ThreeAM, also written 3AM or THREEAM, is a ransomware threat group that emerged publicly in 2023 and has been tracked in leak-site reporting as a comparatively new entrant among active extortion operations. The group has been associated with use of LockBit ransomware in at least some attacks, suggesting operational overlap or affiliate-level ties with the broader ransomware ecosystem. ThreeAM has conducted multi-country victimization across North America, Europe, Latin America, Asia-Pacific, and Southeast Asia. Observed victimology indicates opportunistic targeting across multiple sectors rather than a narrowly specialized focus. Reported victims include organizations in hospitality, technology, business and professional services, agriculture and food production, healthcare-related institutions, education, and industrial or capital-goods environments. Countries directly observed among victims include the United States, Germany, Mexico, Argentina, Australia, Belgium, Brazil, the United Kingdom, and Vietnam. ThreeAM is linked to ransomware intrusions and associated data-breach claims, and its affiliates have used social-engineering tradecraft during operations. Reported behavior includes spoofing an organization’s IT department telephone number to facilitate attacker interaction with targets. Separate reporting on affiliate attack patterns also notes use of stealth measures such as deploying a virtual machine on a compromised host to conceal attacker presence from endpoint protection, though attribution of that specific technique to all ThreeAM operations should be treated cautiously at the affiliate level. The group’s activity is consistent with financially motivated ransomware operations involving initial compromise, post-compromise access, persistence, defense evasion, data theft, and extortion. Publicly observed reporting supports characterization of ThreeAM as a ransomware actor with leak-site style victim claiming and data-exposure pressure, but the supplied facts do not directly establish the full extent of its encryption-versus-theft-only tradecraft across all incidents.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against clubonecasino.com.
Conducting a ransomware attack resulting in a data breach against tws-tac.net.
Conducting a ransomware attack against Guardian Barrier Services.
Conducting a ransomware attack against acemacon.org.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.