.ADAME

ADAME File

Adame Ransomware Encrypted File
Ask a question
QUICK ANSWER

An .adame file is a normal document, photo, or other file that has been encrypted and held for ransom by the Adame ransomware, a strain of the Phobos family. You cannot open it: the contents are scrambled with AES-256 and the key is held by the attackers. There is no free decryptor for this variant, so the only clean recovery is to remove the malware with an antivirus tool and restore your files from a backup made before the infection.

Developer: Unknown cybercriminals (Phobos ransomware operators) Category: Encoded Files MIME: application/octet-stream
OPENS ON Windows
Related: .CRYPT · .SDOC · .AXX · .REM

On this page

19k+ extensions indexed
Last reviewed Jul 7, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the ADAME file format?

An .adame file is an ordinary file, such as a document or photo, that has been encrypted by the Adame ransomware. Adame is a strain of the Phobos ransomware family, first documented in 2019 by researchers Amigo-A and Michael Gillespie. It does not create these files on purpose; it hijacks files you already have.

When the malware runs, it renames each victim file to a long pattern that bundles the original name, a unique ID, an attacker email in brackets, and the suffix. A file called report.pdf becomes something like report.pdf.id[1E857D00-2275].[[email protected]].adame. Under the hood, Phobos encrypts the file data with AES-256 using a random per-file key, then wraps that key with an RSA-1024 public key baked into the sample. Large files are only partially encrypted to speed up the attack. Two ransom notes, info.hta and info.txt, are dropped to explain the payment demand.

Security & safety

RISK: HIGH

The .adame extension is the direct result of an active ransomware infection. The encrypted files themselves are inert data, but their presence means the Adame/Phobos malware ran on the machine and may still be present. Phobos strains delete shadow copies, disable recovery, and can spread across network shares and RDP connections. Isolate the machine from the network, run a reputable anti-malware scan to remove the payload, and restore data only from a clean backup. Do not pay the ransom; there is no guarantee of recovery and it funds further attacks.

Format details

in a nutshell
FULL NAMEAdame Ransomware Encrypted Fileaka Adame Virus, Adame Phobos Ransomware
DEVELOPERUnknown cybercriminals (Phobos ransomware operators)since 2019
MIME TYPEapplication/octet-stream
TYPEEncrypted binary produced by ransomware
This extension is also used by…
  • Adame (Amnesia) ransomware - An older, separate ransomware based on the Amnesia/Globe Imposter family also appended .adame. It is distinct from the dominant Phobos-based Adame and was documented in earlier 2019 removal guides.

Programs that open ADAME files

Windows5 apps
Malwarebytes Freemium Run a full scan to detect and remove the Adame/Phobos payload so it stops encrypting new files; note that removal does not decrypt files already carrying the .adame extension.
Emsisoft Anti-Malware Freemium Scan the system to quarantine the ransomware and then check the Emsisoft decryptor catalog to confirm whether a free tool has appeared for this variant.
ID Ransomware Free Upload an .adame file and a ransom note to confirm the exact ransomware family and learn whether any decryption help is currently listed.
Kaspersky NoRansom Decryptors Free Check the decryptor list for a matching tool; if one becomes available it can rebuild the original file from the .adame copy.
Windows File History / System Restore Built-in After the malware is removed, recover clean copies of affected files from File History, a previous backup, or a restore point created before the infection.

Technical details

deep spec
EncodingAES-256 symmetric encryption of file data; per-file random key and IV
ContainerOriginal file wrapped with appended encrypted payload
EncryptionHybrid cryptosystem: file bytes encrypted with AES-256, and the AES key encrypted with RSA-1024 using a hardcoded public key, then stored at the end of the file. Large files are only partially encrypted in selected segments to speed up the attack.
Typical sizeSlightly larger than the original file due to the appended encrypted key block and metadata
StructureEncrypted original content followed by an RSA-protected key blob. The filename is rewritten to pattern <original>.id[<victim-id>].[<email>].adame, for example document.pdf.id[1E857D00-2275].[[email protected]].adame.
IntegrityNone; no recovery checksum is stored for the victim
PlatformsWindows
NotesDropped alongside two ransom notes: info.hta (pop-up HTML application) and info.txt. Contact addresses seen include [email protected], [email protected], [email protected] and [email protected]. Phobos deletes shadow copies and disables recovery to prevent restoration. No free decryptor exists for the Phobos-based Adame variant.
Released2019

ADAME conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with ADAME files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about ADAME files.

Frequently asked questions

How do I open an .adame file?
You cannot open it in its encrypted state. The file's contents were scrambled by the Adame ransomware and require a decryption key held by the attacker. Your practical options are to restore the original file from a backup or wait to see whether a free decryptor is released for this Phobos variant.
Is there a free decryptor for .adame files?
As of now, no free decryption tool exists for the Phobos-based Adame variant. Check ID Ransomware, Emsisoft, and Kaspersky NoRansom periodically, because decryptors sometimes appear later when researchers find a flaw or seize a key server.
Should I pay the ransom to recover my files?
Security vendors and FileInfo advise against it. Paying does not guarantee you receive a working key, it marks you as a paying target for future attacks, and it funds the criminals. Focus on removing the malware and restoring from backup.
Can I recover .adame files by renaming them?
No. Removing the .adame extension does not decrypt anything; the bytes are still encrypted with AES-256. Renaming only changes the label, not the content.
How did my computer get infected with Adame?
Phobos strains like Adame usually arrive through exposed or brute-forced Remote Desktop connections, malicious email attachments, fake software cracks, and trojan downloaders. Securing RDP, patching, and using strong passwords reduces the risk.
What are the info.hta and info.txt files that appeared?
Those are the ransom notes dropped by Adame. info.hta opens a pop-up window with payment instructions and attacker email addresses, and info.txt is a short plain-text version of the same demand. They are not needed to recover your data and can be deleted after cleanup.

References

1FileInfo - .ADAME filefileinfo.com
2PCrisk - Adame Ransomware removal and recoverywww.pcrisk.com

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.BINCD/DVD Disc Image (BIN/CUE)
5.EXEWindows Executable (Portable Executable)
6.RPMSGRestricted Permission Message
7.MDMarkdown Document
8.DATProgram Data File (generic)
9.NOMEDIAAndroid No-Media Marker File
10.TXTPlain Text File

Related extensions

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z