Skip to content
The Nexus
Group profile2 claimed in last 30d17 total tracked

3Am

Forward this

A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked. > > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim. Source: https://github.com/crocodyli/ThreatActors-TTPs

First seen: Jun 12 · 19:59 UTCLast seen: Aug 19 · 08:15 UTCTracked since: 2023-09-14
Sectors hit
  • Unspecified7
  • Business Services4
  • Technology2
  • Agriculture and Food Production2
  • Manufacturing1
  • Hospitality1
Countries hit
  • Mexico3
  • United States2
  • Germany2
  • Argentina2
  • Vietnam1
  • Croatia1
  • United Kingdom1
  • Brazil1
  • Belgium1
  • Australia1
MITRE ATT&CK · observed TTPs6 tactics

Tactics and techniques attributed to 3AM by ransomware.live's curated TTP catalog. Identifiers link to the canonical MITRE ATT&CK reference for each tactic or sub-technique.

  • TA0003Persistence
    • T1136Create Account

      The threat actor using the 3AM ransomware performed account creation to ensure persistence.

  • TA0004Privilege Escalation
    • T1543.003Service Execution

      The threat actor used PsExec to take advantage of a Windows service to escalate from administrator privileges to SYSTEM.

    • T1548.002Bypass User Account Control

      The threat actor may use Cobalt Strike for a series of known techniques to bypass Windows UAC.

  • TA0005Defense Evasion
    • T1070.001Clear Windows Event Logs

      The executable clears Windows event logs after its execution.

    • T1562.004Disable or Modify System Firewall Settings

      The threat actor uses commands to set the discovery policy of other hosts on the network, altering the Firewall policy.

  • TA0007Discovery
    • T1018Remote System Discovery

      Utilizes Advanced IP Scanner and MASSCAN to discover remote systems.

    • T1135Network Share Discovery

      The threat actor executed reconnaissance commands like 'whoami, netstat, quser, net view, and net share' to enumerate other servers.

    • T1615Group Policy Discovery

      The threat actor used commands like 'gpresult' to dump applied policy settings on the computer for a user (Group Policy).

  • TA0010Exfiltration
    • T1048Exfiltration Over Alternative Protocol

      The threat actor used the 'Wput' tool to exfiltrate files from the victim to their own server via FTP.

  • TA0040Impact
    • T1486Data Encrypted for Impact

      The ransomware encrypts files and appends the '.threeamtime' extension after encryption.

    • T1490Inhibit System Recovery

      The 3AM ransomware deletes volume shadow copies on the disk and backups through the commands presented in the analysis.

Recent claimed victims
MexicoAug 19 · 08:15 UTC

mecasem.org

mecasem.org
HospitalityUnited StatesAug 6 · 08:22 UTC

clubonecasino.com

clubonecasino.com
GermanyJul 18 · 09:58 UTC

tws-tac.net

tws-tac.net
Business ServicesUnited KingdomJun 29 · 21:51 UTC

guardianbarrierservices.com

guardianbarrierservices.com
MexicoJun 28 · 19:30 UTC

acemacon.org

acemacon.org
ManufacturingJun 12 · 20:07 UTC

jetmachprod.com

jetmachprod.com
CroatiaJun 12 · 20:06 UTC

jastrebarsko.hr

jastrebarsko.hr
Jun 12 · 20:05 UTC

palmero.com

palmero.com
ArgentinaJun 12 · 20:05 UTC

insamani.com.ar

insamani.com.ar
TechnologyGermanyJun 12 · 20:04 UTC

bsynchro.com

bsynchro.com
Agriculture and Food ProductionArgentinaJun 12 · 20:04 UTC

molinoscabodi.com.ar

molinoscabodi.com.ar
Business ServicesBrazilJun 12 · 20:03 UTC

ws.com.br

ws.com.br
Business ServicesBelgiumJun 12 · 20:03 UTC

consultic.be

consultic.be
AustraliaJun 12 · 20:02 UTC

amc.org.au

amc.org.au
Agriculture and Food ProductionMexicoJun 12 · 20:01 UTC

agroexportavocados.com

agroexportavocados.com
TechnologyVietnamJun 12 · 20:00 UTC

hoplongtech.com

hoplongtech.com
Business ServicesUnited StatesJun 12 · 19:59 UTC

mgrlaw.com

mgrlaw.com