ZeroHour

3am

ransomware group · aka 3AM, ThreeAM · unknown (no confirmed country of origin in public reporting) · active since 2023-09 (first observed in the wild; documented by SentinelOne and Sophos in October 2023)

Victims · 7d
0flat
Victims · 30d
2active targets
Victims · 90d
6
All-time (tracked)
96since 2023-09-17
Last post
08-29 01:35UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

3AM (ThreeAM) is a low-volume double-extortion ransomware group named for the '3 am' opener of its ransom notes, whose initial Windows encryptor was written in Rust. It drew attention in October 2023 when Sophos documented an affiliate deploying 3AM as a fallback after a failed LockBit deployment, including the unusual tactic of emailing and phoning victims to apply pressure. Operations are affiliate-style, with data exfiltration before encryption and leak-site publication used for extortion; vendor research has also noted tooling and TTP overlaps with the Fog ransomware group, though the relationship is not confirmed. Public reporting has not established the group's origin, typical initial-access vectors, or victim earnings. Dashboard tracking shows 18 leak-site victims since 2026-06-12 (2 in the last 30 days), with the most recent post on 2026-08-29.

Tactics & tooling
  • Deploys Rust-based Windows ransomware; notes open with '3 am' (SentinelOne/Sophos, 2023)
  • Double extortion: data exfiltration before encryption, leak-site publication for pressure
  • Directly contacts victims by email and phone calls when leak-site pressure fails (Sophos, 2023)
  • Affiliate-style deployment; observed as fallback after a failed LockBit affiliate attempt (Sophos, 2023)
  • Clears event logs and deletes volume shadow copies to impede recovery (vendor reporting, 2023)
  • Uses legitimate remote-access and file-transfer utilities for operations (e.g., putty, FileZilla)
  • Reported tooling/TTP overlap with Fog ransomware; relationship unconfirmed (vendor research, 2024)
  • Initial access vectors and exploited CVEs not consistently attributed in public reporting
Targeted sectors
manufacturinghospitality and gaminggovernment (local)professional and IT servicesagriculture and food
Notable public victims

jastrebarsko.hr (Town of Jastrebarsko, Croatia), clubonecasino.com, molinoscabodi.com.ar, bsynchro.com, mecasem.org, jetmachprod.com, insamani.com.ar, palmero.com, wmdn.net, tws-tac.net

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
freedomhomecare.net · Oct 31, 2024
carolinaarthritis.com · Oct 24, 2024
sacredheart.southwark.sch.uk · Oct 24, 2024
oklahomasleepinstitute.com · Oct 24, 2024
oklahomasleepinstitute.co... · Oct 10, 2024
carlile-group.com · Sep 30, 2024
sacredheart.southwark.sch... · Sep 30, 2024
mctas.org.au · Sep 30, 2024
mnpl.com.sg · Sep 30, 2024
verco.co.uk · Sep 30, 2024
gestiriego.com · Sep 17, 2024
brunswickhospitalcenter.org · Sep 13, 2024
brunswickhospitalcenter.o... · Sep 12, 2024
visitingphysiciansnetwork... · Aug 7, 2024
compagniedephalsbourg.com... · Aug 7, 2024
thermalsolutionsllc.com · May 15, 2024
escriba.com.br · May 15, 2024
compagniedephalsbourg.com · Apr 15, 2024
kh.org · Mar 25, 2024
moore-tibbits.co.uk · Feb 27, 2024
mtmrobotics.com · Feb 22, 2024
abcor.com.au · Feb 22, 2024
doneff.com · Feb 21, 2024
garonproducts.com · Feb 13, 2024
etsolutions.com.mx · Feb 1, 2024
thecsi.com · Jan 12, 2024
pharrusa.com · Jan 12, 2024
shareharris.com · Dec 12, 2023
woodruffenterprises.com · Dec 12, 2023
syrtech.com · Dec 6, 2023
ussignandmill.com · Dec 5, 2023
carrellblanton.com · Nov 27, 2023
ds-granit.fr · Nov 22, 2023
nealbrothers.co.uk · Nov 18, 2023
maniland.co.uk · Oct 26, 2023
claimtek.com · Oct 26, 2023
simmonsequip.com · Sep 28, 2023
haciendazorita.com · Sep 22, 2023
fi-tech.com · Sep 22, 2023
neuraxpharm.com · Sep 22, 2023
pvbfabs.com · Sep 17, 2023
wdgroup.com.my · Sep 17, 2023
intechims.com · Sep 17, 2023
zero-pointorganics.com · Sep 17, 2023
visitingphysiciansnetwork.com · Sep 17, 2023
clearwaterlandscape.com · Sep 17, 2023

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .