Classification: TLP:CLEAR | Publication Date: 2026-09-29 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
Executive Summary
THREEAM's dark web leak site was observed listing seven organizations between 2026-09-28 and 2026-09-29: safescaffolding.net, coosalud.com, pistonespersan.com.ar, midwestbit.com, apexus.com, bhn-expertise.com, and stjames.wa.edu.au. These are criminal claims, not confirmed intrusions. The claimed spread spans manufacturing, healthcare, technology, professional services, and education across GB, CO, AR, US, DE, and AU, consistent with opportunistic double-extortion operations rather than a tightly narrowed sector campaign. Security teams in the named sectors should treat the listing cluster as a prompt for immediate compromise assessment focused on edge remote access, virtualization management planes, CI/CD exposure, identity abuse, data staging, and shadow copy deletion.
Sourcing & Verification
0 of 7 listings were independently observed by a second leak-site crawler; 7 of 7 currently appear as single-source observations via ransomware.live monitoring. Inclusion reflects the threat actor's claim and is not confirmation of a breach, compromise, outage, data theft, or regulatory incident. A named organization may dispute a listing; a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction, contract, data type, materiality, and regulator, and not every incident is reportable, so neither silence nor denial settles the question. Security Arsenal will publish corrections and welcomes contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — THREEAM
THREEAM is tracked as a ransomware/extortion operation whose public footprint is primarily its leak-site claims. Aliases are not consistently established in the source material for this briefing; defenders should pivot on infrastructure, tooling, ransom-note artifacts, and victimology rather than names alone. The operating model is assessed with low-to-moderate confidence as RaaS-like or affiliate-enabled, because claimed victims span unrelated sectors and countries in a compressed window; however, this remains an assessment, not attribution. Typical ransom demands for comparable mid-market extortion crews range from low six figures to several million dollars, scaled by claimed data sensitivity, sector, cyber insurance posture, and perceived ability to pay.
Known or likely initial access methods for crews with this victimology include phishing with macro-enabled lures, exploitation of internet-facing VPN/firewall appliances, exposed or weakly authenticated RDP, compromised remote access credentials, vulnerable virtualization management planes, and CI/CD or developer-workstation supply-chain exposure. Double extortion is assumed: the listing pattern implies theft-plus-encryption leverage even where encryption is not independently verified. Dwell time before detonation for comparable operations commonly ranges from days to a few weeks, with faster hands-on-keyboard movement after domain-level access is achieved. Treat these as hunting hypotheses tied to the gang's claimed campaign, not facts about any named organization.
Current Campaign Analysis
Targeted sectors in the current seven-listing cluster: manufacturing (safescaffolding.net, pistonespersan.com.ar), healthcare (coosalud.com), technology (midwestbit.com, apexus.com), professional services (bhn-expertise.com), and education (stjames.wa.edu.au). Geographic concentration is diffuse rather than clustered: GB, CO, AR, US, DE, and AU. This favors broad scanning and access-broker purchase over a single regional intrusion set.
Victim profile skews mid-market and mid-enterprise: manufacturing and healthcare entities often carry operational downtime sensitivity; technology and professional services firms can expose client data and downstream trust; education environments frequently combine open networks, constrained SOC coverage, and high-value personal data. Revenue cannot be responsibly estimated from the data provided; use a working assumption of organizations large enough to hold regulated data but potentially without 24x7 detection depth.
Posting frequency shows seven claimed listings published on 2026-09-28, a burst pattern that often follows either a batch of affiliate claims, staged extortion publication, or cleanup after a collector/access-broker influx. Escalation indicators to watch next: reposting with countdown timers, sample-data archives, partial file-tree screenshots, named executive pressure, and cross-posting to Telegram/X by amplification accounts.
CVE linkage must remain hypothesis. THREEAM's claimed sector mix is consistent with environments where defenders should urgently validate exposure to CISA KEV entries with confirmed ransomware use: CVE-2026-59310 (Broadcom VMware vCenter path traversal), CVE-2026-63077 (JetBrains TeamCity deserialization), CVE-2026-20316 (Cisco Secure FMC hard-coded password), CVE-2026-50751 (Check Point Security Gateway improper authentication), and CVE-2026-48027 (Nx Console embedded malicious code). There is no evidence tying any CVE to any named listing above. Use them as sector-level exposure priorities for edge devices, virtualization control planes, build servers, and developer endpoints.
