Skip to main content

Operator dossier

Threeam is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 88 public victims claimed by this operator between September 14, 2023 and July 18, 2026. Threeam is a financially motivated ransomware group that emerged in September 2023, operating as a relatively new player in the ransomware ecosystem with 64 documented victims across multiple countries and sectors. The group's origin and potential affiliations remain unclear due to limited public documentation from major security agencies, though their targeting patterns suggest a broad opportunistic approach rather than nation-state backing. Based on available victim data, Threeam appears to employ common initial access vectors targeting organizations across business services, healthcare, manufacturing, and technology sectors, with the United States, United Kingdom, Australia, France, and Brazil representing their primary geographic focus areas. While specific technical details about their encryption methods and extortion tactics have not been extensively documented by major threat intelligence firms, their emergence in late 2023 and victim count suggests they have established operational capabilities within the competitive ransomware landscape. The group's current operational status remains active based on the recency of their emergence, though detailed law enforcement actions or disruption efforts have not been publicly reported by CISA, FBI, or other major security organizations.

Most-targeted sectors

Most-affected countries

Recent disclosures by Threeam

Most recent 85 of 88 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Threeam

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

Threeam

88 victims indexed · first seen 3 years ago · last activity 11 days ago

88
Victims indexed
#82 of 370 tracked operators
2y 10m
Active period
Sep 2023 → Jul 2026
25
Countries hit
top United States · 39

At a glance

Status
inactive
First seen
3 years ago
Last activity
11 days ago
Onion sites
1 known endpoint
Primary sector
Business Services · 17 hits

About

Threeam is a financially motivated ransomware group that emerged in September 2023, operating as a relatively new player in the ransomware ecosystem with 64 documented victims across multiple countries and sectors. The group's origin and potential affiliations remain unclear due to limited public documentation from major security agencies, though their targeting patterns suggest a broad opportunistic approach rather than nation-state backing. Based on available victim data, Threeam appears to employ common initial access vectors targeting organizations across business services, healthcare, manufacturing, and technology sectors, with the United States, United Kingdom, Australia, France, and Brazil representing their primary geographic focus areas. While specific technical details about their encryption methods and extortion tactics have not been extensively documented by major threat intelligence firms, their emergence in late 2023 and victim count suggests they have established operational capabilities within the competitive ransomware landscape. The group's current operational status remains active based on the recency of their emergence, though detailed law enforcement actions or disruption efforts have not been publicly reported by CISA, FBI, or other major security organizations.

Timeline

18 months
2023-09-01T00:00:00+00:00 · 102023-10-01T00:00:00+00:00 · 22023-11-01T00:00:00+00:00 · 32023-12-01T00:00:00+00:00 · 42024-01-01T00:00:00+00:00 · 22024-02-01T00:00:00+00:00 · 62024-03-01T00:00:00+00:00 · 12024-04-01T00:00:00+00:00 · 12024-05-01T00:00:00+00:00 · 22024-09-01T00:00:00+00:00 · 72024-10-01T00:00:00+00:00 · 82024-11-01T00:00:00+00:00 · 12024-12-01T00:00:00+00:00 · 22025-01-01T00:00:00+00:00 · 32025-02-01T00:00:00+00:00 · 32025-05-01T00:00:00+00:00 · 92026-05-01T00:00:00+00:00 · 92026-06-01T00:00:00+00:00 · 12
2023-09-01T00:00:00+00:002026-06-01T00:00:00+00:00

Top countries

🇺🇸 United States
39
🇺🇸 United States
6
🇬🇧 United Kingdom
5
🇦🇺 Australia
4
🇪🇸 Spain
3
🇫🇷 France
2
🇦🇷 Argentina
2
🇩🇪 Germany
2

Top sectors

Business Services
17
Manufacturing
14
Healthcare
13
Technology
7
Agriculture and Food Production
5
Transportation/Logistics
3
Construction
2
Public Sector
2

MITRE ATT&CK

5 techniques · 4 tactics

Tactics

Initial AccessExecutionDefense EvasionImpact

Techniques

  • T1566Phishing
  • T1190Exploit Public-Facing Application
  • T1204User Execution
  • T1027Obfuscated Files or Information
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

1 known
  • http://threeamkelxicjsaf2czjyz2lc4q3ngqkxhhlexyfcp2o6raw4rphyad.onion

Source

Updated 11 days ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Threeam posts a victim.

Add Threeam to your watchlist — Pro pings you within 5 minutes of any new Threeam leak-site post, Telegram callout, or affiliate-rebrand inference.