惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
量子位
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
U
Unit 42
IT之家
IT之家
F
Fortinet All Blogs
GbyAI
GbyAI
MongoDB | Blog
MongoDB | Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
大猫的无限游戏
大猫的无限游戏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Register - Security
The Register - Security
NISL@THU
NISL@THU
Webroot Blog
Webroot Blog
A
Arctic Wolf
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
Recent Announcements
Recent Announcements
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Blog — PlanetScale
Blog — PlanetScale
L
LangChain Blog
P
Palo Alto Networks Blog
Y
Y Combinator Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
有赞技术团队
有赞技术团队
Engineering at Meta
Engineering at Meta
C
Cybersecurity and Infrastructure Security Agency CISA
aimingoo的专栏
aimingoo的专栏
Know Your Adversary
Know Your Adversary
Cyberwarzone
Cyberwarzone
Martin Fowler
Martin Fowler
The Hacker News
The Hacker News
P
Privacy International News Feed
T
Threat Research - Cisco Blogs
G
GRAHAM CLULEY
宝玉的分享
宝玉的分享
博客园 - 聂微东
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
S
Securelist
T
The Exploit Database - CXSecurity.com
T
Threatpost
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
F
Full Disclosure

RansomLook – Last entries

Direwolf · RansomLook Inc Ransom · RansomLook Qilin · RansomLook Bavacai · RansomLook Killsec3 · RansomLook Black X · RansomLook Coinbase Cartel · RansomLook Audit Team · RansomLook Abyss-Data · RansomLook Play · RansomLook Ailock · RansomLook Bravox · RansomLook Gunra · RansomLook Genesis · RansomLook Pear · RansomLook Termite · RansomLook Everest · RansomLook Worldleaks · RansomLook Payoutsking · RansomLook Nightspire · RansomLook Triple X · RansomLook Spy Corporate · RansomLook Nova · RansomLook Titan · RansomLook Stormous · RansomLook Nitrogen · RansomLook Money Message · RansomLook Akira · RansomLook Sinobi · RansomLook Icarus · RansomLook Ms13-089 · RansomLook Space Bears · RansomLook Cmd Organization · RansomLook Radar · RansomLook Aurora · RansomLook Secp0 · RansomLook Fulcrumsec · RansomLook Mnt6 · RansomLook Clop · RansomLook Rhysida · RansomLook Tridentlocker · RansomLook Brain Cipher · RansomLook M3rx · RansomLook Lockbit5 · RansomLook Securotrop · RansomLook Leak Bazaar · RansomLook Morpheus · RansomLook Embargo · RansomLook kairos details Leakeddata · RansomLook Safepay · RansomLook Prinz Eugen · RansomLook Crypto24 · RansomLook Ransomexx · RansomLook Payload · RansomLook Leaknet · RansomLook Vect · RansomLook Interlock · RansomLook Nasir Security · RansomLook Black Nevas · RansomLook Chaos · RansomLook Medusa · RansomLook Ransomhouse · RansomLook Affordable Oil By dragonforce Krybit · RansomLook Gauthier Tissus By lamashtu medical-park By blackwater Exitium · RansomLook Shinyhunters · RansomLook shadowbyt3$ details The Gentlemen · RansomLook insomnia details Eraleign (Apt73) · RansomLook anubis details lynx details beast details timc details
3am · RansomLook
RansomLook · 2026-06-13 · via RansomLook – Last entries

3am logo

90posts (all time)

12last 30 days

12last 7 days

79% avg uptime 30d

Activity · last 30 days last post

3am logo 3am logo

Parsing: enabled

View crypto

Description

3AM, also known as ThreeAM, is a relatively new ransomware family that emerged in late 2023, initially deployed as a fallback option when LockBit infections failed. Written in Rust for 64-bit systems, it appends the “.threeamtime” extension to encrypted files and tags them with the marker “0x666,” while deleting Volume Shadow Copies to hinder recovery. 3AM operators use a double extortion strategy, combining file encryption with data theft and threats to leak stolen information. More recent campaigns have shown increased sophistication, incorporating email bombing followed by vishing calls to convince victims to grant remote access via Microsoft Quick Assist. Attackers then deploy virtual machines containing backdoors, allowing them to remain undetected while exfiltrating data before attempting to launch the ransomware payload.

External Analysis6
Ransom notes1
  • RECOVER-FILES.txt txt
Mail1
Urls1
File servers1
Chat servers1
Activity (interactive) 90
Posts90