#1 Trending Cybersecurity News & Magazine
Tuesday, September 19, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Ministry of Public Works and Housing Cyber Attack

    OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

    Araújo e Policastro Advogados Breach

    Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

    TransUnion cyber attack

    USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

    Dymocks Cyber Attack

    Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

    Retool Data Breach

    Retool Data Breach Linked to Google Authenticator Vulnerability

    Cybercrime competitions

    Inside Cybercrime Tournaments: Players, Incentives, and Impact on Security

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Ministry of Public Works and Housing Cyber Attack

    OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

    Araújo e Policastro Advogados Breach

    Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

    TransUnion cyber attack

    USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

    Dymocks Cyber Attack

    Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

    Retool Data Breach

    Retool Data Breach Linked to Google Authenticator Vulnerability

    Cybercrime competitions

    Inside Cybercrime Tournaments: Players, Incentives, and Impact on Security

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Cybersecurity News

3AM Ransomware – A Potential Backup for LockBit Ransomware?

The Threat Actor, who is presumed to be a ransomware affiliate at this point, then attempted to use 3AM ransomware as an alternative vector to compromise the target.

Ishita Tripathi by Ishita Tripathi
September 19, 2023
in Cybersecurity News
0
3AM Ransomware
585
SHARES
3.2k
VIEWS
Share on LinkedInShare on Twitter

Cybersecurity researchers have recently discovered “3AM”, a new variant of ransomware.

The name 3AM comes from the ransom notes it leaves on victims’ systems. This new threat was discovered in an instance where Threat Actors initially attempted to deploy the well-known LockBit ransomware but were unsuccessful.

You might also like

Evolution of Cybersecurity in the Middle East

Anonfiles Shuts Down: The End of an Era in Anonymous File Sharing

Everything You Need to Know About the Digital Personal Data Protection Bill 2023

While data on 3AM ransomware still remains scarce due to the limited instances where it has been observed being deployed; all indications point towards it being used as a backup variant deployed by ransomware affiliates when LockBit and other known variants are unsuccessful in compromising the target system(s).

Potential Contingency for failed LockBit attacks?

Currently, researchers are basing this assumption mostly basis an isolated incident where LockBit was oberseved to be deployed but failed to execute due to comprehensive security measures established by the intended target.

The Threat Actor, who is presumed to be a ransomware affiliate at this point, then attempted to use 3AM ransomware as an alternative vector to compromise the target.

3AM Ransomware
Graphic Illustration

Characteristics of 3AM Ransomware

Unlike most ransomware variants, 3AM is coded in the Rust programming language and does not seem to be affiliated with any known ransomware groups at this point.

Its specific targets are backup and security services like Veeam, Ivanti, and McAfee, with the express aim of disabling them prior to initiating file encryption on targeted systems.

3AM’s Extortion Techniques and Negotiation platform

3AM uses fairly standard extortion techniques typical to most ransomware variants. The target data is initially exfiltrated to the Threat Actor, and the exfiltrated files are then encrypted.

Victims will be greeted with a ransom note upon login or trying to open the aforementioned encrypted files, wherein the note states that their data will be auctioned if the demanded ransom is not paid.

Similarly, 3AM also has a fairly basic Tor Negotiation network, which victims can access using the passkey given in the ransom note. While fairly rudimentary and standard for most Ransomware groups, this step adds an extra layer of security for the Threat Actor when it comes to the negotiation/ransom payment stage.

Command-Line Parameters of the 3AM Ransomware

3AM ransomware operates based on various command-line parameters, each with a unique purpose. We have listed them below, along with the purpose they serve:

• “-k”: This requires a 32-character Base64 string, typically the “access key” from the ransom note.
• “-p” and “-h”: The functionalities of these parameters are yet to be identified.
• “-m”: This specifies the operational method, which can be either “local” or “net.”
• “-s”: This controls the speed of the encryption process by determining offsets within files.

Evasion, Reconnaissance, and Persistence methods employed

The threat actor first deployed the “gpresult” command to obtain the enforced policy settings for a particular user on the device. Additionally, the attacker ran several Cobalt Strike modules and attempted to increase their level of access to the machine by utilizing PsExec.

3AM ransomware used multiple techniques to evade detection, such as incorporating Cobalt Strike Components and running privilege escalation tools like PsExec. For reconnaissance purposes, it implements commands like “netstat”, “whoami”, and “net share”.

After their initial attempt to employ LockBit ransomware was unsuccessful, the attackers turned to 3AM. Only a small portion of the utilization of 3AM proved successful. On the organization’s network, the attackers were only able to deploy malware to three machines before two of them prevented it.

3AM also tries to establish persistence on compromised systems by creating a new user account to ensure decryption and data recovery processes do not work, and the ransom needs to be paid for victims to regain access to their data.

Conclusion: A Budding Threat Yet To Bloom?

New ransomware families emerge constantly, but the majority either vanish just as soon or never manage to establish much traction. But given that a LockBit affiliate utilized 3AM as a fallback, it’s possible that attackers are still interested in it and that it will show up again in the future.

3AM is a relatively new variant in the ransomware game with a muted impact. This is partly due to the low number of systems that have been confirmed victims of this variant (researchers have identified just 3 victims at the moment, and mitigation efforts managed to prevent 2 of them from encryption by 3AM).

While this can be a good sign, indicating that 3AM can be countered with standard mitigation and security protocols, its usage as a backup to the notorious LockBit ransomware variant will surely give it credibility amongst ransomware operators and affiliates.

We expect further development and refinement of 3AM in the near future due to these reasons, making it a threat to watch out for.

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: 3AM3AM Ransomware variantcobalt strikeLockBit ransomwareThe Cyber ExpressThe Cyber Express News
Previous Post

Evolution of Cybersecurity in the Middle East

Ishita Tripathi

Ishita Tripathi

Related Posts

Cybersecurity in the Middle East
Cybersecurity News

Evolution of Cybersecurity in the Middle East

by Ishita Tripathi
September 19, 2023
Anonfiles Shuts Down: The End of an Era in Anonymous File Sharing
Cybersecurity News

Anonfiles Shuts Down: The End of an Era in Anonymous File Sharing

by Ashish Khaitan
August 17, 2023
Digital Personal Data Protection Bill 2023
Cybersecurity News

Everything You Need to Know About the Digital Personal Data Protection Bill 2023

by Augustin Kurian
August 15, 2023 - Updated on August 16, 2023
Cyberattacks with Juhani Hintikka of WithSecure
Cybersecurity News

Deciphering the Future of Cyberattacks with Juhani Hintikka of WithSecure

by Augustin Kurian
August 13, 2023
HUB cyber security
Cybersecurity News

Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

by Chandu Gopalakrishnan
August 2, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

Ministry of Public Works and Housing Cyber Attack
Firewall Daily

OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

September 18, 2023
Araújo e Policastro Advogados Breach
Firewall Daily

Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

September 18, 2023
TransUnion cyber attack
Data Breach News

USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

September 18, 2023
Dymocks Cyber Attack
Firewall Daily

Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

September 18, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance