ROLLCOAST
Aliases: Arcane, S4bb47h, Sabbath
- First seen
- 2022-03-15 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-16 17:56:14
- Profile updated
- 2026-07-07 13:50:34
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications government-and-public-sector
Context
ROLLCOAST is a ransomware program that encrypts files on logical drives attached to a system. ROLLCOAST is a Dynamic Linked Library (DLL) with no named exports. When observed by Mandiant it uniquely had only one ordinal export 0x01. This suggested the sample was designed to avoid detection and be invoked within memory, possibly through BEACON provided to affiliates. Incident responders working on similar intrusions should capture memory for analysis.
Detection coverage
- 1 YARA rules
Used by threat actors
- Storm-0501 Hybrid Cloud Compromise (campaign)
- UNC2190 2021 Ransomware Activity (campaign)
Detection rules
- MALPEDIA_Win_Arcane_Stealer_Auto (yara-rule)
Reports & references
- Mandiant — Sabbath Ransomware Affiliate (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Rollcoast (report)