3Am
A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked. > > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim. Source: https://github.com/crocodyli/ThreatActors-TTPs
- Unspecified
- Business Services
- Technology
- Agriculture and Food Production
- Manufacturing
- Hospitality
- TA0003Persistence
- T1136Create Account
The threat actor using the 3AM ransomware performed account creation to ensure persistence.
- TA0004Privilege Escalation
- TA0005Defense Evasion
- TA0007Discovery
- T1018Remote System Discovery
Utilizes Advanced IP Scanner and MASSCAN to discover remote systems.
- T1135Network Share Discovery
The threat actor executed reconnaissance commands like 'whoami, netstat, quser, net view, and net share' to enumerate other servers.
- T1615Group Policy Discovery
The threat actor used commands like 'gpresult' to dump applied policy settings on the computer for a user (Group Policy).
- TA0010Exfiltration
- T1048Exfiltration Over Alternative Protocol
The threat actor used the 'Wput' tool to exfiltrate files from the victim to their own server via FTP.
- TA0040Impact