Ransomware Intelligence

threeam

Ransomware group profile

20Victims
RussiaSource country
66Impact score
Also Known As
Time 3AM

Description

Threeam is a ransomware group that emerged in February 2023, known for its quick deployment and sophisticated encryption methods. Primarily motivated by financial gain, they employ double extortion tactics to pressure high-value organizations into paying ransoms after encrypting their data and exfiltrating sensitive information.

Key insights

  • Utilizes custom-built ransomware variants written in Rust.
  • Employs social engineering tactics to gain initial access, including phishing and voice phishing.
  • Focuses on double extortion by encrypting files and threatening to release sensitive data publicly.
  • Targets high-value sectors such as healthcare and financial services.
  • Uses advanced evasion techniques like disabling security software and deleting Volume Shadow Copies.
  • Linked to other ransomware operations like LockBit and Conti, indicating a collaborative nature among threat groups.

Threat Level & Status Breakdown

For threeam · Based on incidents in selected period

2.8threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality3.3/ 10

Status Breakdown

Claimed100.0%20
First seenNov 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for threeam in the selected period

20Total attacks
11peak in Jun
6.7avg / month
↑ 10 vs first month
NovMayJun036912

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for threeam

Other

T1486

T1486

T1490

T1490

T1021

T1021

T1562

T1562

T1080

T1080

T1078

T1078

T1547

T1547

T1041

T1041

T1021.001

T1021.001

T1059

T1059

Victims(20)

CompanyDomainCountryIndustryStatusDiscovered
jetmachprod.comjetmachprod.comUS United StatesManufacturing
Claimed
7 days ago
jastrebarsko.hrjastrebarsko.hrHR CroatiaGovernment & Defense
Claimed
7 days ago
palmero.compalmero.comAR ArgentinaOther
Claimed
7 days ago
insamani.com.arinsamani.com.arAR ArgentinaOther
Claimed
7 days ago
bsynchro.combsynchro.comDE GermanyTechnology
Claimed
7 days ago
molinoscabodi.com.armolinoscabodi.com.arAR ArgentinaOther
Claimed
7 days ago
ws.com.brws.com.brBR BrazilProfessional Services
Claimed
7 days ago
amc.org.auamc.org.auAU AustraliaEducation
Claimed
7 days ago
agroexportavocados.comagroexportavocados.comMX MexicoOther
Claimed
7 days ago
hoplongtech.comhoplongtech.comVN VietnamTechnology
Claimed
7 days ago
mgrlaw.commgrlaw.comUS United StatesProfessional Services
Claimed
7 days ago
wyomingcountyny.govwyomingcountyny.govUS United StatesGovernment & Defense
Claimed
about 2 months ago
sequoiadental.comsequoiadental.comUS United StatesHealthcare
Claimed
about 2 months ago
townofnorwell.nettownofnorwell.netUS United StatesGovernment & Defense
Claimed
about 2 months ago
curedentalbeltontx.comcuredentalbeltontx.comUS United StatesHealthcare
Claimed
about 2 months ago
austinplasticandreconstructivesurgery.comaustinplasticandreconstructivesurgery.comUS United StatesHealthcare
Claimed
about 2 months ago
hsjlawyers.comhsjlawyers.comCA CanadaProfessional Services
Claimed
about 2 months ago
bun.nlbun.nlNL NetherlandsOther
Claimed
about 2 months ago
ic-controls.comic-controls.comDE GermanyManufacturing
Claimed
about 2 months ago
aceforwarding.comaceforwarding.comUS United StatesTransportation
Claimed
about 2 months ago