Ransomware Group intelligence
Sabbath
InactiveTrack Sabbath with 17 published victims and 2 known leak locations in a single intelligence view.
Overview
Sabbath is tracked by Breach House as a ransomware group with 17 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | 54bb47h5qu4k7l4d7v5ix3i6ak6elysn3net4by4ihmvrhu7cvbskoqd.onion |
| Leak location 2 | Web location | Down checked 15d ago | 54bb47h.blog |
Top Activity Sectors (6)
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Sabbath, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1047 Windows Management Instrumentation Execution
What they do: sabbath uses Windows Management Instrumentation to execute commands and maintain persistence.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: sabbath uses PowerShell scripts to execute malicious commands and spread payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: sabbath leverages native API calls to interact with system functions for execution and evasion.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: sabbath modifies registry run keys to ensure malware execution upon system reboot.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: sabbath disables security tools like antivirus software to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: sabbath encrypts and encodes files with custom symmetric cryptography to render data unusable.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: sabbath deletes Volume Shadow Copies and recovery files to prevent data restoration.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1057 Process Discovery Discovery
What they do: sabbath performs process discovery to identify active processes for targeting or privilege escalation.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1083 File and Directory Discovery Discovery
What they do: sabbath discovers files and directories to locate sensitive data for encryption or exfiltration.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1560.001 Archive via Utility Collection
What they do: sabbath archives victim data before exfiltration to maximize pressure for ransom payment.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: sabbath encrypts victim files using a custom ransomware payload to hold data hostage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: sabbath inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (17)
Search, filter and paginate the victim timeline for Sabbath. Showing 1–17 of 17.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | aria-label=Google> id2744 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | JALEEL TRADERS LLC id2451 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ASL Napoli 3 Sud Network Seized id2441 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Protected: PRIVATE POST ITALY id2433 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Summit College id2366 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Close drawer id2365 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Close search modal id2364 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TRIGYN 2 0 | Data Leak id2303 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Prenax id2249 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Social Enterprise (SEC) id2164 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Trigyn Technologies Ltd id2155 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Flagship id1974 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Stoningtonschools id1973 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AISD id1972 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Starline id1971 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | RocTechnologies id1970 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MCP Services LLC id1969 View details | Services | — | ||
|
No additional victim description available. |
|||||