Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomware

JanaWare

JanaWare is a ransomware family used in a geographically focused campaign targeting victims in Turkey, primarily home users and small to medium-sized businesses. Reporting attributes delivery to a customized Java-based Adwind RAT used as a loader and staging mechanism. Initial access is typically via phishing emails that deliver or link to malicious Java archive (JAR) files, including observed chains where Outlook opens a phishing message, Chrome retrieves a Google Drive-hosted payload, and the JAR executes via javaw.exe.

The malware is heavily obfuscated and polymorphic. Reported protections include the Java obfuscators Stringer and Allatori, custom class loaders, and a FilePumper component that modifies its own JAR by adding random content, inflating file size and causing different hashes per deployment. Embedded configuration reportedly includes a command-and-control domain, TCP ports, Tor-related paths, a version identifier, persistence-related settings, and a static PASSWORD value used both for initial authentication and for decrypting downloaded payloads.

JanaWare enforces strict geofencing. It checks system locale, language, country settings, and external IP geolocation, and proceeds only when Turkish regional indicators are present, including country code beginning with TR. If checks pass, the malware executes PowerShell and registry commands to weaken defenses, including attempts to disable or reduce Microsoft Defender protections, suppress security notifications, remove Volume Shadow Copy recovery mechanisms, hide ransomware protection features, enumerate installed antivirus products, and interfere with endpoint protection integrations.

After preparation, the Adwind-based loader downloads a Java ransomware plugin associated with JanaWare. The ransomware module reportedly communicates exclusively over Tor, uses AES encryption, and can encrypt files across available drives; reporting also states it can delete and exfiltrate files. During C2 handshake it uses the prefix JANAWARE. It drops Turkish-language ransom notes in multiple folders using partially randomized filenames with the fixed prefix ONEMLI_NOT. Victims are instructed to contact the operators via qTox and in some cases through a Tor Browser-accessible .onion site. Observed ransom demands were approximately $200 to $400, consistent with a low-value, high-volume extortion model.

The campaign has been assessed as active since at least 2020, with reporting indicating infrastructure remained active as late as November 2025. High-confidence infrastructure and sample indicators mentioned in the content include elementsplugin.duckdns.org resolving to 151.243.109.115 on ports 49152 and 49153; sample hash 4f0444e11633a331eddb0deeec17fd69 associated with Adwind RAT; and sample hash b2d5bbf7746c2cb87d5505ced8d6c4c6 associated with the JanaWare ransomware module.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

18 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence6

The analysis indicates that the campaign relies on email-based phishing to initiate the attack, leading users to download a malicious payload that ultimately results in ransomware execution.

T1566.002Spearphishing LinkEvidence4

organizations in Turkey especially small businesses and home users should treat unsolicited emails linking to Google Drive downloads with extreme caution

Execution

2 techniques
T1059.001PowerShellEvidence3

After confirming the victim is located in Turkey, the malware turns off security defenses using PowerShell commands.

T1204.002Malicious FileEvidence2

A JAR file is downloaded and executed. Once executed via Java (javaw.exe), the malware establishes a foothold on the system.

Persistence

1 technique
T1112Modify RegistryEvidence2

Once the geofencing checks pass, the malware executes a series of PowerShell and registry commands designed to weaken the system’s defenses before encryption begins.

Stealth

5 techniques
T1027Obfuscated Files or InformationEvidence4

JanaWare uses multiple layers of obfuscation to hinder analysis. Researchers observed the use of publicly available tools like Stringer and Allatori, combined with custom class loaders that complicate reverse engineering.

T1027.002Software PackingEvidence1

The malware modifies its own JAR file using a component called “FilePumper,” inserting random data to generate unique file hashes for each infection.

T1070.004File DeletionEvidence2

Remove recovery mechanisms such as Microsoft Volume Shadow Copy Service (VSS).

T1497Virtualization/Sandbox EvasionEvidence1

Throughout this stage, both the RAT and the ransomware use simple but effective detection-evasion tactics such as common process names, basic anti-analysis checks, and environment awareness to limit their exposure to automated analysis systems.

