Executive Summary
RobbinHood is a Windows‑based ransomware first observed targeting the Baltimore city government in May 2019. It encrypts files on infected hosts and demands payment, leveraging standard SMB/Remote Desktop lateral movement. The attack emphasized the severe operational impact of ransomware against public‑sector networks.
Enhanced Description
RobbinHood is a Windows‑based ransomware first documented in May 2019 during an incident that targeted the Baltimore city government’s computer network, as reported by Carbon Black and The Baltimore Sun. Although publicly detailed technical data are scarce, the malware has been classified within a broader ransomware family and is known for encrypting victim files on infected hosts and delivering ransomware notes demanding payment. Typical of ransomware emerging in that period, RobbinHood likely leverages simple lateral‑movement techniques such as SMB or Remote Desktop protocols to spread through an internal network once initial infection occurs. It then encrypts large volumes of data with a strong symmetric algorithm, leaving ransom notes in affected directories and often attempting to exfiltrate data before encryption. The Baltimore incident forced significant disruptions to city services and highlighted the business‑impact risks associated with ransomware attacks on public sector networks: extended downtime, potential loss or compromise of critical data, and reputational damage. Mitigating such threats requires rapid isolation of affected endpoints, restoration from reliable backups, and persistent monitoring for anomalous encryption activity.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The description is based on publicly available incident reports and generic ransomware behavior. Specific technical details such as the exact encryption algorithm, persistence mechanisms, or command and control infrastructure are not documented in this data set, resulting in a moderate confidence level for operational guidance.
RobbinHood is ransomware that was first observed being used in an attack against the Baltimore city government's computer network.(Citation: CarbonBlack RobbinHood May 2019)(Citation: BaltimoreSun RobbinHood May 2019)