White Paper
THREAT PROFILE: ThreeAM Ransomware
ThreeAM is a ransomware-as-a-service (RaaS) group first identified in 2023 that uses a double-extortion model, combining data encryption with the theft of sensitive information to pressure victims into paying a ransom. If payment is not made, the group threatens to publish stolen data through a dedicated leak site. ThreeAM has frequently targeted organizations in the healthcare sector, particularly in North America, where operational disruptions can have significant consequences. The threat profile examines the group’s operations, targeted industries and regions, known tools, and associations with other ransomware groups, including BlackSuit and Conti. It also analyzes observed behaviors in Windows environments and maps the group’s tactics, techniques, and procedures to the MITRE ATT&CK fr
