Threeam Ransomware

Description Summary

A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked. The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.

Threat Actor

Operator/affiliate cluster behind the Threeam leak site. Detailed actor attribution is not available in curated public reporting.

Technical Indicators

Encryption Extension
Not publicly reported
Encryption Algorithm
Not publicly reported
Ransom Note Name
Not publicly reported
Targeted Industries
Cross-sector (per leak-site victim telemetry)
First Seen
Unknown
Last Seen
No public victim disclosures observed
Geographical Location
Global / not publicly profiled

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts