ThreeAM, also written as 3AM or THREEAM, is a ransomware threat actor active since at least 2023. The group has been observed in leak-site reporting and victim claims across multiple countries, indicating broad opportunistic targeting rather than a narrowly regional focus. Reported victims span North America, Latin America, Europe, Asia-Pacific, and Southeast Asia, including organizations in hospitality, professional and business services, information technology, agriculture and food production, industrial and manufacturing-related businesses, health-related standards bodies, and public-facing institutions. ThreeAM is associated with ransomware operations and data-breach-style victim disclosures. The group has been linked to use of LockBit ransomware in attacks, suggesting either tooling reuse, affiliate overlap, or operational ties with established ransomware ecosystems, although the precise nature of that relationship is not established at high confidence. ThreeAM has also been identified among newer ransomware groups emerging during the broader fragmentation of the ransomware landscape. Operationally, affiliates associated with ThreeAM have used social-engineering tradecraft, including spoofing the telephone number of an organization’s IT department as part of intrusion or extortion workflows. Reporting also places ThreeAM within the broader ransomware trend of combining unauthorized access, data theft, and public victim listing on leak infrastructure. Based on attributed incidents, the actor demonstrates initial access, exfiltration, extortion, and post-compromise operational capability consistent with financially motivated ransomware activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against Newman Tractor, a U.S.-based heavy-equipment business in the manufacturing sector.
Conducting a ransomware attack against mecasem.org.
Conducting a ransomware attack against clubonecasino.com.
Conducting a ransomware attack resulting in a data breach against tws-tac.net.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.