arcane

First seen
2021-06-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-16 17:56:14
Profile updated
2026-07-07 13:57:55

Targeted industries: education-and-nonprofits healthcare-and-pharmaceutical energy-and-utilities

Targeted regions: country_code:us country_code:ca

Context

Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations against critical infrastructure like hospitals, schools, and educational entities. It follows a double-extortion model—encrypting data (using ROLLCOAST/Eruption malware) while also exfiltrating sensitive information and threatening to leak it. Victims have included institutions in the U.S. and Canada across sectors such as healthcare, education, and natural resources. Initial intrusion tactics involved deployment of Cobalt Strike with custom profiles, DLL-based in-memory execution, and signed TLS certificates, plus use of stealthy GET requests ending with “kitten.gif.” Specific encryption algorithms or file extensions have not been publicly confirmed. The group appears to operate in an affiliate-style model but remains under single management rather than a full RaaS platform.

Detection coverage

  • 1 YARA rules

Used by threat actors

  • UNC2190 2021 Ransomware Activity (campaign)

Detection rules

  • MALPEDIA_Win_Arcane_Stealer_Auto (yara-rule)

Reports & references

  • ransomlook.io — Arcane (report)
  • anvilogic.com — Unc2190 Arcane And Sabbath (report)
  • cyberscoop.com — Mandiant Sabbath Arcane Ransomware Rebrand (report)

External references