Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors sabbath

Description

Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums. Known victims: 17

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Sabbath, also known as 54BB47h (operated by UNC2190), is a medium-sophistication ransomware group that emerged in mid-2021. Originally rebranded from Arcane ransomware, they target critical infrastructure sectors such as healthcare, education, and natural resources in the US and Canada, employing double extortion and backup destruction to maximize financial gain.

Goals & Targeting

Sabbath's strategic objectives are centered around financial gain through ransomware activities. They specifically target sectors where downtime can lead to significant disruption or harm, such as hospitals and schools, maximizing the impact of their attacks and increasing the likelihood of payment. Their focus on natural resources may reflect an interest in critical infrastructure with high recovery costs. The choice of targeting the US and Canada suggests a strategic decision based on these countries' robust cyber infrastructures and higher ransom-paying potentials.

Enhanced Description

Sabbath has positioned itself as a significant player in the ransomware landscape by exploiting vulnerabilities in critical infrastructure. The group's shift from Arcane ransomware indicates an attempt to rebrand and reestablish themselves, possibly to avoid detection or enhance their operational capabilities. Their primary focus is on double extortion—encrypting victims' data and threatening to leak it unless a ransom is paid. This strategy increases the pressure on targets topay, often leading to quicker negotiations. Additionally, Sabbath's affiliate recruitment program on Russian dark web forums has expanded their reach, enabling them to target a broader range of organizations without directly exposing themselves.

Key Capabilities

  • Ransomware deployment
  • Double extortion tactics
  • Backup destruction techniques
  • Affiliate recruitment networks
  • Targeting critical infrastructure

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access

ATT&CK Techniques

T1059.003 - Executive Account Access Through Force Account Credential Use
T1055 - spear_phishing_using_infostealing_attachments
T1566.001 - Data Destruction

Software / Tooling

Custom ransomware (akin to DarkSide)
Phishing tools/spear-phishing campaigns
Cobalt Strike for lateral movement or credential dumping
Mimikatz for credential extraction
Custom scripts/trools for encryption and persistence

Campaigns & Victims

Sabbath has demonstrated a clear pattern of targeting critical infrastructure since their emergence in 2021. Their operations span approximately four months, with notable campaigns against hospitals, schools, and natural resource sectors. The group's use of affiliate recruitment indicates an organized business model focused on scaling their attack capabilities without direct operational involvement. This approach allows them to maintain a lower profile while increasing their attack volume and geographic reach.

IOC Patterns

  • Phishing emails with macro-laced Office documents
  • Ransomware encryption of specific file types (e.g., .sabbath)
  • Use of dark web forums for affiliate recruitment
  • C2 communication via encrypted channels
  • Presence of custom ransomware binaries in compromised systems

Recommended Actions

  • Implement robust email filtering to detect and block phishing attempts.
  • Conduct regular, secure backups and store them offline to mitigate backup destruction risks.
  • Monitor network traffic for anomalous activities indicative of lateral movement or data exfiltration.
  • Educate employees on identifying potential ransomware attack vectors, such as suspicious emails.
  • Segment critical infrastructure networks to limit the spread of attacks.

Suggested Tags

Ransomware
Critical Infrastructure Targeting
Double Extortion
Healthcare Sector Attack
Natural Resources Sector Attack

Confidence Assessment

There is medium confidence in the data regarding Sabbath's operational methods and targets, as they have been active and are well-documented. However, specific details on their tools, exact MITRE techniques, and long-term strategic goals remain unclear due to limited公开 reporting and dynamic adversary behavior.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Critical Infrastructure Targeting
Double Extortion
Healthcare Sector Attack
Natural Resources Sector Attack

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 22, 2021
Last Seen
Feb 28, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.