ROLLCOAST

Aliases: Arcane, S4bb47h, Sabbath

First seen
2022-03-15 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-16 17:56:14
Profile updated
2026-07-07 13:50:34

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications government-and-public-sector

Context

ROLLCOAST is a ransomware program that encrypts files on logical drives attached to a system. ROLLCOAST is a Dynamic Linked Library (DLL) with no named exports. When observed by Mandiant it uniquely had only one ordinal export 0x01. This suggested the sample was designed to avoid detection and be invoked within memory, possibly through BEACON provided to affiliates. Incident responders working on similar intrusions should capture memory for analysis.

Detection coverage

  • 1 YARA rules

Used by threat actors

  • Storm-0501 Hybrid Cloud Compromise (campaign)
  • UNC2190 2021 Ransomware Activity (campaign)

Detection rules

  • MALPEDIA_Win_Arcane_Stealer_Auto (yara-rule)

Reports & references

  • Mandiant — Sabbath Ransomware Affiliate (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rollcoast (report)

External references