In the first quarter of 2025, Sophos Incident Response aided an organization targeted by attackers affiliated with the 3AM ransomware group.
3AM
3AM, also referred to as ThreeAM, is a ransomware operation first publicly reported in 2023 after operators were observed switching to it when a LockBit deployment failed.
Profile source: Mallory opens in a new tab3AM
Family profile
3AM, also referred to as ThreeAM, is a ransomware operation first publicly reported in 2023 after operators were observed switching to it when a LockBit deployment failed. Multiple researchers have assessed 3AM as closely connected to the Royal/BlackSuit lineage and to former Conti operators, based on overlaps in tradecraft, infrastructure, and operator behavior. It has also been linked in some reporting to actors associated with BlackBasta-style social-engineering intrusions.
3AM is used in financially motivated intrusions that combine social engineering, hands-on-keyboard post-compromise activity, data theft, and attempted encryption. Observed access patterns include email bombing followed by voice phishing or Microsoft Teams impersonation of internal IT or help-desk staff to persuade users to grant remote access through legitimate remote-support tools. In documented cases, operators used Quick Assist and other remote administration utilities to establish an initial foothold.
Post-compromise activity associated with 3AM includes reconnaissance, credential and account abuse, lateral movement over administrative protocols, persistence establishment, and exfiltration prior to ransomware deployment. In one investigated intrusion, the attackers deployed a QEMU-based virtual machine containing the QDoor backdoor to create a stealthy foothold, then used compromised accounts, WMIC, PowerShell, RDP, and commercial remote-management software to expand access across the environment. The same intrusion involved large-scale data theft to cloud storage before an attempted 3AM encryption event. Operators also attempted to weaken defenses by uninstalling MFA components and endpoint protections, though those efforts were not always successful.
3AM campaigns have targeted enterprise Windows environments, including organizations in North America, and broader reporting places the group within the active ransomware ecosystem affecting multiple sectors. The operation has also experimented with extortion pressure beyond encryption, including public leak-site activity and at least one observed attempt to amplify victim pressure through social-media replies linking to leaked data. Its leak-site presentation has been noted as resembling LockBit.
Overall, 3AM is best understood as a ransomware brand operating within the post-Conti criminal ecosystem, using modern social-engineering-led intrusion methods, established backdoors and remote-access tooling, data exfiltration, and double-extortion tactics against enterprise victims.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
- Initial Access
- Lateral Movement
- Persistence
- Post Exploitation
- Reconnaissance
- Spoofing
Operational record
Recent claims
Reported operators
Threat actors
2 named in public reportingSecurity researchers analyzing the activity of the recently emerged 3AM ransomware operation uncovered close connections with infamous groups, such as the Conti syndicate and the Royal ransomware gang.
MITRE ATT&CK
3AM in ATT&CK
18 distinct techniquesTechniques
18 techniquesReporting
Research mentioning 3AM
Telegram shortlinks knocked offline over sanctioned VPN connection
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.