HackerFeeds
All ransomware groups

threeam

85 tracked victims
·first seen 2023-08-04·last activity 2026-06-12

Group profile

A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.<BR> > <BR> > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

MITRE ATT&CK TTPs

TA0003

Persistence

  • T1136Create Account

    The threat actor using the 3AM ransomware performed account creation to ensure persistence.

TA0004

Privilege Escalation

  • T1543.003Service Execution

    The threat actor used PsExec to take advantage of a Windows service to escalate from administrator privileges to SYSTEM.

  • T1548.002Bypass User Account Control

    The threat actor may use Cobalt Strike for a series of known techniques to bypass Windows UAC.

TA0005

Defense Evasion

  • T1070.001Clear Windows Event Logs

    The executable clears Windows event logs after its execution.

  • T1562.004Disable or Modify System Firewall Settings

    The threat actor uses commands to set the discovery policy of other hosts on the network, altering the Firewall policy.

TA0007

Discovery

  • T1018Remote System Discovery

    Utilizes Advanced IP Scanner and MASSCAN to discover remote systems.

  • T1135Network Share Discovery

    The threat actor executed reconnaissance commands like 'whoami, netstat, quser, net view, and net share' to enumerate other servers.

  • T1615Group Policy Discovery

    The threat actor used commands like 'gpresult' to dump applied policy settings on the computer for a user (Group Policy).

TA0010

Exfiltration

  • T1048Exfiltration Over Alternative Protocol

    The threat actor used the 'Wput' tool to exfiltrate files from the victim to their own server via FTP.

TA0040

Impact

  • T1486Data Encrypted for Impact

    The ransomware encrypts files and appends the '.threeamtime' extension after encryption.

  • T1490Inhibit System Recovery

    The 3AM ransomware deletes volume shadow copies on the disk and backups through the commands presented in the analysis.

Recent victims

showing 50 of 85
DateWebsite / victimSectorCountry
2026-05-15
jetmachprod.com
jetmachprod.comjetmachprod.com
Manufacturing
2026-04-30
jastrebarsko.hr
jastrebarsko.hrjastrebarsko.hr
Not FoundHR
2026-05-09
palmero.com
palmero.compalmero.com
Not Found
2026-05-11
insamani.com.ar
insamani.com.arinsamani.com.ar
Not FoundAR
2026-06-12
bsynchro.com
bsynchro.combsynchro.com
TechnologyDE
2026-05-14
molinoscabodi.com.ar
molinoscabodi.com.armolinoscabodi.com.ar
Agriculture and Food ProductionAR
2026-05-13
ws.com.br
ws.com.brws.com.br
Business ServicesBR
2026-05-17
consultic.be
consultic.beconsultic.be
Business ServicesBE
2026-06-12
amc.org.au
amc.org.auamc.org.au
Not FoundAU
2026-06-12
agroexportavocados.com
agroexportavocados.comagroexportavocados.com
Agriculture and Food ProductionMX
2026-05-24
hoplongtech.com
hoplongtech.comhoplongtech.com
TechnologyVN
2026-06-12
mgrlaw.com
mgrlaw.commgrlaw.com
Business ServicesUS
2025-06-02
wyomingcountyny.gov
wyomingcountyny.govwyomingcountyny.gov
Public SectorUS
2025-06-25
sequoiadental.com
sequoiadental.comsequoiadental.com
HealthcareUS
2025-08-31
townofnorwell.net
townofnorwell.nettownofnorwell.net
Public SectorUS
2026-05-01
curedentalbeltontx.com
curedentalbeltontx.comcuredentalbeltontx.com
HealthcareUS
2025-08-07
austinplasticandreconstructivesurgery.com
austinplasticandreconstructivesurgery.comaustinplasticandreconstructivesurgery.com
HealthcareUS
2025-09-20
hsjlawyers.com
hsjlawyers.comhsjlawyers.com
Business Services
2025-09-26
bun.nl
bun.nlbun.nl
Agriculture and Food ProductionNL
2025-11-19
aceforwarding.com
aceforwarding.comaceforwarding.com
Transportation/Logistics
2025-11-27
ic-controls.com
ic-controls.comic-controls.com
ManufacturingDE
2025-02-06
kkp.law
kkp.lawkkp.law
Business ServicesUS
2025-02-18
iss-na.com
iss-na.comiss-na.com
Business ServicesUS
2025-02-21
icgad.com
icgad.comicgad.com
ConstructionUS
2025-03-19
dbhcares.com
dbhcares.comdbhcares.com
HealthcareUS
2025-02-06
icmtx.com
icmtx.comicmtx.com
TechnologyUS
2024-03-03
jastreet.com
jastreet.comjastreet.com
ConstructionUS
2025-02-18
neffendorfblockercpa.com
neffendorfblockercpa.comneffendorfblockercpa.com
Financial ServicesUS
2025-05-25
gosvt.com
gosvt.comgosvt.com
TechnologyUS
2025-05-20
vazirilaw.com
vazirilaw.comvazirilaw.com
Business ServicesUS
2025-01-15
leonardo.com
leonardo.comleonardo.com
TechnologyIT
2025-02-01
sehma.com
sehma.comsehma.com
HealthcareDE
2025-02-05
corehandf.com
corehandf.comcorehandf.com
Consumer ServicesUS
2025-01-30
soitinlaine.fi
soitinlaine.fisoitinlaine.fi
Consumer ServicesFI
2025-01-15
anwsd.org
anwsd.organwsd.org
EducationUS
2024-11-27
hapsch.de
hapsch.dehapsch.de
HealthcareDE
2024-11-29
kuritaamerica.com
kuritaamerica.comkuritaamerica.com
ManufacturingJP
2024-12-04
hobokennj.gov
hobokennj.govhobokennj.gov
Public SectorUS
2024-11-13
midstatesindustrial.com
midstatesindustrial.commidstatesindustrial.com
ManufacturingUS
2024-09-28
anuenterprise.com.au
anuenterprise.com.auanuenterprise.com.au
Business ServicesAU
2024-10-31
inhometexas.com
inhometexas.cominhometexas.com
HealthcareUS
2024-10-08
caillau.com.br
caillau.com.brcaillau.com.br
ManufacturingBR
2024-10-10
sandray.com
sandray.comsandray.com
ManufacturingUS
2024-10-24
mpspromotions.com
mpspromotions.commpspromotions.com
Business ServicesAU
2024-10-19
freedomhomecare.net
freedomhomecare.netfreedomhomecare.net
HealthcareUS
2024-10-24
carolinaarthritis.com
carolinaarthritis.comcarolinaarthritis.com
HealthcareUS
2024-10-10
oklahomasleepinstitute.com
oklahomasleepinstitute.comoklahomasleepinstitute.com
HealthcareUS
2024-09-30
verco.co.uk
verco.co.ukverco.co.uk
ManufacturingGB
2024-09-30
carlile-group.com
carlile-group.comcarlile-group.com
Transportation/LogisticsGB
2024-06-18
sacredheart.southwark.sch.uk
sacredheart.southwark.sch.uksacredheart.southwark.sch.uk
EducationGB