Skip to main content

Operator dossier

Threeam is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 85 public victims claimed by this operator between September 14, 2023 and June 12, 2026. Threeam is a financially motivated ransomware group that emerged in September 2023, operating as a relatively new player in the ransomware ecosystem with 64 documented victims across multiple countries and sectors. The group's origin and potential affiliations remain unclear due to limited public documentation from major security agencies, though their targeting patterns suggest a broad opportunistic approach rather than nation-state backing. Based on available victim data, Threeam appears to employ common initial access vectors targeting organizations across business services, healthcare, manufacturing, and technology sectors, with the United States, United Kingdom, Australia, France, and Brazil representing their primary geographic focus areas. While specific technical details about their encryption methods and extortion tactics have not been extensively documented by major threat intelligence firms, their emergence in late 2023 and victim count suggests they have established operational capabilities within the competitive ransomware landscape. The group's current operational status remains active based on the recency of their emergence, though detailed law enforcement actions or disruption efforts have not been publicly reported by CISA, FBI, or other major security organizations.

Most-targeted sectors

Most-affected countries

Recent disclosures by Threeam

Most recent 30 of 85 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for Threeam

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

Threeam

85 victims indexed · first seen 3 years ago · last activity 16 hours ago

85
Victims indexed
#80 of 356 tracked operators
2y 9m
Active period
Sep 2023 → Jun 2026
10
Countries hit
top United States · 31

At a glance

Status
inactive
First seen
3 years ago
Last activity
16 hours ago
Onion sites
1 known endpoint
Primary sector
Business Services · 10 hits

About

Threeam is a financially motivated ransomware group that emerged in September 2023, operating as a relatively new player in the ransomware ecosystem with 64 documented victims across multiple countries and sectors. The group's origin and potential affiliations remain unclear due to limited public documentation from major security agencies, though their targeting patterns suggest a broad opportunistic approach rather than nation-state backing. Based on available victim data, Threeam appears to employ common initial access vectors targeting organizations across business services, healthcare, manufacturing, and technology sectors, with the United States, United Kingdom, Australia, France, and Brazil representing their primary geographic focus areas. While specific technical details about their encryption methods and extortion tactics have not been extensively documented by major threat intelligence firms, their emergence in late 2023 and victim count suggests they have established operational capabilities within the competitive ransomware landscape. The group's current operational status remains active based on the recency of their emergence, though detailed law enforcement actions or disruption efforts have not been publicly reported by CISA, FBI, or other major security organizations.

Timeline

16 months
2023-09-01T00:00:00+00:00 · 102023-10-01T00:00:00+00:00 · 22023-11-01T00:00:00+00:00 · 32023-12-01T00:00:00+00:00 · 42024-01-01T00:00:00+00:00 · 22024-02-01T00:00:00+00:00 · 62024-03-01T00:00:00+00:00 · 12024-04-01T00:00:00+00:00 · 12024-05-01T00:00:00+00:00 · 22024-09-01T00:00:00+00:00 · 72024-10-01T00:00:00+00:00 · 82024-11-01T00:00:00+00:00 · 12024-12-01T00:00:00+00:00 · 22025-01-01T00:00:00+00:00 · 32025-02-01T00:00:00+00:00 · 32025-05-01T00:00:00+00:00 · 9
2023-09-01T00:00:00+00:002025-05-01T00:00:00+00:00

Top countries

🇺🇸 United States
31
🇬🇧 United Kingdom
5
🇦🇺 Australia
4
🇫🇷 France
2
🇧🇷 Brazil
2
🇩🇪 Germany
2
🇷🇴 Romania
1
🇪🇸 Spain
1

Top sectors

Business Services
10
Healthcare
8
Manufacturing
7
Technology
5
Agriculture and Food Production
2
Transportation/Logistics
2
Financial Services
1
Entertainment
1

MITRE ATT&CK

5 techniques · 4 tactics

Tactics

Initial AccessExecutionDefense EvasionImpact

Techniques

  • T1566Phishing
  • T1190Exploit Public-Facing Application
  • T1204User Execution
  • T1027Obfuscated Files or Information
  • T1486Data Encrypted for Impact

Recent victims

Loading…

Onion infrastructure

1 known
  • http://threeamkelxicjsaf2czjyz2lc4q3ngqkxhhlexyfcp2o6raw4rphyad.onion

Source

Updated 16 hours ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time Threeam posts a victim.

Add Threeam to your watchlist — Pro pings you within 5 minutes of any new Threeam leak-site post, Telegram callout, or affiliate-rebrand inference.