A 3AM ransomware affiliate has been conducting highly targeted attacks using a combination of email bombing and spoofed IT support calls to trick employees into providing credentials for remote access to corporate systems. Sophos has identified at least 55 attacks using this technique between November 2024 and January 2025, linked to two distinct threat clusters.
## Attack Methodology
The attack strategy follows a playbook previously associated with the Black Basta ransomware gang and FIN7:
1. **Email Bombing**: Overwhelming targets with dozens of unsolicited emails in minutes
2. **Voice Phishing**: Spoofing legitimate IT department phone numbers
3. **Microsoft Quick Assist Abuse**: Convincing employees to grant remote access
In a recent case study from Q1 2025, attackers called an employee during an email bombing wave (24 emails in three minutes), impersonating the company’s IT department with a spoofed phone number. The attacker persuaded the employee to open Microsoft Quick Assist and grant remote access under the pretense of addressing malicious activity.
## Technical Execution
Once access was gained, the attackers:
1. Downloaded malicious files from a spoofed domain
2. Deployed QEMU emulator with a Windows 7 image containing QDoor backdoor
3. Used virtual machines to evade detection while maintaining network access
4. Performed reconnaissance using WMIC and PowerShell
5. Created local admin accounts for RDP connections
6. Installed XEOXRemote (commercial remote management tool)
7. Compromised domain administrator accounts
Although Sophos products blocked lateral movement attempts, the attackers still exfiltrated 868 GB of data to Backblaze cloud storage using GoodSync. The attack lasted nine days, with data theft completed by day three.
## Defensive Recommendations
Sophos recommends several key defensive measures:
– Audit administrative accounts for security vulnerabilities
– Deploy XDR tools to block unapproved legitimate tools like QEMU and GoodSync
– Enforce signed scripts only via PowerShell execution policies
– Implement blocklists using known indicators of compromise
– Increase employee awareness about email bombing and voice phishing tactics
The 3AM ransomware operation, which launched in late 2023, has been linked to the Conti and Royal ransomware gangs.
