An affiliate of the 3AM ransomware gang appears to be leveraging sophisticated social engineering techniques to infiltrate corporate networks, combining email bombing, IT support phone scams , and remote access tools. Its goal is to extract credentials from unsuspecting employees.

These techniques — previously identified in attacks by the Black Basta and FIN7 — appear to be increasingly being adopted, as they prove to be particularly effective.
According to a report by Sophos, at least 55 such incidents were recorded between November 2024 and January 2025, linked to two different threat clusters. The attacks mimicked Black Basta's methodology and included email bombing, vishing via Microsoft Teams , and abuse of Microsoft's Quick Assist tool .
See also: VanHelsing ransomware-as-a-service: Source code leaked
A decisive role in the spread of these techniques was allegedly played by the leak of internal Black Basta conversations , which contained ready-made phishing scripts and instructions for deception via Microsoft Teams (as a "fake helpdesk").
3AM ransomware: New forms of attack
In the first quarter of 2025, one of these attacks, targeting a Sophos customer, used a variation of the above attack model, avoiding Teams and opting for actual voice phishing over the phone.
The call appeared to come from the target company's real IT department. The call was timed with a spate of spam emails — 24 messages were sent in just three minutes — to add to the sense of urgency.
The employee was tricked into opening Microsoft Quick Assist and granting remote access, believing they were facing a threat. Through this access, the attacker downloaded malware from a fake domain, which included a VBS script , QEMU emulator , and a Windows 7 image with the QDoor backdoor pre-installed .
See also: KeePass: Fake version leads to ransomware infection
Cybercriminals exploited QEMU to bypass detection mechanisms. They created virtual machines to route network traffic in a way that ensured permanent but undetectable access to corporate infrastructure.
Through this infrastructure, the attackers conducted reconnaissance with tools such as WMIC and PowerShell, created a local administrator account for access via RDP, installed the commercial remote administration tool XEOXRemote, and ultimately compromised a domain administrator account.
Despite the active interventions of Sophos, which limited the attackers' movements within the network and prevented attempts to disable defenses, cybercriminals managed to extract 868 GB of data by exploiting GoodSync.
The attempted activation of the 3AM ransomware was detected and blocked in a timely manner, limiting the damage to only data theft and encryption of a single host computer.
Duration and defenses
The attack lasted a total of nine days, with the mass data extraction being completed by the third day. The attackers attempted further moves, but the defense mechanisms stopped them.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Sophos, as part of its analysis, recommends specific protection measures to prevent similar attacks:
- Checking administrative accounts for weaknesses.
- Using XDR (Extended Detection and Response) tools to detect and block unauthorized applications such as QEMU and GoodSync .
- Enforce a PowerShell policy that only allows signed scripts.
- Creation of blacklists based on indicators of violation (IOCs) for known malicious addresses, domains and files.
Finally, it is emphasized that staff training is the most critical defense factor against phishing emails and vishing phone attacks, which continue to be a key infiltration technique.
The 3AM ransomware group emerged in late 2023 and, according to experts, maintains ties to the well-known Conti and Royal gangs .
See also: Ransomware gangs use Skitnet malware

General tips for protection against ransomware
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to the network
- Encryption of sensitive data
- Updating devices and systems with the latest security patches
- Conducting regular security audits and penetration testing
- Using strong, unique passwords
- Limiting user access to only necessary systems and information
- Use solutions email security for additional protection against phishing attacks
- Recovery plan for quick recovery
Source: www.bleepingcomputer.com
