Sabbath
Ransomware Group Profile
Overview
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.
Dark Web Infrastructure (2)
54bb47h5qu4k7l4d7v5ix3i6ak6elysn3net4by4ihmvrhu7cvbskoqd.onion
54bb47h.blog
Activity Timeline
First Seen2021
Last Seen2026
Leak Sites2
Quick Actions