Skip to content

3AM

3AM, also written ThreeAM, is a ransomware operation first publicly reported in 2023 after attackers were observed switching to it when a LockBit deployment failed.

Profile source: Mallory opens in a new tab

3AM

Family profile

3AM, also written ThreeAM, is a ransomware operation first publicly reported in 2023 after attackers were observed switching to it when a LockBit deployment failed. Multiple investigations have linked 3AM to the Royal and BlackSuit lineage and, more broadly, to former Conti operators. Reporting has also described Royal as a newer iteration of 3AM or a closely related rebrand, reflecting overlap in personnel, infrastructure, and tradecraft rather than a clean separation between brands.

3AM is used in financially motivated intrusions that emphasize rapid hands-on-keyboard post-compromise activity, data theft, and enterprise-wide encryption. Observed operator behavior includes extensive reconnaissance, abuse of valid accounts, lateral movement over administrative protocols and remote desktop access, deployment of additional remote management tooling, and attempts to weaken defensive controls such as endpoint protection and multifactor authentication. In at least one documented intrusion, operators exfiltrated large volumes of data before attempting ransomware deployment, consistent with modern double-extortion practices.

A notable tradecraft pattern associated with 3AM involves voice-based social engineering. Intrusions have begun with email bombing followed by spoofed calls impersonating internal IT staff, persuading users to grant remote access through remote assistance tools. In one investigated case, the attackers then launched a QEMU-based virtual machine on the victim host containing the QDoor backdoor, creating a stealthy foothold that initially evaded endpoint detection and enabled persistence, command and control, and lateral movement. Operators also used native administration utilities, PowerShell, WMIC, RDP, and commercial remote management software during follow-on activity.

3AM has also been associated with Microsoft Teams-based vishing activity and clusters linked to BlackBasta-style social engineering operations, indicating convergence between ransomware affiliates and access brokers using help-desk impersonation. Researchers have additionally observed experimentation with public-pressure extortion tactics, including social-media amplification intended to increase reputational pressure on victims.

Victimology is consistent with broad opportunistic enterprise targeting rather than a narrow vertical focus, with incidents and reporting spanning industrial and corporate environments. The operation is best understood as part of the post-Conti ransomware ecosystem, where rebranding, affiliate migration, and shared tooling blur boundaries between nominally distinct groups.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

Operational record

1
YARA rules
2
Leak sites
1 available

Recent claims

Reported operators

Threat actors

2 named in public reporting
Storm-1811

In the first quarter of 2025, Sophos Incident Response aided an organization targeted by attackers affiliated with the 3AM ransomware group.

Conti

Security researchers analyzing the activity of the recently emerged 3AM ransomware operation uncovered close connections with infamous groups, such as the Conti syndicate and the Royal ransomware gang.

MITRE ATT&CK

3AM in ATT&CK

18 distinct techniques

Reporting

Research mentioning 3AM

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Jul 14
Cyberscoop

US sanctions First VPN and administrator for supporting ransomware | CyberScoop

Jul 14
Chainalysis

“Stern” Ransomware Operator Sanctioned by EU

Jul 14
Cyber Security News

US Treasury Sanctions VPN Service that Helped Ransomware Actors to Attack Organizations

Jul 14
The Hacker News

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.