New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments
好的,我现在需要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100字以内,不需要特定的开头,直接描述文章内容。 首先,我得通读整篇文章,抓住主要信息。文章讲的是一个名为JanaWare的勒索软件,由网络安全公司Acronis报告。这个勒索软件自2020年起活跃,主要针对土耳其的个人和中小企业。攻击者通过钓鱼邮件传播恶意Java档案,利用Adwind恶意软件作为初始入侵手段。勒索金额较低,在200到400美元之间,采用高量低额策略。此外,该软件通过系统语言和地理位置限制只影响土耳其用户,这使得国际安全研究人员难以分析。 接下来,我需要将这些关键点浓缩到100字以内。确保涵盖目标群体、攻击方式、勒索金额、地域限制以及影响范围等信息。 可能的结构是:介绍JanaWare及其目标群体,说明攻击手段和勒索金额,提到地域限制带来的影响。 现在开始组织语言: “文章指出,名为JanaWare的勒索软件自2020年起活跃于土耳其地区,主要针对个人及中小企业。攻击者通过钓鱼邮件传播恶意Java档案,并利用Adwind恶意软件进行初始入侵。勒索金额较低,在200至400美元之间。” 这样已经涵盖了主要信息,并且控制在100字以内。 </think> 文章指出,名为JanaWare的勒索软件自2020年起活跃于土耳其地区,主要针对个人及中小企业。攻击者通过钓鱼邮件传播恶意Java档案,并利用Adwind恶意软件进行初始入侵。勒索金额较低,在200至400美元之间。 2026-4-14 19:51:7 Author: therecord.media(查看原文) 阅读量:15 收藏

Cybercriminals are using a new ransomware strain called JanaWare to target people in Turkey, according to a new report from cybersecurity firm Acronis.

The researchers said the ransomware operation has been ongoing since 2020 and is associated with a strain of malware that enforces execution constraints based on system locale and external IP geolocation — restricting its activity to systems only in Turkey. 

The ransom demands are very low, hovering around $200 to $400, and Acronis said the hackers are likely opting for a low-value, high-volume approach. 

“Despite evidence suggesting the campaign has been active for several years, its regional focus and relatively small-scale operations likely helped it remain largely unnoticed,” the researchers said. “This case demonstrates how targeted, localized ransomware campaigns can quietly persist in the threat landscape.”

Acronis said the ransomware was typically used against home users and small to medium-sized businesses, with most becoming infected through phishing emails that delivered malicious Java archives. 

The attacks begin with a malware strain called Adwind that contains several features that “hinder detection and analysis, including heavy obfuscation,” Acronis said. 

The ransom notes are written in Turkish and victims are urged to contact the hackers through qTox — a free decentralized chat platform that operates over the Tox peer-to-peer network.

Several analyzed incidents began with an email read through Microsoft Outlook. A Google Drive link in the email triggered the launch of a process that led to the download of a malicious file. Acronis shared one victim report found on a popular public forum confirming that their device files were encrypted by JanaWare after opening an email in Outlook. 

The malware checks the victim’s system location, language and country settings — requiring it to match the Turkish language and location. It will proceed only if the system is in Turkey.

Acronis noted that the focus on Turkey also limits the ability of international security researchers to examine the malware and ransomware. They suggested the specific targeting of Turkish residents “suggests the malware is not opportunistic but instead part of a targeted campaign with a defined geographic scope, using location checks both to evade detection and to ensure it operates only in intended environments.”

The ransom note — which is written in Turkish — is embedded directly within the malware, according to Acronis, providing another example proving the campaign is targeted specifically at Turkish residents. 

The Acronis report comes amid warnings from cybersecurity researchers and law enforcement agencies that the ransomware ecosystem is fragmenting following multiple high-profile disruptions of larger ransomware gangs. 

Last week, the FBI said it identified 63 new ransomware variants that caused more than $32 million in losses last year.

A ransomware report published on April 8 by TRM Labs backed that assessment, finding that while ransomware-linked volume on the blockchain fell from $1.9 billion in 2024 to $1.3 billion in 2025, 93 new ransomware variants emerged last year. That represents a 94% increase compared to 2024. 

But TRM Labs found that ransomware activity was expanding beyond Russia and other regions that do not have extradition treaties with the U.S.

"What we saw in 2025 is a ransomware ecosystem that is more fragmented than ever — but that fragmentation is also creating real vulnerabilities," said Ari Redbord, global head of policy at TRM Labs. "The old playbook of brand-level takedowns is less effective against 161 variants — but for the first time, we're seeing operators in reachable jurisdictions, weaker service layers exposed, and a laundering infrastructure that is far more traceable than actors assume."

Redbord added that the intelligence gained from past leaks and seizures has given law enforcement an opportunity to disrupt ransomware gangs “at a scale we haven't seen before.”

"The question for 2026 is whether that window gets used,” Redbord said.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/new-janaware-ransomware-targeting-turkey
如有侵权请联系:admin#unsafe.sh