« All threats

Ransomware group

3am

3AM, also known as ThreeAM, is a relatively new ransomware family that emerged in late 2023, initially deployed as a fallback option when LockBit infections failed. Written in Rust for 64-bit systems, it appends the “.threeamtime” extension to encrypted files and tags them with the marker “0x666,” while deleting Volume Shadow Copies to hinder recovery. 3AM operators use a double extortion strategy, combining file encryption with data theft and threats to leak stolen information. More recent campaigns have shown increased sophistication, incorporating email bombing followed by vishing calls to convince victims to grant remote access via Microsoft Quick Assist. Attackers then deploy virtual machines containing backdoors, allowing them to remain undetected while exfiltrating data before attempting to launch the ransomware payload.

Victims in the last 90 days12

Most affected countries

  1. United States7
  2. Argentina1
  3. Australia1
  4. Colombia1
  5. France1

Most affected sectors

  1. Professional services2
  2. Manufacturing2
  3. Education1
  4. Healthcare1
  5. Hospitality & tourism1
  6. Media & entertainment1
  7. Other1
  8. Automotive1

Recent victims

OrganisationCountrySectorClaimedStatus
Safe ScaffoldingUnited StatesConstruction9/28/2026◌ Claimed (unverified)
Coosalud EPSColombiaHealthcare9/28/2026◌ Claimed (unverified)
Pistones PersanArgentinaAutomotive9/28/2026◌ Claimed (unverified)
Midwest Business TechnologyUnited StatesTechnology9/28/2026◌ Claimed (unverified)
ApexusUnited StatesProfessional services9/28/2026◌ Claimed (unverified)
BHN ExpertiseFranceProfessional services9/28/2026◌ Claimed (unverified)
St James' Anglican SchoolAustraliaEducation9/28/2026◌ Claimed (unverified)
Newman TractorUnited StatesManufacturing9/21/2026◌ Claimed (unverified)
Twin States NewsUnited StatesMedia & entertainment8/28/2026◌ Claimed (unverified)
MECASEM—Manufacturing8/18/2026◌ Claimed (unverified)
Club One CasinoUnited StatesHospitality & tourism8/5/2026◌ Claimed (unverified)
TWS-TACUnited StatesOther7/8/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.