T1497.001System ChecksEvidence4

Crucially, JanaWare enforces execution constraints based on system locale and IP geolocation, ensuring it only operates on systems within Turkey.

Defense Impairment

1 technique
T1112Modify RegistryEvidence2

Once the geofencing checks pass, the malware executes a series of PowerShell and registry commands designed to weaken the system’s defenses before encryption begins.

Discovery

3 techniques
T1082System Information DiscoveryEvidence2

Enumerate installed antivirus products.

T1497Virtualization/Sandbox EvasionEvidence1

Throughout this stage, both the RAT and the ransomware use simple but effective detection-evasion tactics such as common process names, basic anti-analysis checks, and environment awareness to limit their exposure to automated analysis systems.

T1497.001System ChecksEvidence4

Crucially, JanaWare enforces execution constraints based on system locale and IP geolocation, ensuring it only operates on systems within Turkey.

Command and Control

3 techniques
T1071Application Layer ProtocolEvidence2

Additionally, the malware contains hardcoded configuration data, including command-and-control (C2) infrastructure, authentication tokens, and TOR network settings for anonymized communication.

T1090.003Multi-hop ProxyEvidence4

It also includes references to TOR-related paths and components, indicating that the malware can route over the TOR network... The module relies exclusively on Tor for command-and-control (C2) communication

T1105Ingress Tool TransferEvidence2

The ransomware then downloads and runs its encryption module, which uses AES encryption and transmits the key directly to the C2 server over Tor, making file recovery without that key virtually impossible.

Impact

2 techniques
T1486Data Encrypted for ImpactEvidence5

This module is also implemented in Java, and it is responsible for encrypting files across all available drives... Based on static analysis of the Java classes, the ransomware employs AES encryption

T1490Inhibit System RecoveryEvidence1

These actions include: Removing Volume Shadow Copies to prevent recovery.

Other

2 techniques
T1562Impair DefensesEvidence4

After confirming the victim is located in Turkey, the malware turns off security defenses using PowerShell commands.

T1562.001Disable or Modify ToolsEvidence1

These actions include: Disabling Microsoft Defender and security notifications. Disabling Windows Update and ransomware protections. Interfering with installed antivirus solutions.

INDICATORS OF COMPROMISE

IOCs tracked for this family

5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app17 days ago
ip.v4●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app2 months ago
hash.md5●●●●●●●●●●●●View more in app2 months ago
hash.md5●●●●●●●●●●●●View more in app2 months ago
ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
Apr 20, 2026
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT

Ransomware targeting home users and SMBs in Turkey. It is selectively dropped after initial compromise, performs geofencing for Turkish systems, weakens defenses via PowerShell and registry changes, encrypts files with AES, sends the key to C2 over Tor, and drops Turkish-language ransom notes.

Read more
gbhackersNews
Apr 20, 2026
JanaWare Ransomware Hits Turkish Users via Tailored Adwind RAT

Regionally focused ransomware targeting users in Turkey. It uses phishing emails and Google Drive-hosted JAR payloads, applies geofencing checks for Turkish locale indicators, disables security defenses via PowerShell, downloads a Java-based ransomware module, encrypts files with AES, and communicates with C2 over Tor.

Read more
scworldNews
Apr 15, 2026
New JanaWare ransomware targets Turkey with low-value, high-volume attacks | brief | SC Media

Localized ransomware strain targeting victims in Turkey, encrypting victim data and using low ransom demands to support a high-volume profit model. It applies execution constraints based on system locale and IP geolocation and delivers ransom notes in Turkish.

Read more
cyber security newsNews
Apr 15, 2026
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT - Cyber Security News

Ransomware targeting users in Turkey. It is selectively deployed after reconnaissance via a customized Adwind RAT, then encrypts documents, archives, images, and databases, renames files with a campaign-specific extension, and drops a ransom note with Turkish-language instructions.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching5

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping18

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.