Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors threeam

Also known as: 3Am

Description

A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.<BR> > <BR> > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 73

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

3AM is a medium-sophistication ransomware group emerged in August 2023. It initially deployedLockBit ransomware but shifted to its own variant after LockBit was blocked. The group primarily targets organizations for financial gain, focusing on various sectors through sophisticated attack campaigns.

Goals & Targeting

ThreeAM targets a wide array of sectors, reflecting its focus on maximizing victim diversity for financial gain. The group's victims include local governments, healthcare providers, educational institutions, and small to medium-sized enterprises (SMEs). This broad targeting suggests an operational strategy focused on easy access with high potential for disruption, likely indicating resource availability as the primary targeting criterion. Geographically,ThreeAM appears to focus on regions with less mature cybersecurity defenses but has been observed globally.

Enhanced Description

ThreeAM, alias '3Am', is a medium-sophistication cybercriminal threat group specializing in ransomware operations. Emerging in mid-2023, the group initially attempted to deploy LockBit ransomware but transitioned to its own variant due to operational challenges. The group operates with a primary goal of financial gain through organizational disruption and data theft. ThreeAM's campaigns have been observed targeting diverse sectors, including government, healthcare, legal services, and various commercial industries across multiple countries.

Key Capabilities

  • Ransomware deployment through phishing campaigns
  • Double extortion tactics (encrypting data and threatening data leaks)
  • Fast-flux domain generation for C2 infrastructure
  • Sophisticated encryption techniques
  • Custom malware development post-LockBit blocking

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Credential Access
Disruption

ATT&CK Techniques

T1059.003
T1566.001
T1074
T1201

Software / Tooling

ThreeAM Ransomware
Cobalt Strike (potential use)
Mimikatz (used for credential access)
Custom C2 tools

Campaigns & Victims

ThreeAM's campaigns exhibit a high operational tempo, frequently shifting tactics after detection. The group has targeted both small and large organizations across various sectors. Notable victims include local governments (e.g., Wyoming County NY), dental practices, legal firms, and international businesses. ThreeAM employs double extortion techniques, encrypting data and threatening to leak it unless a ransom is paid in cryptocurrency. The group uses fast-flux domains for command-and-control infrastructure, making takedowns challenging.

IOC Patterns

  • Spear-phishing emails with malicious links
  • 3AM ransomware encryption patterns
  • Encrypted files with '.3Am' extension
  • C2 communication via fast-flux DNS domains
  • Scheduled task creation for persistence

Recommended Actions

  • Implement advanced phishing detection solutions
  • Enhance endpoint detection and response (EDR) capabilities
  • Monitor for unusual process injection activities
  • Encrypt sensitive data with strong encryption standards
  • Conduct regular employee training on ransomware threats
  • Establish robust backup and recovery mechanisms
  • Implement multi-factor authentication (MFA)
  • Perform regular network traffic analysis

Suggested Tags

Ransomware
Financial crime
Cybercriminal group
Healthcare sector
Local government targets

Confidence Assessment

There is a high confidence in the data related to ThreeAM's operational tactics, including its shift from LockBit and the identification of multiple victims across varied sectors. However, specific details regarding its exact technical capabilities, such as precise malware binaries or C2 configurations, remain gaps, limiting full understanding of its attack vector nuances.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

26

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial crime
Cybercriminal group
Healthcare sector
Local government targets

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Aug 4, 2023
Last Seen
Aug 6, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.