Sabbath

Inactive
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.
17 Victims
Nov 22, 2021 First Discovered
Feb 28, 2022 Last Discovered
1661 Days Inactive
0% Infostealer
0/2 Sites Online
Known Locations (2)
BLOG
54bb47h5qu4k7l4d7v5ix3i6ak6elysn3net4by4ihmvrhu7cvbskoqd.onion
54bb47h.blog
Victims (17)

Detailed victim list temporarily unavailable

This group has 17 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.