Skip to content

Sabbath

Sabbath is a ransomware family active since at least 2021 and associated with ransomware-as-a-service activity.

Profile source: Mallory opens in a new tab

Sabbath

Family profile

Sabbath is a ransomware family active since at least 2021 and associated with ransomware-as-a-service activity. It has been linked to financially motivated intrusion operations, including campaigns attributed to Storm-0501, which used Sabbath in attacks against education organizations in the United States before later expanding to other ransomware payloads. Sabbath is used to encrypt victim files for extortion and has appeared as one of several ransomware options deployed by affiliates during post-compromise operations.

Operationally, Sabbath has been observed in intrusions that involve extensive credential theft, Active Directory and cloud reconnaissance, lateral movement, data exfiltration, and impact actions preceding or accompanying encryption. In Storm-0501-linked activity, ransomware deployment occurred after compromise of on-premises and hybrid cloud environments through exploitation of known public-facing vulnerabilities, brute-force activity, credential dumping, and abuse of administrative access. These operations also included double-extortion behavior, with data theft and pressure on victims in addition to file encryption.

Sabbath is primarily associated with Windows enterprise environments and has been used against sectors including education. Its use in affiliate-driven campaigns places it within a broader ecosystem of commodity post-exploitation tooling, credential access, and extortion-focused intrusion tradecraft.

Capabilities

  • Brute Force
  • Credential Theft
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Post Exploitation
  • Reconnaissance

Operational record

1
YARA rules
2
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
Storm-0501

Tyler McLellan, Brandan Schondorfer. (2021, November 29). Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again.

MITRE ATT&CK

Sabbath in ATT&CK

1 distinct techniques

Reporting

Research mentioning Sabbath

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.