Ransomware Group: threeam

Fecha
25 Jun 2026
Actor
threeam
Tipo
Threat-actor
Pais
Unknown
Sector
-
Confianza
high
55
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

1IOCs
0TTPs
threeamActor
UnknownPais
Executive Summary
Perfil del grupo segun ransomware.anggipradana.com.

Key Points

  • Ransomware Dashboard

Grupo Ransomware: threeam

Perfil del grupo segun ransomware.anggipradana.com.

CampoValor
Alias
Pais
Estado

Descripcion

A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.<BR> > <BR> > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

Referencias

Diamond Model

Adversary
threeam
Ver perfil →
Victim
Ransomware Group: threeam
Capability
Threat-actor
Infrastructure
github.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

18 enlaces
Nodo actual
Ransomware Group: threeam
threeam

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain github.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor threeam en el blog → Ver threeam en IntelTracker → URL IntelTracker: ransomware.anggipradana.com → Fuente OSINT: ransomware.anggipradana.com → Buscar threeam en APTTrail → Repositorio APTTrail → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes