3AM
Aliases: ThreeAM, 3AM ransomware
Source profile review date: 2026-06-21
Added to the source registry: 2023-09-14 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.
Locally generated translation; linguistic review is still pending.
Executive summary
3AM is a ransomware family that stood out as an alternative to failing other payloads, with post-exploitation via Cobalt Strike, privilege use and classic impact preparation.
3AM is relevant because public analysis shows that ransomware operators can switch to another payload when a primary encryption device does not work. Detection should therefore be on attack chain and behaviour, not on a single family name.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Management summary
3AM is a good example of why ransomware defense should not lean on a single payload. Public analyses described 3AM in a context where operators tried to cause impact after problems with another payload. For organizations, this means that stopping the chain is more important than recognizing a brand name.
The risk translation is concrete: if an actor already has Cobalt Strike-like access, administrator privileges, lateral movement and data or server view, switching payload is only a final step. The defense should therefore intervene earlier in beaconing, privilege usage, remote execution and service disruption.
3AM also shows that incident response is not ready during a partially blocked attack. If an encryption failure, the actor can switch. Only stopping a process is insufficient when credentials, sessions and lateral access still exist.
Grouping and development
3AM was publicly described as ransomware family that was seen in limited but striking incidents. Symantec reported that 3AM was used after LockBit was unsuccessful in an incident, making 3AM interesting as a fallback or alternative within criminal operating chains.
The name 3AM refers to a specific ransomware payload, but the real threat is in the operator that has access. Affiliates can exchange tooling and payloads depending on availability, detection or technical errors.
Therefore 3AM should be analysed in addition to post-exploitation behaviour. The payload is the visible impact phase; the previous chain determines whether the organisation could have prevented it.
Operation and attack chain
Public reporting mentions Cobalt Strike-like use in the run-up to 3AM-impact. The actor uses post-exploitation access for exploration, lateral movement and preparation. Think of internal host discovery, domain information, privilege usage and remote execution.
In impact preparation security tools can be stopped, services are adjusted and data or systems selected. The ransomware can then encrypt files and place ransom notes. If a payload fails, another may be tried.
The main detection points are beaconing, suspicious PowerShell or command-lines, new services, remote process execution, use of adminshares, credential dumping, datataging and sudden file write bursts.
3AM underlines the importance of session and credential reset. If only the encryption is removed but the actor still has valid tokens or domain rights, the attack remains active.
Known IOCs and artifacts
Artefacts are 3AM-ransom notes, encrypted files, payload execution, Cobalt Strike-like spores, remote execution and possible service changes. Specific hashes should be added from current analyses or own telemetry.
Behaviour indicators are more important than just the payload name: C2-beaconing, privilege escalation, lateral movement, remote service creation, security tool interference and massive file changes.
Because 3AM may appear as a fallback, hunting should also look back to previous failed impact attempts. Search for blocked LockBit-like or other payloads followed by new output files or scripts.
Victim pattern and lessons
3AM is not known as a massive dominant group, but the limited perception makes it educational. A single organization can be touched by operators who try multiple payloads within the same intrusion.
The lesson is that blocking an encryption device is not automatic containment. Incident teams must fully cut off access, credentials, C2, lateral motion and data diode.
A second lesson is that detections should be generic, and a new or less known payload will then still become visible via behaviour: remote execution, service stops, datataging and encryption patterns.
How to arm yourself
Detect post-exploitation before ransomware runs. Cobalt Strike-like beaconing, unusual PowerShell, remote service creation and adminshare usage should be quickly correlated.
Ransomware block directly execute credential and session consent. Reset affected accounts, withdraw tokens, isolate lateral routes and check that C2 is still active.
Make impact preparation visible. Monitor stop security services, shadow-copy removal, bcdedit/vssadmin/wbadmin, new scheduled tasks and massive file operations.
Identity, naming and attribution
For 3AM, the operational starting point is an exact identity match. The local dossier records the following names or aliases: ThreeAM, 3AM ransomware. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.
Timeline and interpretation of dates
The source registry date available for 3AM is 2023-09-14; the metadata snapshot was collected on 2026-09-15. These timestamps describe the available record, not a proven beginning of criminal operations. Registration may follow earlier activity, and a claim can concern an older incident. A defensible timeline separates suspected intrusion, data access, discovery by the victim, publication by the claimant and discovery by the monitoring service. The profile review date is another independent timestamp. Analysts should not silently convert one date into another. When sources disagree, preserve both observations and their provenance, then explain the uncertainty rather than presenting a falsely precise attack chronology.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| tooling | Cobalt Strike-style post-exploitation activity | Symantec 3AM reporting | Observed in advance of impact. |
| behavior | fallback ransomware payload after another payload failed | Symantec reporting | Important operational pattern. |
| behavior | remote execution, service manipulation and encryption impact | public 3AM analysis | Detection on chain behavior. |
Sources
- Symantec: 3AM ransomware used as fallback
- Ransomware.live: 3AM
- MITRE ATT&CK — Valid Accounts (defensive context)
- MITRE ATT&CK — External Remote Services (defensive context)
- MITRE ATT&CK — Exfiltration Over Web Service (defensive context)
- MITRE ATT&CK — Inhibit System Recovery (defensive context)
- Ransomware.live — 3AM
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.