Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

3am Ransomware Group

Ransomware group profile

13Victims
RussiaSource country
68Impact score
Also Known As
Time 3AM

Description

Threeam is a ransomware group that emerged in February 2023, known for its quick deployment and sophisticated encryption methods. Primarily motivated by financial gain, they employ double extortion tactics to pressure high-value organizations into paying ransoms after encrypting their data and exfiltrating sensitive information.

Key insights

  • Utilizes custom-built ransomware variants written in Rust.
  • Employs social engineering tactics to gain initial access, including phishing and voice phishing.
  • Focuses on double extortion by encrypting files and threatening to release sensitive data publicly.
  • Targets high-value sectors such as healthcare and financial services.
  • Uses advanced evasion techniques like disabling security software and deleting Volume Shadow Copies.
  • Linked to other ransomware operations like LockBit and Conti, indicating a collaborative nature among threat groups.

Threat Level & Status Breakdown

For 3am · Based on incidents in selected period

1.9threat level
Aggressiveness3.3/ 10
Lethality0/ 10
Criticality2.6/ 10

Status Breakdown

Claimed100.0%13
First seenSep 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 10, 2026

Recent activity

Monthly attack count for 3am in the selected period

13Total attacks
7peak in Jun
3.3avg / month
↑ 4 vs first month
SepOctNovJun02468

Intelligence

IOCs, YARA/Sigma rules, and related families for 3am

  1. 185.202.0.111
View full IOC feed2 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for 3am

Defense Evasion

T1070.001

Clear Windows Event Logs

T1562.004

Disable or Modify System Firewall

Discovery

T1018

Remote System Discovery

T1135

Network Share Discovery

T1615

Group Policy Discovery

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Persistence

T1136

Create Account

Privilege Escalation

T1543.003

Windows Service

Victims(13)

ArgentinaOtherpalmero.com
Claimed
2 months ago
ArgentinaOtherinsamani.com.ar
Claimed
2 months ago
GermanyFinancial Servicesbsynchro.com
Claimed
2 months ago
ArgentinaManufacturingmolinoscabodi.com.ar
Claimed
2 months ago
BrazilProfessional Servicesws.com.br
Claimed
2 months ago
MexicoOtheragroexportavocados.com
Claimed
2 months ago
VietnamTechnologyhoplongtech.com
Claimed
2 months ago
GermanyManufacturingic-controls.com
Claimed
9 months ago
NetherlandsOtherbun.nl
Claimed
10 months ago
CanadaProfessional Serviceshsjlawyers.com
Claimed
10 months ago
United StatesGovernment & Defensetownofnorwell.net
Claimed
11 months ago
United StatesHealthcarecuredentalbeltontx.com
Claimed
11 months ago
United StatesHealthcareaustinplasticandreconstructivesurgery.com
Claimed
11 months ago