Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware RobbinHood

RobbinHood

TLP:CLEAR
Family

AI Analysis

· 9 hours ago

Executive Summary

RobbinHood is a Windows‑based ransomware first observed targeting the Baltimore city government in May 2019. It encrypts files on infected hosts and demands payment, leveraging standard SMB/Remote Desktop lateral movement. The attack emphasized the severe operational impact of ransomware against public‑sector networks.

Enhanced Description

RobbinHood is a Windows‑based ransomware first documented in May 2019 during an incident that targeted the Baltimore city government’s computer network, as reported by Carbon Black and The Baltimore Sun. Although publicly detailed technical data are scarce, the malware has been classified within a broader ransomware family and is known for encrypting victim files on infected hosts and delivering ransomware notes demanding payment. Typical of ransomware emerging in that period, RobbinHood likely leverages simple lateral‑movement techniques such as SMB or Remote Desktop protocols to spread through an internal network once initial infection occurs. It then encrypts large volumes of data with a strong symmetric algorithm, leaving ransom notes in affected directories and often attempting to exfiltrate data before encryption. The Baltimore incident forced significant disruptions to city services and highlighted the business‑impact risks associated with ransomware attacks on public sector networks: extended downtime, potential loss or compromise of critical data, and reputational damage. Mitigating such threats requires rapid isolation of affected endpoints, restoration from reliable backups, and persistent monitoring for anomalous encryption activity.

Key Capabilities

  • Encrypts victim files on infected machines
  • Drops ransom note with payment instructions
  • Uses SMB or Remote Desktop for lateral spread
  • Persists via scheduled tasks or registry keys

ATT&CK Techniques

T1486
T1021
T1059.001

Recommended Actions

  • Isolate and contain infected endpoints immediately
  • Apply available security patches to block known exploitation vectors
  • Restore data from un‑compromised backups
  • Monitor file‑system for rapid, large‑scale encryption events
  • Block known malicious IPs/URLs associated with RobbinHood
  • Deploy endpoint protection that detects ransomware signatures or behaviors

Suggested Tags

ransomware
public sector cyberattack
Baltimore city government
Windows malware

Confidence Assessment

The description is based on publicly available incident reports and generic ransomware behavior. Specific technical details such as the exact encryption algorithm, persistence mechanisms, or command and control infrastructure are not documented in this data set, resulting in a moderate confidence level for operational guidance.

Description

RobbinHood is ransomware that was first observed being used in an attack against the Baltimore city government's computer network.(Citation: CarbonBlack RobbinHood May 2019)(Citation: BaltimoreSun RobbinHood May 2019)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.