Ransomware Research
Bam! Ransomware
Bam! is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on August 1, 2017, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: Bam-2021.
Quick Facts
- Ransomware Family
- Bam!
- First Seen
- August 1, 2017
- Known Aliases
- Bam-2021
How Bam! Ransomware Works
Targeted Files
HKEY_CURRENT_USER\Software\Rs IsEncrypt key (1 means encryption finished) Should start with win7 compatibility
File Encryption Patterns
Bam! modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..bam!
Ransom Note and Payment Demands
After encrypting files, Bam! displays ransom notes demanding payment for file recovery:
Ransom message:
notes/108.bmp
Note locations:
Desktop
Technical Indicators
Associated Executable Files
The following executable files are associated with Bam! ransomware:
Mau bao cao 2.docx.exe
26b9b4849dbb611e05e8e2cacf0fe746_black
bam_ransomware.exe
ransomware.exe_
Elastio Can Help You
Don't let Bam! ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This Bam! ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Bam!.
Last updated: July 30, 2025