What is the ADAME file format?
An .adame file is an ordinary file, such as a document or photo, that has been encrypted by the Adame ransomware. Adame is a strain of the Phobos ransomware family, first documented in 2019 by researchers Amigo-A and Michael Gillespie. It does not create these files on purpose; it hijacks files you already have.
When the malware runs, it renames each victim file to a long pattern that bundles the original name, a unique ID, an attacker email in brackets, and the suffix. A file called report.pdf becomes something like report.pdf.id[1E857D00-2275].[[email protected]].adame. Under the hood, Phobos encrypts the file data with AES-256 using a random per-file key, then wraps that key with an RSA-1024 public key baked into the sample. Large files are only partially encrypted to speed up the attack. Two ransom notes, info.hta and info.txt, are dropped to explain the payment demand.
Security & safety
RISK: HIGHThe .adame extension is the direct result of an active ransomware infection. The encrypted files themselves are inert data, but their presence means the Adame/Phobos malware ran on the machine and may still be present. Phobos strains delete shadow copies, disable recovery, and can spread across network shares and RDP connections. Isolate the machine from the network, run a reputable anti-malware scan to remove the payload, and restore data only from a clean backup. Do not pay the ransom; there is no guarantee of recovery and it funds further attacks.
Format details
in a nutshell- Adame (Amnesia) ransomware - An older, separate ransomware based on the Amnesia/Globe Imposter family also appended
.adame. It is distinct from the dominant Phobos-based Adame and was documented in earlier 2019 removal guides.
Programs that open ADAME files
.adame extension. .adame file and a ransom note to confirm the exact ransomware family and learn whether any decryption help is currently listed. .adame copy. Technical details
deep spec| Encoding | AES-256 symmetric encryption of file data; per-file random key and IV |
| Container | Original file wrapped with appended encrypted payload |
| Encryption | Hybrid cryptosystem: file bytes encrypted with AES-256, and the AES key encrypted with RSA-1024 using a hardcoded public key, then stored at the end of the file. Large files are only partially encrypted in selected segments to speed up the attack. |
| Typical size | Slightly larger than the original file due to the appended encrypted key block and metadata |
| Structure | Encrypted original content followed by an RSA-protected key blob. The filename is rewritten to pattern <original>.id[<victim-id>].[<email>].adame, for example document.pdf.id[1E857D00-2275].[[email protected]].adame. |
| Integrity | None; no recovery checksum is stored for the victim |
| Platforms | Windows |
| Notes | Dropped alongside two ransom notes: info.hta (pop-up HTML application) and info.txt. Contact addresses seen include [email protected], [email protected], [email protected] and [email protected]. Phobos deletes shadow copies and disables recovery to prevent restoration. No free decryptor exists for the Phobos-based Adame variant. |
| Released | 2019 |
ADAME conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about ADAME files.
Frequently asked questions
How do I open an .adame file?
Is there a free decryptor for .adame files?
Should I pay the ransom to recover my files?
Can I recover .adame files by renaming them?
.adame extension does not decrypt anything; the bytes are still encrypted with AES-256. Renaming only changes the label, not the content.