# JanaWare Ransomware: Polymorphic Java RAT Campaign Targeting Turkey via Customized Adwind

> New ransomware module tracked as JanaWare, delivered via a customized Adwind Java RAT with polymorphic characteristics. The campaign uses Stringer and Allatori obfuscators with a FilePumper class that generates unique file hashes per infection. Geofenced exclusively to Turkey via locale and IP checks, employing AES encryption with keys exfiltrated over Tor, and demanding $200-$400 ransoms via qTox.

- **Published:** 2026-04-15T12:00:00Z
- **Last reviewed:** 2026-04-15T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0368
- **ID:** TL-2026-0368
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** JanaWare Operators (Russia)
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

JanaWare is a ransomware module deployed through a customized variant of the Adwind (jRAT) remote access trojan, specifically targeting Turkish users and small-to-medium businesses. The campaign has been active since at least 2020, with the most recent compiled samples dating to November 2025 and continued infrastructure activity confirmed through April 2026.

The infection chain begins with phishing emails crafted in Turkish, directing victims to Google Drive links hosting malicious Java Archive (JAR) files. Upon execution via javaw.exe (Java Runtime Environment 1.8.0_451), the Adwind RAT establishes command-and-control communication with elementsplugin.duckdns.org on TCP ports 49152 and 49153. The C2 handshake uses the distinctive prefix 'JANAWARE', from which the ransomware derives its name.

A defining characteristic of this campaign is its polymorphic evasion capability. The malware contains a class named FilePumper that performs self-modification by injecting random content into the JAR archive during installation, inflating the file size by tens of megabytes. This ensures each deployed instance produces a unique file hash (MD5, SHA256), effectively defeating signature-based detection at scale.

The malware employs strict geofencing controls before proceeding with encryption. It verifies: (1) the system locale matches Turkish language/region settings, and (2) the external IP geolocation confirms the country code begins with 'TR'. Only systems passing both checks receive the ransomware payload.

Prior to encryption, JanaWare executes a series of defense-weakening actions via PowerShell and registry commands: disabling Microsoft Defender real-time protection, deleting Volume Shadow Copy Service (VSS) snapshots to prevent recovery, terminating Windows Update services, and enumerating installed antivirus products to identify additional security tools to neutralize.

The ransomware module uses AES encryption for file encryption, with encryption keys transmitted to the C2 server over Tor infrastructure, making decryption impossible without access to the operator's key server. Ransom notes follow the naming pattern '_ONEMLI_NOT_' (Turkish for 'Important Notice') followed by randomized hex strings (e.g., '_ONEMLI_NOT_F3E4CFA185D1AEAE.TXT'). Victims are instructed to contact operators via qTox peer-to-peer messaging or Tor Browser .onion sites, with ransom demands in the $200-$400 range.

The Adwind RAT component provides extensive post-compromise capabilities including keylogging, screen and webcam capture, audio recording, clipboard monitoring, credential harvesting from browsers and files, and arbitrary file download/execution. Persistence is achieved through registry Run key modification at HKCU\Software\Microsoft\Windows\CurrentVersion\Run, ensuring the malware survives system reboots.

The campaign reflects a broader trend of ransomware ecosystem fragmentation following high-profile gang disruptions, with smaller operators adopting commodity RATs and targeting specific geographic regions with low-value, high-volume monetization strategies. The use of Adwind as a malware-as-a-service platform significantly lowers the barrier to entry for the threat actors behind JanaWare.

## MITRE ATT&CK

- T1566.002 Phishing: Spearphishing Link
- T1566.001 Phishing: Spearphishing Attachment
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1027 Obfuscated Files or Information
- T1027.002 Obfuscated Files or Information: Software Packing
- T1685 Disable or Modify Tools
- T1070.004 Indicator Removal: File Deletion
- T1082 System Information Discovery
- T1614.001 System Location Discovery: System Language Discovery
- T1518.001 Software Discovery: Security Software Discovery
- T1056.001 Input Capture: Keylogging
- T1113 Screen Capture
- T1115 Clipboard Data
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1571 Non-Standard Port
- T1572 Protocol Tunneling
- T1105 Ingress Tool Transfer
- T1568.002 Dynamic Resolution: Domain Generation Algorithms
- T1020 Automated Exfiltration
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery

## Sources

- [Acronis TRU: New JanaWare ransomware targets Turkey via Adwind RAT](https://www.acronis.com/en/tru/posts/new-janaware-ransomware-targets-turkey-via-adwind-rat/)
- [Cyber Security News: New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT](https://cybersecuritynews.com/new-janaware-ransomware-targets-turkish-users/)
- [GBHackers: JanaWare Ransomware Hits Turkish Users via Customized Adwind RAT](https://gbhackers.com/janaware-ransomware/)
- [The Record: New JanaWare ransomware targeting Turkish citizens as cybercriminal ecosystem fragments](https://therecord.media/new-janaware-ransomware-targeting-turkey)
- [The Cyber Express: JanaWare Ransomware Hits Turkish Users In Phishing Attack](https://thecyberexpress.com/janaware-ransomware-hits-turkish-users/)
- [CyberPress: Customized Adwind RAT Delivers JanaWare Ransomware To Turkish Victims](https://cyberpress.org/adwind-delivers-janaware-ransomware/)
- [MITRE ATT&CK: jRAT (S0283)](https://attack.mitre.org/software/S0283/)
- [Malpedia: AdWind Malware Family](https://malpedia.caad.fkie.fraunhofer.de/details/jar.adwind)
- [Check Point Research: The Turkish Rat - Evolved Adwind in a Massive Ongoing Phishing Campaign](https://research.checkpoint.com/2020/the-turkish-rat-distributes-evolved-adwind-in-a-massive-ongoing-phishing-campaign/)
- [CYFIRMA: Tracking Ransomware January 2026](https://www.cyfirma.com/research/tracking-ransomware-jan-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0368
