Skip to content

sabbath

Inactive

0 tracked victims · First seen Nov 22, 2021 · Last seen Feb 28, 2022

About

Aggregated threat-intel description

Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.

Recent victims

View all →
No recent victims.

All ransomware groups · Dark web intelligence