sabbath logo

sabbath

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: 54BB47h, UNC2190, ROLLCOAST, Eruption, Arcane
Ver en IntelTracker → APTTrail →
Sabbath is a financially motivated ransomware group that initially emerged under the names Eruption and Arcane, with activity tracked as UNC2190 starting mid-2020. The group rebranded to Sabbath in October 2021, and is also tracked as 54BB47h, notably for its shift to an affiliate-based ransomware-as-a-service model. A distinguishing characteristic of Sabbath and its associated operations, including Storm-0501, is their practice of providing pre-configured Cobalt Strike BEACON backdoor payloads to affiliates, an unusual method among similar groups. They are known for aggressive double extortion tactics, which include direct emails to staff, parents, and students of compromised educational institutions to pressure victims into paying multi-million dollar ransom demands. The group often undergoes rebranding, which analysts suggest allows them to avoid scrutiny, although recurring grammatical errors across their various public-facing forums hint at a consistent underlying operational enti
Tecnicas MITRE
T1552, T1530, T1580, T1087.002, T1053, T1556.009

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesAustraliaBelgiumCanadaSwitzerlandGermanyFranceUnited KingdomIndiaItaly

Sectores objetivo (SOCRadar)

Food ManufacturingReal EstateManufacturingConstructionPublic AdministrationOil & GasBeverag & Tobacco ManufacturingEducational ServicesEnergy & Utilities Educational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com