Detection Engineering
---
title: THREEAM Suspected Edge Access Followed by RDP or VPN Anomaly
id: 9f1c7a10-3am-edge-rdp-vpn
status: experimental
description: Detects suspicious remote access patterns consistent with ransomware pre-staging after VPN or firewall compromise; hunt, not confirmation.
author: Security Arsenal
date: 2026/09/29
references:
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
logsource:
category: authentication
product: windows
detection:
selection_rdp:
EventID: 4624
LogonType: 10
selection_vpn:
EventID: 4624
LogonType: 3
IpAddress|contains:
- '10.'
- '172.16.'
- '192.168.'
filter_admin:
TargetUserName|endswith: '$'
condition: selection_rdp or (selection_vpn and not filter_admin)
fields:
- TargetUserName
- IpAddress
- WorkstationName
- LogonProcessName
falsepositives:
- Administrative RDP from jump hosts
level: medium
---
title: THREEAM Pre-Encryption Staging via WMIC PsExec or Scheduled Task
id: 9f1c7a11-3am-psexec-wmi-schtask
status: experimental
description: Identifies common hands-on-keyboard lateral movement and staging artifacts used before ransomware detonation.
author: Security Arsenal
date: 2026/09/29
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\psexec.exe'
- '\wmic.exe'
- '\schtasks.exe'
- '\powershell.exe'
- '\rclone.exe'
- '\7z.exe'
- '\winrar.exe'
selection_cmd:
CommandLine|contains:
- 'shadowcopy'
- 'delete shadows'
- 'resize shadowstorage'
- 'bcdedit'
- 'recoveryenabled no'
- '\\admin$'
- '/create'
- 'mega'
- 'sync '
- 'copy '
condition: selection_img and selection_cmd
fields:
- CommandLine
- ParentCommandLine
- User
- Computer
falsepositives:
- Software deployment
- Backup administration
level: high
---
title: THREEAM Data Exfiltration to Cloud or Rare External Destination
id: 9f1c7a12-3am-exfil-cloud
status: experimental
description: Flags archive creation plus outbound transfer tooling and suspicious egress volume associated with double-extortion staging.
author: Security Arsenal
date: 2026/09/29
logsource:
category: network_connection
product: windows
detection:
selection_proc:
Image|endswith:
- '\rclone.exe'
- '\megacmd.exe'
- '\curl.exe'
- '\wget.exe'
- '\filezilla.exe'
- '\winscp.exe'
selection_dest:
DestinationIp|cidr:
- '0.0.0.0/0'
filter_private:
DestinationIp|cidr:
- '10.0.0.0/8'
- '172.16.0.0/12'
- '192.168.0.0/16'
condition: selection_proc and selection_dest and not filter_private
fields:
- Image
- CommandLine
- DestinationHostname
- DestinationIp
- User
falsepositives:
- Approved backup replication
level: high
let lookback = 14d;
let suspicious_tools = dynamic(["psexec.exe","wmic.exe","schtasks.exe","rclone.exe","7z.exe","winrar.exe","curl.exe","wget.exe","powershell.exe","cmd.exe"]);
let staging_terms = dynamic(["shadowcopy","delete shadows","bcdedit","recoveryenabled","\\admin$","rclone","mega","sync","copy",".zip",".7z",".rar"]);
DeviceProcessEvents
| where TimeGenerated >= ago(lookback)
| where FileName has_any (suspicious_tools) or ProcessCommandLine has_any (staging_terms)
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Commands=make_set(ProcessCommandLine, 20), Files=make_set(FileName, 20), Devices=dcount(DeviceId), Users=make_set(AccountName, 20) by DeviceId, AccountName, InitiatingProcessFileName
| where Commands has_any (staging_terms) or Files has_any (suspicious_tools)
| join kind=leftouter (
DeviceNetworkEvents
| where TimeGenerated >= ago(lookback)
| summarize NetFirst=min(TimeGenerated), RemoteIPs=make_set(RemoteIP, 30), RemoteHosts=make_set(RemoteUrl, 30), TotalBytes=sum(SentBytes) by DeviceId, InitiatingProcessFileName
) on DeviceId, InitiatingProcessFileName
| project FirstSeen, LastSeen, DeviceId, AccountName, InitiatingProcessFileName, Files, Commands, RemoteHosts, RemoteIPs, TotalBytes
| order by TotalBytes desc, FirstSeen asc;
$since = (Get-Date).AddDays(-7)
Write-Output '=== Exposed RDP listeners ==='
Get-NetTCPConnection -State Listen -LocalPort 3389 -ErrorAction SilentlyContinue | Select-Object LocalAddress,LocalPort,OwningProcess,@{n='Process';e={(Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).ProcessName}}
Write-Output '=== Scheduled tasks created or changed in last 7 days ==='
