Sabbath, operated by UNC2190, is a cybercrime group rebranded from Arcane ransomware targeting critical infrastructure.
Analyst brief
Sabbath, operated by UNC2190 and also tracked as 54BB47h, is a cybercrime group that emerged in mid-2021 as a rebrand of the Arcane ransomware. It is targeting critical infrastructure in the US and Canada, with a distinct focus on hospitals, schools, and natural resources. Key TTPs include double extortion, backup destruction, and active affiliate recruitment on Russian-language dark web forums. Defenders should prioritize immutable offline backups, strict network segmentation, and review ransomware negotiation and incident response procedures.
sabbath
crime
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.