TH

Threeam Ransomware

Active

Threat actor group tracked in the global ransomware database · Last disclosure: Aug 30, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
73
Total Victims
0.3% of all tracked
19
Countries Targeted
13
Sectors Targeted
2024
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Threeam and from this database. Figures and technique mappings are quoted from the source data, not inferred.

A newly identified ransomware family called Threeam, tracked by Symantec in September 2023, has struck 72 victims worldwide across 18 countries, expanding its reach in key sectors like Business Services, Healthcare, and Manufacturing.

Who Threeam is

A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked. > > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim. Source: https://github.com/crocodyli/ThreatActors-TTPs

Recorded activity

Disclosures attributed to Threeam in this database run from January 2024 to August 2026, totalling 73 victims — 0.3% of everything tracked here. Threeam has listed victims in 19 countries in this database, most often United States, followed by Germany and Australia. The sectors appearing most in its listings are Business Services, Healthcare, Manufacturing.

How Threeam is documented to operate

Create Account T1136 Persistence

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system. Accounts may be created on the local system or within a domain or cloud tenant. In cloud environments, adversaries may create accounts that only have access to specific services, which can reduce the chance of detection.

Mitigations: Operating System Configuration, Network Segmentation, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference →
Service Execution T1569.002 Execution

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<codeservices.exe</code) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <codesc.exe</code and Net. PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API. Tools such as PsExec and <codesc.exe</code can accept remote servers as arguments and may be used to conduct remote execution. Adversaries may leverage these mechanisms to execute malicious content.

Mitigations: Behavior Prevention on Endpoint, Restrict File and Directory Permissions, Privileged Account Management

MITRE ATT&CK reference →
Bypass User Account Control T1548.002 Privilege Escalation

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.

Mitigations: User Account Control, Privileged Account Management, Audit, Update Software

MITRE ATT&CK reference →
Remote System Discovery T1018 Discovery

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <codenet view</code using Net, or, on ESXi servers, esxcli network diag ping. Adversaries may also analyze data from local host files (ex: <codeC:\Windows\System32\Drivers\etc\hosts</code or <code/etc/hosts</code) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.

MITRE ATT&CK reference →
Network Share Discovery T1135 Discovery

Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network. File sharing over a Windows network occurs over the SMB protocol. Net can be used to query a remote system for available shared drives using the <codenet view \\\\remotesystem</code command. It can also be used to query shared drives on the local system using <codenet share</code.

Mitigations: Operating System Configuration

MITRE ATT&CK reference →
Group Policy Discovery T1615 Discovery

Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that can be manipulated or used to blend in the environment. Group Policy allows for centralized management of user and computer settings in Active Directory (AD). Group policy objects (GPOs) are containers for group policy settings made up of files stored within a predictable network path \<DOMAIN\SYSVOL\<DOMAIN\Policies\.

MITRE ATT&CK reference →
Exfiltration Over Alternative Protocol T1048 Exfiltration

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server. Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to encrypt and/or obfuscate these alternate channels. Exfiltration Over Alternative Protocol can be done using various common operating system utilities such as Net/SMB or FTP. On macOS and Linux <codecurl</code may be used to invoke protocols such as HTTP/S or FTP/S to exfiltrate data from a system.

Mitigations: Network Intrusion Prevention, Filter Network Traffic, Data Loss Prevention, Network Segmentation, User Account Management, Restrict File and Directory Permissions

MITRE ATT&CK reference →
Data Encrypted for Impact T1486 Impact

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Mitigations: Data Backup, Behavior Prevention on Endpoint

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Threeam across its recorded activity. They describe the group overall, not any single incident.

YARA detection rules

threeam.yar
/*
ThreeAM ransomware (Rust-based)
*/

rule ThreeAM_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.threeam"
        description = "Detects ThreeAM ransomware ransom note"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $s1 = "RECOVER-FILES.txt" ascii nocase
        $s2 = "ThreeAM" ascii nocase
        $s3 = "Three Am" ascii nocase
        $s4 = ".threeamtime" ascii

    condition:
        any of them
}

rule ThreeAM_PE
{
    meta:
        author = "ransomware.live"
        family = "ransomware.threeam"
        description = "Detects ThreeAM ransomware executable"
        date = "2026-05-04"
        severity = 9
        score = 90

    strings:
        $s1 = "ThreeAM" ascii wide
        $s2 = ".threeamtime" ascii
        $s3 = "RECOVER-FILES" ascii

    condition:
        uint16(0) == 0x5A4D and 2 of them
}

Community-contributed rules for Threeam, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Threeam is a ransomware threat group that has disclosed 73 victims in publicly accessible leak site data, representing 0.3% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Threeam in our dataset dates to January 2024.

