- Home
- Detectable Ransomware
- FarAttack
Ransomware Research
FarAttack Ransomware
FarAttack is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on January 1, 2022, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: Bomani, BomCrypt, IThelp02, IThelp01.
Quick Facts
- Ransomware Family
- FarAttack
- First Seen
- January 1, 2022
- Known Aliases
- BomaniBomCryptIThelp02IThelp01
How FarAttack Ransomware Works
File Encryption Patterns
FarAttack modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..farattack
..[Bomani@Email.Com]
..marlock011
..chipslock
..Chuklock
..faratacks
..farataks
Ransom Note and Payment Demands
After encrypting files, FarAttack displays ransom notes demanding payment for file recovery:
How_to_recovery.txt
Ransom message:
notes/How_to_recovery.txt
Note locations:
EveryFolder
Read Me!.hTa
Ransom message:
notes/Read Me!.hTa
Note locations:
EveryFolder
how_to_back_files.html
Ransom message:
notes/how_to_back_files.html
Note locations:
EveryFolder
Technical Indicators
Associated Executable Files
The following executable files are associated with FarAttack ransomware:
bomani2.exe
ML011s.exe
2.exe
new bomani.exe
FAs.exe
Elastio Can Help You
Don't let FarAttack ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This FarAttack ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like FarAttack.
Last updated: July 30, 2025