216.73.216.6

New ransomware targets Turkey via Adwind RAT

· Published 15/04/2026 17:04 · Modified 15/04/2026 16:29

Export JSON

Essential information

Published
15/04/2026 17:04
Modified
15/04/2026 16:29
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
adwind janaware phishing campaign
Tags
2026-04-15 adwind janaware phishing campaign
Related entities
3 indicators, 3 observables, 19 techniques (mitre), 4 malware, 1 others

Description

A threat cluster has been identified leveraging a customized (Java RAT) variant with polymorphic characteristics to deliver ransomware. The campaign specifically targets Turkish users through geofencing mechanisms that check system locale and external IP geolocation. Active since at least 2020, the operation primarily affects home users and small to medium-sized businesses. Initial access occurs via phishing emails with malicious Java archives distributed through Google Drive links. The ransomware employs AES encryption and communicates over Tor networks, demanding modest ransoms between $200-$400. The malware uses multiple obfuscation techniques including Stringer and Allatori obfuscators, implements file pumping for polymorphism, and disables Windows security features before encryption. Victims are instructed to contact attackers through qTox or dedicated Tor onion sites.

External references