49152-49153 for outbound connections to unknown destinations
  • Block execution of JAR files from user-writable directories via application control policies
  • Scan endpoints for presence of javaw.exe running from AppData directories
  • Search for registry Run keys referencing javaw.exe with -jar parameters
  • Quarantine any endpoints with _ONEMLI_NOT_ ransom notes

Workarounds

  • Restrict Java Runtime Environment installation to systems that require it
  • Configure Windows Firewall to block outbound javaw.exe connections
  • Disable Java Web Start and JAR file associations on endpoints that do not require Java applications
  • Block Tor exit node IPs at the network perimeter

Longer-term hardening

  • Deploy EDR with behavioral detection for Java-based malware and ransomware pre-encryption activity
  • Implement email gateway filtering for JAR file attachments and Google Drive phishing lures
  • Enable tamper protection for Microsoft Defender to prevent programmatic disabling
  • Configure Volume Shadow Copy protection to prevent unauthorized deletion
  • Implement network segmentation to limit lateral movement from compromised endpoints
  • Deploy DNS filtering to block dynamic DNS services (duckdns.org) used for C2
  • Enable PowerShell script block logging and constrained language mode
  • Maintain offline backups with regular testing of restoration procedures

Timeline of JanaWare Ransomware

  • Earliest observed JanaWare campaign activity based on telemetry and sample compilation dates
  • Check Point Research publishes analysis of Turkish Adwind campaign with similar geofencing and targeting patterns, indicating established Adwind abuse ecosystem targeting Turkey
  • Most recent JanaWare/Adwind samples compiled, confirming continued development and active operations
  • CYFIRMA includes JanaWare activity in monthly ransomware tracking report for January 2026
  • Multiple cybersecurity news outlets including The Record, GBHackers, Cyber Security News, and The Cyber Express publish coverage of JanaWare threat
  • Acronis Threat Research Unit publishes comprehensive technical analysis of JanaWare ransomware campaign with detailed IOCs and kill chain analysis
  • Threadlinqs Intelligence Platform publishes threat intelligence report TL-2026-0368 with full MITRE mapping, IOCs, and detection coverage
  • As of 2026-05-29, JanaWare remains an active, undisrupted ransomware campaign: Acronis TRU's April 2026 disclosure and follow-on reporting confirm samples compiled through Nov 2025 and live C2 (DuckDNS/Tor), with no takedown, arrests, or decryptor. As a phishing-delivered Adwind/jRAT threat with no CVE, there is no patch and the tooling/technique stay fully viable.

Sources cited for JanaWare Ransomware

Detection coverage for TL-2026-0368

As of 2026-04-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0368 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats