3AM, also referred to as ThreeAM, is a ransomware operation first publicly reported in 2023 and assessed by multiple researchers as closely linked to Royal and BlackSuit, with broader ties to former Conti operators. It has been described as either a newer iteration or rebranding within that lineage, and its tradecraft overlaps with ecosystems associated with Conti, Royal, and BlackBasta-affiliated activity.
3AM is used in targeted intrusions rather than indiscriminate mass deployment. Observed operations have combined social engineering, remote access abuse, stealthy foothold establishment, lateral movement, data theft, and attempted encryption. In one documented 2025 intrusion, attackers used email bombing followed by a spoofed support call to impersonate internal IT staff and convince an employee to grant access through Microsoft Quick Assist. The operators then deployed a QEMU-based virtual machine containing the QDoor backdoor, giving them a covert foothold that initially evaded endpoint monitoring. From there, they used compromised accounts, command execution, remote desktop access, and commercial remote-management software to move through the environment, attempted to weaken defensive controls including MFA and endpoint protection, exfiltrated large volumes of data to cloud storage, and finally launched 3AM ransomware from an unmanaged server.
The malware’s operational model is consistent with modern double-extortion ransomware: theft of victim data followed by attempted encryption and public pressure. 3AM operators have maintained a leak site for publishing victim data and have experimented with amplifying extortion pressure through social media by publicizing breaches to victims’ followers. Researchers have also noted infrastructure and tooling overlaps with broader Conti-linked tradecraft, including use of backdoors, tunneling mechanisms, and commodity malware historically seen in related ransomware campaigns.
3AM primarily targets Windows enterprise environments. Reported activity indicates interest in organizations where remote administration pathways, identity compromise, and unmanaged systems can be leveraged to bypass defenses. The group has appeared in the broader ransomware landscape affecting commercial organizations and has been discussed alongside other major extortion operations active after the fragmentation of Conti.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the first quarter of 2025, Sophos Incident Response aided an organization targeted by attackers affiliated with the 3AM ransomware group.
Security researchers analyzing the activity of the recently emerged 3AM ransomware operation uncovered close connections with infamous groups, such as the Conti syndicate and the Royal ransomware gang.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. | Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region between 2024 and 2026, and found that ransomware groups are going after the entire healthcare supply chain.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family mentioned as financially connected to Stern’s activity.
Ransomware used in a targeted intrusion following email bombing and vishing-based initial access. Attackers later deployed the 3AM ransomware binary remotely across the network from an unmanaged host.
Minimal-activity ransomware brand referenced as part of the long-tail of operators.
3AM is a ransomware strain that encrypts files and demands payment for decryption, typically used in targeted attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.