Quick Summary
AllegedExecutive Summary
ThreeAM added Mecasem to its dark web leak site on August 19, 2026. Mecasem, a commercial organization based in Mexico, is the latest Latin American victim claimed by the ThreeAM ransomware group. SOCRadar’s Dark Web Monitoring identified this listing. The commercial sector is a consistent target for ThreeAM, aligning with their operational focus. ThreeAM, also known as 3AM, emerged in late 2023 and is believed to be composed of former LockBit and Conti affiliates. The group utilizes a ransomware payload written in Rust. Their targeting appears selective but consistent, focusing on professional services, manufacturing, and commercial entities across the United States, Canada, and Latin America. Given their Conti lineage, their operational capabilities likely surpass what their public victim count might suggest. Mexico is a known geography for this group’s operations.
Technical Analysis
A stealer-log query was performed against mecasem[.]com. The query returned no records. However, it is important to note that this query was bounded and paginated, meaning it covered only a limited sample of available data. Credentials belonging to Mecasem that might exist under a sibling domain or be associated with staff personal email aliases would not be surfaced by this specific query. Therefore, a null result from this query does not confirm that the organization is unaffected by credential compromise. Infostealer-harvested credentials are a documented initial access vector for the ThreeAM ransomware group. Threat actors often source credential logs from underground markets. These credentials may then be validated against corporate access points such as Microsoft 365 or VPN portals before being deployed for ransomware operations. This process allows threat actors to gain unauthorized access to victim networks, potentially leading to data exfiltration and encryption. The absence of stealer-log records for mecasem[.]com in the queried dataset does not rule out the possibility of a compromise. Continued dark web monitoring and proactive credential hygiene checks, including password rotation and multi-factor authentication review, are recommended to mitigate potential risks. Reviewing activity logs for Microsoft 365, VPNs, and other remote-access portals may also provide valuable insights.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.