×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Acronis
  • Acronis TRU identifies JanaWare, a new ransomware targeting Turkey via Adwind RAT

Customer Press Room

Acronis TRU identifies JanaWare, a new ransomware targeting Turkey via Adwind RAT

by Grandangolo Communications / Tuesday, 14 April 2026 / Published in Acronis

Acronis Threat Research Unit (TRU) ha New targeted, low-profile ransomware identified that uses advanced techniques such as obfuscation, dynamic modules and polymorphism to avoid detection

Acronis, global leader in the protection informatica, identified JanaWare, a new ransomware targeting Turkey via Adwind RAT. The Acronis Threat Research Unit (TRU) investigation began with the analysis of a custom variant of the Adwind RAT malware, suspected of being linked to ransomware activity. After collecting several JAR archives from VirusTotal, anomalous behavior of one of them emerged: while running in the lab, the sample dropped a ransom note in the Turkish language. In the note, the hackers invite victims to contact them through secure, private channels, such as qTox, a decentralized open source application with end-to-end encryption. In some campaigns, however, the use of the Tor browser was required to access dedicated .onion sites.

The infection sequence was reconstructed through the analysis of EDR telemetry. The attack begins with an email phishing campaign that tricks the user into downloading a malicious file. Specifically, the user opens an email in Outlook that launches Chrome to access a Google Drive link, from which a JAR file is downloaded and executed via javaw.exe.

Advanced techniques used to avoid detection

JanaWare is a low-profile, targeted ransomware operation that used advanced techniques to avoid detection. Although its prolonged activity remained little visible thanks to the limited geographical focus, the threat was, however, detected and blocked by Acronis EDR/XDR solutions.

Below are the advanced techniques used by JanaWare:

Obfuscation
Although Java bytecode is relatively easy to decompile, this becomes significantly more difficult when obfuscation is applied. Malware authors use several techniques, including custom class loaders. During the analysis, two publicly available obfuscators were identified: Stringer and Allatori. Fortunately, the open source java-deobfuscator project provides useful tools for bypassing the protections implemented by both.

Polymorphism
The malware also contains a class called FilePumper, whose purpose is to perform self-modification. Instead of simply copying itself to the target system during installation, the malware adds random content to its JAR archive, increasing its size by tens of megabytes. As a result, each deployed instance becomes unique, generating a different file hash on each infected machine. This technique hinders hash-based detection and signature comparison.

Configuration
At the beginning of the initialization process, the malware loads a set of hard-coded configuration parameters built into Java that define key aspects of execution behavior and communications. The configuration specifies the command-and-control (C2) infrastructure, including a domain and two TCP ports, used by the malware to establish and maintain the control channel. It also includes references to TOR-related routes and components, indicating that the malware can route traffic through this network. In this context, TOR is not related to payment mechanisms, but rather to network obfuscation and possible anonymous communications or data exfiltration. The configuration also contains a version identifier, suggesting that the malware is maintained as part of an evolving codebase, and a parameter (STARTUP_TYPE) that defines the persistence mechanism.

Geofencing

The malware is designed to exclusively target systems in Türkiye. Checks language, locale and IP geolocation, running only if the country code is “TR”. This approach reduces exposure and indicates targeted targeting. Overall, this geofencing mechanism suggests that the malware is not opportunistic, but part of a targeted campaign with a precise geographic scope, using location controls to both evade detection and ensure it operates only in intended environments.

File encryption

If the infected system passes geofencing checks, the malware initially weakens defenses by executing a series of PowerShell commands and registry changes. In particular, the malware disables defenses such as Microsoft Defender, suppresses security notifications, deletes Shadow Copies, blocks updates, hides ransomware protection features and detects installed antiviruses. Next download a module a ransomware plugin designed to work with this customized version of Adwind RAT. This module, also implemented in Java and responsible for encrypting files on all available drives, uses TOR exclusively for communication with the command and control server (C2) and is capable of not only encrypting files, but also deleting and exfiltrating them. During the handshake phase with C2 server, it uses the prefix JANAWARE, which is why it was named JanaWare Ransomware. After encryption, it drops a ransom note (“ONEMLI NOT” or “Important Note”) in multiple folders. Recovering files without access to the C2 server is highly unlikely.

For further information on the full investigation please see this link.

About Grandangolo Communications

What you can read next

The Acronis ecosystem touches 300 technological additions and opens to new opportunities for MSP and ISV
Acronis identifies new global campaigns linked to the North Korean groups Lazarus and Kimsuky
Acronis Esg Report 2024: sustainable growth, leadership in cyber security and social responsibility

Customer Press Room

  • Arrow Electronics has been awarded by Equinix as Distributor of the Year 2025 for the EMEA region

    Arrow Electronics, a global supplier of technology...
  • SentinelOne makes the Purple AI Agentic Investigation solution available to all customers, bringing the latest generation AI directly into the SOC

    The investigations, started autonomously and without need...
  • Acronis TRU reveals the ongoing evolution of the INC ransomware group

    A recent report published by Acronis Threat ...
  • ESET Research investigates the Gentlemen ransomware author group and its defense evasion tools

    The Gentlemen Group develops, maintains and supplies...
  • Imprivata presents the Agentic Identity Management solution to protect and govern the access of AI agents

    Imprivata, a leading company in Ac...

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • abstract
  • Abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP