arcane
- First seen
- 2021-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-16 17:56:14
- Profile updated
- 2026-07-07 13:57:55
Targeted industries: education-and-nonprofits healthcare-and-pharmaceutical energy-and-utilities
Targeted regions: country_code:us country_code:ca
Context
Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations against critical infrastructure like hospitals, schools, and educational entities. It follows a double-extortion model—encrypting data (using ROLLCOAST/Eruption malware) while also exfiltrating sensitive information and threatening to leak it. Victims have included institutions in the U.S. and Canada across sectors such as healthcare, education, and natural resources. Initial intrusion tactics involved deployment of Cobalt Strike with custom profiles, DLL-based in-memory execution, and signed TLS certificates, plus use of stealthy GET requests ending with “kitten.gif.” Specific encryption algorithms or file extensions have not been publicly confirmed. The group appears to operate in an affiliate-style model but remains under single management rather than a full RaaS platform.
Detection coverage
- 1 YARA rules
Used by threat actors
- UNC2190 2021 Ransomware Activity (campaign)
Detection rules
- MALPEDIA_Win_Arcane_Stealer_Auto (yara-rule)
Reports & references
- ransomlook.io — Arcane (report)
- anvilogic.com — Unc2190 Arcane And Sabbath (report)
- cyberscoop.com — Mandiant Sabbath Arcane Ransomware Rebrand (report)