Get-ScheduledTask | ForEach-Object { $_ | Add-Member -NotePropertyName LastWrite -NotePropertyValue ((Get-Item ("$env:SystemRoot\System32\Tasks\" + ($_.TaskPath.TrimStart('\')) + $_.TaskName) -ErrorAction SilentlyContinue).LastWriteTime) -PassThru } | Where-Object {$_.LastWrite -ge $since} | Select-Object TaskName,TaskPath,State,LastWrite
Write-Output '=== Volume Shadow Copy status ==='
vssadmin list shadows
Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue | Select-Object ID,InstallDate,DeviceObject
Write-Output '=== Recently modified admin-share and startup persistence ==='
$paths = @("$env:ProgramData\Microsoft\Windows\Start Menu\Programs\Startup", "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup")
foreach ($p in $paths) { if (Test-Path $p) { Get-ChildItem $p -Recurse -ErrorAction SilentlyContinue | Where-Object {$_.LastWriteTime -ge $since} | Select-Object FullName,LastWriteTime } }
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -ErrorAction SilentlyContinue
Incident Response Priorities
T-minus detection checklist, before encryption fires: unexpected VPN/firewall admin logons; new local/domain admins; RDP from non-jump hosts; PsExec service creation; WMI process call create; scheduled tasks under SYSTEM; mass 7z/RAR creation; rclone, MEGAcmd, WinSCP, curl, or wget on servers; vssadmin delete shadows or wmic shadowcopy delete; bcdedit recoveryenabled no; abnormal SMB writes to admin shares; endpoint tampering or EDR service stop attempts; backup catalog access followed by deletion jobs; DCSync-like replication requests; and sudden egress spikes to rare cloud storage or bulletproof hosting.
Critical assets this profile historically pressures: virtualization management planes such as vCenter and ESXi clusters, backup servers and immutable repositories, file shares holding finance/HR/legal data, EHR and patient-adjacent systems for healthcare claims, source code and build servers for technology claims, client deliverables and engagement data for professional services, student information systems for education, and identity systems including AD, Entra ID, Okta, VPN concentrators, and firewall management consoles.
Containment actions ordered by urgency: isolate suspected hosts without powering off if memory capture is feasible; disable or rotate exposed VPN/firewall accounts and revoke tokens; block egress to unapproved storage and known exfil destinations; protect backup control planes and freeze snapshot deletion; reset KRBTGT twice if domain compromise is plausible; throttle SMB/RDP lateral movement via host firewall and segmentation; preserve firewall, VPN, EDR, DNS, proxy, and hypervisor logs; capture ransom notes, extension patterns, and encrypted samples only after evidence preservation; engage counsel and insurers before any actor contact; do not pay or communicate from corporate infrastructure.
Hardening Recommendations
Immediate 24h: patch or mitigate CISA KEV exposure on internet-facing and management-plane assets, especially vCenter, TeamCity, Cisco FMC, Check Point gateways, and developer extensions; enforce phishing-resistant MFA on VPN, RDP gateways, firewall admin, hypervisor, backup, and cloud consoles; block RDP from the internet and require brokered access with device compliance; disable Office macros from the internet; restrict local admin and use LAPS; alert on vssadmin, wmic, bcdedit, PsExec service names, rclone, and archive tools on servers; enable attack surface reduction rules; set egress default-deny for servers; verify immutable backups and test one restore; hunt the last 14 days for the Sigma/KQL indicators above.
Short-term 2 weeks: segment OT, healthcare clinical, education student systems, backup, and hypervisor management from general user networks; move management planes behind PAM/jump hosts with session recording; implement tiered administration and just-in-time privileged access; deploy canary shares and decoy credentials; baseline server egress and alert on first-seen destinations; require signed scripts and application control on servers; enforce protected users and authentication policy silos for privileged accounts; centralize VPN/firewall/hypervisor logs into Sentinel/SIEM with 180-day retention; run purple-team validation for exfil-then-encrypt workflows; establish leak-site monitoring and external attack surface management for executive exposure.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.