3AM, also written ThreeAM, is a ransomware operation first publicly reported in 2023 and widely assessed as part of the post-Conti cybercrime ecosystem. Multiple researchers have linked it to former Conti personnel and to the Royal/BlackSuit lineage, with additional tradecraft overlap noted with Black Basta–associated social-engineering clusters. The group has been observed targeting organizations in multiple sectors and regions, including healthcare entities in EMEA and at least one U.S. victim, and it has appeared in broader industrial-sector ransomware reporting. 3AM is known for combining hands-on intrusion activity with ransomware deployment and data theft. Reported operations have used reconnaissance, email bombing, voice phishing, spoofed IT-support calls, and abuse of remote assistance tools such as Microsoft Quick Assist to obtain initial access. Post-compromise behavior has included use of compromised accounts, remote execution, PowerShell, WMIC, RDP, commercial remote-management software, lateral movement, persistence, and attempts to weaken defenses by disabling MFA components and endpoint protections. The group has also been associated with exfiltration prior to encryption and with use of tunneling backdoors such as QDoor, including deployment through QEMU-based virtual-machine tradecraft to evade host-based detection. 3AM operates as an extortion-focused ransomware actor. In addition to maintaining a leak site for non-paying victims, it has experimented with amplified pressure tactics by publicizing leaks through social-media replies directed at victims and their followers, indicating victim-harassment behavior beyond conventional leak-site posting. Researchers have also observed cases where actors switched to 3AM ransomware after failed deployment of other ransomware, underscoring operational ties within the broader ransomware affiliate ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a new entrant in quarterly rankings.
Ransomware group listed among those targeting healthcare organizations in the EMEA region.
Referenced as part of publicly reported activity aligned with the surge in Microsoft Teams-based social-engineering intrusions.
Referenced as a ransomware group that previously abused QEMU in operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.