logo

3AM Ransomware Adopts Email Bombing, Vishing Combo Attack

ID: 26431882-e14d-56cc-9b76-74259ae66c42

STIX ID: report--26431882-e14d-56cc-9b76-74259ae66c42

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2025-05-22

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers tracked 3AM ransomware actors leveraging an email‑bombing followed by vishing (via Microsoft Teams) to trick employees into granting remote access (Quick Assist), deploy a virtual machine hosting a QDoor Trojan, and steal data — the ransomware stage was later blocked but attackers remained on the network for nine days. Sophos documented multiple incidents and attempts using this playbook, linked 3AM to prior ransomware groups, and recommended user awareness, strict remote‑access policies, and application control to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.