Skip to content
Leak site of threeam, captured by ThreatCluster

threeam

Active

25 tracked victims · First seen Aug 4, 2023 · Last seen Sep 28, 2026

About

Aggregated threat-intel description

A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.<BR> > <BR> > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

Sectors: Business Services, Manufacturing, Healthcare · Countries: US, GB, AU

Recent victims

View all →
VictimSectorCountryPostedStatus
safescaffolding.netManufacturingGBSep 28, 2026
coosalud.comHealthcareCOSep 28, 2026
pistonespersan.com.arManufacturingARSep 28, 2026
midwestbit.comTechnologyUSSep 28, 2026
apexus.comTechnologyUSSep 28, 2026
bhn-expertise.comProfessional ServicesDESep 28, 2026
stjames.wa.edu.auEducationAUSep 28, 2026
newmantractor.comManufacturingUSSep 21, 2026
wmdn.netNot FoundMDAug 29, 2026listed
mecasem.orgNot FoundMXAug 18, 2026listed
clubonecasino.comHospitalityUSMay 8, 2026
tws-tac.netNot FoundDEJul 18, 2026
guardianbarrierservices.comBusiness ServicesGBJun 29, 2026listed
acemacon.orgNot FoundMXJun 26, 2026
jetmachprod.comManufacturingJun 12, 2026
jastrebarsko.hrNot FoundCroatiaOct 5, 2026listed
palmero.comManufacturingMay 14, 2026listed
insamani.com.arAgribusinessArgentinaJun 12, 2026
bsynchro.comTechnologyDEJun 12, 2026
molinoscabodi.com.arFood & BeverageArgentinaMay 17, 2026
ws.com.brContract AdministrationBRMay 19, 2026
consultic.beHostingBEJun 12, 2026
amc.org.auEducationAUJun 12, 2026
agroexportavocados.comFood processingMXFeb 6, 2026listed
hoplongtech.comTechnologyVNJun 12, 2026

All ransomware groups · Dark web intelligence