Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums. Known victims: 17
Objectives
Executive Summary
Sabbath, also known as 54BB47h (operated by UNC2190), is a medium-sophistication ransomware group that emerged in mid-2021. Originally rebranded from Arcane ransomware, they target critical infrastructure sectors such as healthcare, education, and natural resources in the US and Canada, employing double extortion and backup destruction to maximize financial gain.
Goals & Targeting
Sabbath's strategic objectives are centered around financial gain through ransomware activities. They specifically target sectors where downtime can lead to significant disruption or harm, such as hospitals and schools, maximizing the impact of their attacks and increasing the likelihood of payment. Their focus on natural resources may reflect an interest in critical infrastructure with high recovery costs. The choice of targeting the US and Canada suggests a strategic decision based on these countries' robust cyber infrastructures and higher ransom-paying potentials.
Enhanced Description
Sabbath has positioned itself as a significant player in the ransomware landscape by exploiting vulnerabilities in critical infrastructure. The group's shift from Arcane ransomware indicates an attempt to rebrand and reestablish themselves, possibly to avoid detection or enhance their operational capabilities. Their primary focus is on double extortion—encrypting victims' data and threatening to leak it unless a ransom is paid. This strategy increases the pressure on targets topay, often leading to quicker negotiations. Additionally, Sabbath's affiliate recruitment program on Russian dark web forums has expanded their reach, enabling them to target a broader range of organizations without directly exposing themselves.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Sabbath has demonstrated a clear pattern of targeting critical infrastructure since their emergence in 2021. Their operations span approximately four months, with notable campaigns against hospitals, schools, and natural resource sectors. The group's use of affiliate recruitment indicates an organized business model focused on scaling their attack capabilities without direct operational involvement. This approach allows them to maintain a lower profile while increasing their attack volume and geographic reach.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is medium confidence in the data regarding Sabbath's operational methods and targets, as they have been active and are well-documented. However, specific details on their tools, exact MITRE techniques, and long-term strategic goals remain unclear due to limited公开 reporting and dynamic adversary behavior.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics