Also known as: 3Am
A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.<BR> > <BR> > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 73
Objectives
Executive Summary
3AM is a medium-sophistication ransomware group emerged in August 2023. It initially deployedLockBit ransomware but shifted to its own variant after LockBit was blocked. The group primarily targets organizations for financial gain, focusing on various sectors through sophisticated attack campaigns.
Goals & Targeting
ThreeAM targets a wide array of sectors, reflecting its focus on maximizing victim diversity for financial gain. The group's victims include local governments, healthcare providers, educational institutions, and small to medium-sized enterprises (SMEs). This broad targeting suggests an operational strategy focused on easy access with high potential for disruption, likely indicating resource availability as the primary targeting criterion. Geographically,ThreeAM appears to focus on regions with less mature cybersecurity defenses but has been observed globally.
Enhanced Description
ThreeAM, alias '3Am', is a medium-sophistication cybercriminal threat group specializing in ransomware operations. Emerging in mid-2023, the group initially attempted to deploy LockBit ransomware but transitioned to its own variant due to operational challenges. The group operates with a primary goal of financial gain through organizational disruption and data theft. ThreeAM's campaigns have been observed targeting diverse sectors, including government, healthcare, legal services, and various commercial industries across multiple countries.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ThreeAM's campaigns exhibit a high operational tempo, frequently shifting tactics after detection. The group has targeted both small and large organizations across various sectors. Notable victims include local governments (e.g., Wyoming County NY), dental practices, legal firms, and international businesses. ThreeAM employs double extortion techniques, encrypting data and threatening to leak it unless a ransom is paid in cryptocurrency. The group uses fast-flux domains for command-and-control infrastructure, making takedowns challenging.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is a high confidence in the data related to ThreeAM's operational tactics, including its shift from LockBit and the identification of multiple victims across varied sectors. However, specific details regarding its exact technical capabilities, such as precise malware binaries or C2 configurations, remain gaps, limiting full understanding of its attack vector nuances.
No techniques linked yet.
No tools linked yet.
New ransomware
Imported from MISP event #455 (57174526-23d8-4895-8c08-4ed1950d210f).
Apr 20, 2016
TLP:CLEARNo observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
26
Campaigns
0
IOCs
0
Observed Data
0
Tactics