Geographically, Threeam has targeted organisations in 19 countries. The most frequently targeted nation is United States with 32 victim organisations. Other heavily targeted nations include Germany, Australia, United Kingdom.

Industry-wise, Threeam shows a concentration in the Business Services, Healthcare, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Threeam likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 73 most recent of the 73 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 73 of 73)

# Organization Country Sector Date
1 wmdn.net wmdn.net MD Aug 30, 2026
2 mecasem.org mecasem.org 🇲🇽 Mexico Aug 19, 2026
3 clubonecasino.com clubonecasino.com 🇺🇸 United States Hospitality Aug 6, 2026
4 tws-tac.net tws-tac.net 🇩🇪 Germany Jul 18, 2026
5 tws-tac.net tws-tac.net 🇩🇪 Germany Jul 18, 2026
6 guardianbarrierservices.com guardianbarrierservices.com 🇬🇧 United Kingdom Business Services Jun 29, 2026
7 acemacon.org acemacon.org 🇲🇽 Mexico Jun 28, 2026
8 agroexportavocados.com agroexportavocados.com 🇲🇽 Mexico Agriculture and Food Production Jun 12, 2026
9 amc.org.au amc.org.au 🇦🇺 Australia Healthcare Jun 12, 2026
10 bsynchro.com bsynchro.com 🇩🇪 Germany Technology Jun 12, 2026
11 consultic.be consultic.be 🇧🇪 Belgium Business Services Jun 12, 2026
12 hoplongtech.com hoplongtech.com 🇻🇳 Vietnam Technology Jun 12, 2026
13 insamani.com.ar insamani.com.ar 🇦🇷 Argentina Healthcare Jun 12, 2026
14 jastrebarsko.hr jastrebarsko.hr 🇭🇷 Croatia Government & Defense Jun 12, 2026
15 jetmachprod.com jetmachprod.com Manufacturing Jun 12, 2026
16 mgrlaw.com mgrlaw.com 🇺🇸 United States Business Services Jun 12, 2026
17 molinoscabodi.com.ar molinoscabodi.com.ar 🇦🇷 Argentina Agriculture and Food Production Jun 12, 2026
18 palmero.com palmero.com Jun 12, 2026
19 ws.com.br ws.com.br 🇧🇷 Brazil Business Services Jun 12, 2026
20 aceforwarding.com aceforwarding.com Transportation/Logistics May 1, 2026
21 austinplasticandreconstructivesurgery.com austinplasticandreconstructivesurgery.com 🇺🇸 United States Healthcare May 1, 2026
22 bun.nl bun.nl 🇳🇱 Netherlands Agriculture and Food Production May 1, 2026
23 curedentalbeltontx.com curedentalbeltontx.com 🇺🇸 United States Healthcare May 1, 2026
24 hsjlawyers.com hsjlawyers.com Business Services May 1, 2026
25 ic-controls.com ic-controls.com 🇩🇪 Germany Manufacturing May 1, 2026
26 sequoiadental.com sequoiadental.com 🇺🇸 United States Healthcare May 1, 2026
27 townofnorwell.net townofnorwell.net 🇺🇸 United States Public Sector May 1, 2026
28 wyomingcountyny.gov wyomingcountyny.gov 🇺🇸 United States Public Sector May 1, 2026
29 dbhcares.com dbhcares.com 🇺🇸 United States Healthcare May 25, 2025
30 gosvt.com gosvt.com 🇺🇸 United States Technology May 25, 2025
31 icgad.com icgad.com 🇺🇸 United States Construction May 25, 2025
32 icmtx.com icmtx.com 🇺🇸 United States Technology May 25, 2025
33 iss-na.com iss-na.com 🇺🇸 United States Business Services May 25, 2025
34 jastreet.com jastreet.com 🇺🇸 United States Construction May 25, 2025
35 kkp.law kkp.law 🇺🇸 United States Business Services May 25, 2025
36 neffendorfblockercpa.com neffendorfblockercpa.com 🇺🇸 United States Financial Services May 25, 2025
37 vazirilaw.com vazirilaw.com 🇺🇸 United States Business Services May 25, 2025
38 leonardo.com leonardo.com 🇮🇹 Italy Technology Feb 13, 2025
39 sehma.com sehma.com 🇩🇪 Germany Healthcare Feb 11, 2025
40 corehandf.com corehandf.com 🇺🇸 United States Consumer Services Feb 5, 2025
41 soitinlaine.fi soitinlaine.fi 🇫🇮 Finland Consumer Services Jan 30, 2025
