3AM, also written ThreeAM, is a ransomware operation first publicly reported in 2023 after attackers were observed switching to it when a LockBit deployment failed. Multiple investigations have linked 3AM to the Royal and BlackSuit lineage and, more broadly, to former Conti operators. Reporting has also described Royal as a newer iteration of 3AM or a closely related rebrand, reflecting overlap in personnel, infrastructure, and tradecraft rather than a clean separation between brands.
3AM is used in financially motivated intrusions that emphasize rapid hands-on-keyboard post-compromise activity, data theft, and enterprise-wide encryption. Observed operator behavior includes extensive reconnaissance, abuse of valid accounts, lateral movement over administrative protocols and remote desktop access, deployment of additional remote management tooling, and attempts to weaken defensive controls such as endpoint protection and multifactor authentication. In at least one documented intrusion, operators exfiltrated large volumes of data before attempting ransomware deployment, consistent with modern double-extortion practices.
A notable tradecraft pattern associated with 3AM involves voice-based social engineering. Intrusions have begun with email bombing followed by spoofed calls impersonating internal IT staff, persuading users to grant remote access through remote assistance tools. In one investigated case, the attackers then launched a QEMU-based virtual machine on the victim host containing the QDoor backdoor, creating a stealthy foothold that initially evaded endpoint detection and enabled persistence, command and control, and lateral movement. Operators also used native administration utilities, PowerShell, WMIC, RDP, and commercial remote management software during follow-on activity.
3AM has also been associated with Microsoft Teams-based vishing activity and clusters linked to BlackBasta-style social engineering operations, indicating convergence between ransomware affiliates and access brokers using help-desk impersonation. Researchers have additionally observed experimentation with public-pressure extortion tactics, including social-media amplification intended to increase reputational pressure on victims.
Victimology is consistent with broad opportunistic enterprise targeting rather than a narrow vertical focus, with incidents and reporting spanning industrial and corporate environments. The operation is best understood as part of the post-Conti ransomware ecosystem, where rebranding, affiliate migration, and shared tooling blur boundaries between nominally distinct groups.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Lockbit 3.0 attack infrastructure allowed Ransomware Affiliates to exploit CVE 2023–4966 Citrix Bleed Vulnerability and encrypt a wide range of victims around October 2023.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the first quarter of 2025, Sophos Incident Response aided an organization targeted by attackers affiliated with the 3AM ransomware group.
Security researchers analyzing the activity of the recently emerged 3AM ransomware operation uncovered close connections with infamous groups, such as the Conti syndicate and the Royal ransomware gang.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Le logiciel malveillant utilise des commandes de reconnaissance spécifiques telles que "whoami"
Le logiciel malveillant utilise des commandes de reconnaissance spécifiques telles que "netstat"
Le ransomware 3AM chiffre exclusivement les fichiers qui répondent à des critères prédéfinis et ajoute l'extension ".threeamtime" aux noms de fichiers compromis.
Il tente d'arrêter les services de sécurité et de sauvegarde avant de chiffrer les fichiers
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware brand newly appearing in industrial victim claims in Q2 2026.
Referenced as another ransomware family tied to similar Teams-vishing activity, not as the main malware in this campaign.
A ransomware family mentioned as financially connected to Stern’s activity.
Ransomware used in a targeted intrusion following email bombing and vishing-based initial access. Attackers later deployed the 3AM ransomware binary remotely across the network from an unmanaged host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.