Sabbath is a ransomware family active since at least 2021 and associated with ransomware-as-a-service activity. It has been linked to financially motivated intrusion operations, including campaigns attributed to Storm-0501, which used Sabbath in attacks against education organizations in the United States before later expanding to other ransomware payloads. Sabbath is used to encrypt victim files for extortion and has appeared as one of several ransomware options deployed by affiliates during post-compromise operations.
Operationally, Sabbath has been observed in intrusions that involve extensive credential theft, Active Directory and cloud reconnaissance, lateral movement, data exfiltration, and impact actions preceding or accompanying encryption. In Storm-0501-linked activity, ransomware deployment occurred after compromise of on-premises and hybrid cloud environments through exploitation of known public-facing vulnerabilities, brute-force activity, credential dumping, and abuse of administrative access. These operations also included double-extortion behavior, with data theft and pressure on victims in addition to file encryption.
Sabbath is primarily associated with Windows enterprise environments and has been used against sectors including education. Its use in affiliate-driven campaigns places it within a broader ecosystem of commodity post-exploitation tooling, credential access, and extortion-focused intrusion tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tyler McLellan, Brandan Schondorfer. (2021, November 29). Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware payload used by Storm-0501 in earlier operations (notably 2021) to encrypt victim systems as part of extortion activity.
Ransomware used by Storm-0501 earlier in its activity, including targeting education entities.
Ransomware affiliate program mentioned only in a reference citation and not discussed in the body of the content.
RaaS ransomware referenced as used by Storm-0501 (no further details provided).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.