logo

Researchers link 3AM ransomware to Conti, Royal cybercrime gangs

ID: 01777f0e-cfdc-5f04-bb5f-de13527ee926

STIX ID: report--01777f0e-cfdc-5f04-bb5f-de13527ee926

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-01-20

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Security researchers link the recently emerged 3AM/ThreeAM ransomware operation to the Conti syndicate and Royal/Blacksuit affiliates based on overlapping infrastructure, TTPs, and reused artifacts; investigators found IOCs including IP 185.202.0.111, PowerShell/Cobalt Strike artifacts, SOCKS4 proxy usage, TLS certificates, and hosting overlaps on UAB Cherry Servers. 3AM has leaked data for at least 19 victims on a Tor site and tested a novel extortion tactic using automated replies on X/Twitter to broadcast breaches and pressure victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.