3AM, also spelled ThreeAM, is a ransomware operation first publicly reported by Symantec in September 2023. Reporting in the provided content links 3AM closely to the Royal/BlackSuit ransomware lineage and to former Conti operators. Multiple researchers assessed 3AM to be a rebrand of BlackSuit or Royal, and Intrinsec reported significant overlap with the Conti syndicate in communication channels, infrastructure, and TTPs. The content also notes ties to BlackBasta-affiliated actors involved in Microsoft Teams and vishing activity. Observed 3AM intrusions used social engineering for initial access, including email bombing followed by spoofed IT support calls or Microsoft Teams voice phishing to convince victims to grant remote access through Microsoft Quick Assist. In a Sophos-investigated 2025 case, attackers used Quick Assist access to stage a QEMU-based Windows 7 virtual machine containing the QDoor tunneling backdoor, giving them a stealthy foothold that initially evaded endpoint detection. The actors then used compromised accounts, WMIC, PowerShell, RDP, and remote management tools including XEOXRemote for lateral movement, persistence, and account compromise. They conducted discovery with standard administrative commands, attempted to disable Duo MFA and Sophos protections, exfiltrated approximately 868 GB of data to Backblaze using GoodSync, and ultimately attempted to deploy 3AM ransomware from an unmanaged server. The content specifically associates 3AM with abuse of QEMU and QDoor. QDoor was used as a tunneling backdoor, and Sophos noted infrastructure overlap with BlackSuit-related activity. Additional reporting states that 3AM operations are characterized by the use of QDoor and that related intrusion chains overlap with Black Basta-style Teams phishing and Quick Assist abuse. 3AM has also used extortion tactics beyond encryption. Researchers reported that the group experimented with public pressure by sharing news of data leaks with victims’ social media followers and likely using bots on X/Twitter to amplify links to its Tor leak site. Intrinsec reported that 3AM’s leak site listed 19 victims and visually resembled LockBit’s leak site. Symantec also observed actors switching to ThreeAM ransomware after failing to deploy LockBit. Known aliases and related names mentioned in the content include ThreeAM. Related groups or lineages mentioned in the reporting include Royal, BlackSuit, Conti, and ties to BlackBasta-affiliated actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of publicly reported activity aligned with the surge in Microsoft Teams-based social-engineering intrusions.
Referenced as a ransomware group that previously abused QEMU in operations.
Conducted a targeted ransomware intrusion using pre-attack reconnaissance, email bombing, phone-number spoofing, Quick Assist social engineering, QEMU-based VM deployment, QDoor backdoor access, lateral movement, data exfiltration, and attempted ransomware deployment.
Referenced as a comparator set of ransomware intrusions sharing tooling/characteristics (e.g., QDoor tunneling backdoor, Rust payload likely loader for SSH utility, and Anubis Python RAT).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.