42 anwsd.org anwsd.org 🇺🇸 United States Education Jan 15, 2025
43 hapsch.de hapsch.de 🇩🇪 Germany Healthcare Jan 9, 2025
44 kuritaamerica.com kuritaamerica.com 🇯🇵 Japan Manufacturing Dec 17, 2024
45 hobokennj.gov hobokennj.gov 🇺🇸 United States Public Sector Dec 4, 2024
46 midstatesindustrial.com midstatesindustrial.com 🇺🇸 United States Manufacturing Nov 13, 2024
47 anuenterprise.com.au anuenterprise.com.au 🇦🇺 Australia Business Services Oct 31, 2024
48 caillau.com.br caillau.com.br 🇧🇷 Brazil Manufacturing Oct 31, 2024
49 freedomhomecare.net freedomhomecare.net 🇺🇸 United States Healthcare Oct 31, 2024
50 inhometexas.com inhometexas.com 🇺🇸 United States Healthcare Oct 31, 2024
51 mpspromotions.com mpspromotions.com 🇦🇺 Australia Business Services Oct 31, 2024
52 sandray.com sandray.com 🇺🇸 United States Manufacturing Oct 31, 2024
53 carolinaarthritis.com carolinaarthritis.com 🇺🇸 United States Healthcare Oct 24, 2024
54 oklahomasleepinstitute.com oklahomasleepinstitute.com 🇺🇸 United States Healthcare Oct 10, 2024
55 carlile-group.com carlile-group.com 🇬🇧 United Kingdom Transportation/Logistics Sep 30, 2024
56 mctas.org.au mctas.org.au 🇦🇺 Australia Healthcare Sep 30, 2024
57 mnpl.com.sg mnpl.com.sg 🇸🇬 Singapore Transportation/Logistics Sep 30, 2024
58 sacredheart.southwark.sch.uk sacredheart.southwark.sch.uk 🇬🇧 United Kingdom Education Sep 30, 2024
59 verco.co.uk verco.co.uk 🇬🇧 United Kingdom Manufacturing Sep 30, 2024
60 gestiriego.com gestiriego.com 🇪🇸 Spain Agriculture and Food Production Sep 18, 2024
61 brunswickhospitalcenter.org brunswickhospitalcenter.org 🇺🇸 United States Healthcare Sep 12, 2024
62 escriba.com.br escriba.com.br 🇧🇷 Brazil Technology May 16, 2024
63 thermalsolutionsllc.com thermalsolutionsllc.com 🇺🇸 United States Manufacturing May 16, 2024
64 compagniedephalsbourg.com compagniedephalsbourg.com 🇫🇷 France Business Services Apr 15, 2024
65 kh.org kh.org 🇺🇸 United States Healthcare Mar 25, 2024
66 moore-tibbits.co.uk moore-tibbits.co.uk 🇬🇧 United Kingdom Business Services Feb 27, 2024
67 abcor.com.au abcor.com.au 🇦🇺 Australia Business Services Feb 22, 2024
68 mtmrobotics.com mtmrobotics.com 🇺🇸 United States Technology Feb 22, 2024
69 doneff.com doneff.com 🇺🇸 United States Agriculture and Food Production Feb 21, 2024
70 garonproducts.com garonproducts.com 🇺🇸 United States Manufacturing Feb 12, 2024
71 etsolutions.com.mx etsolutions.com.mx 🇲🇽 Mexico Business Services Feb 1, 2024
72 pharrusa.com pharrusa.com 🇺🇸 United States Manufacturing Jan 12, 2024
73 thecsi.com thecsi.com 🇨🇦 Canada Business Services Jan 12, 2024

Frequently Asked Questions

What is Threeam ransomware?

Threeam is a ransomware threat group that has claimed 73 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Threeam attacked?

Threeam has claimed 73 victims in our database, representing 0.3% of all tracked ransomware attacks. The most targeted countries are United States, Germany, Australia, United Kingdom.

Which countries does Threeam target?

Threeam has attacked organizations in 19 countries. The top targeted countries are: United States, Germany, Australia, United Kingdom.

Which industries does Threeam target?

Threeam most frequently targets the Business Services, Healthcare, Manufacturing sectors based on victim disclosures in our database.

Is Threeam still active?

Threeam's most recent victim disclosure in our database was on August 30, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.