On May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced via Twitter1. This infection was later confirmed to be conducted by OUTLAW SPIDER, which is the actor behind the RobbinHood ransomware. The actor demanded to be paid 3 BTC (approximately $17,600 USD at the time) per infected system, or 13 BTC (approximately $76,500 USD at the time) for all infected systems to recover the city’s files.
Executive Summary
OUTLAW SPIDER is a cyber threat actor known for conducting ransomware attacks targeting municipal networks. The actor is linked to the RobbinHood ransomware variant and has demonstrated focus on U.S. cities, demanding cryptocurrency payments for decryption keys. Their operations highlight a strategic approach to target vulnerable critical infrastructure with high disruption potential.
Goals & Targeting
OUTLAW SPIDER's primary motivation appears to be financial gain, as evidenced by their ransomware demands. Their targeting profile suggests a focus on sectors that are critical yet may have lower resilience to cyberattacks, such as municipal IT systems. The actor likely selects cities over other targets due to the potential for rapid payouts and limited recovery options. Typical victims include local government agencies, healthcare providers, and public utilities.
Enhanced Description
OUTLAW SPIDER gained notoriety after attacking the city network of Baltimore in May 2019 using RobbinHood ransomware. The actor targeted a critical service provider, leading to significant operational disruption. Their modus operandi involves deploying ransomware to encrypt files and demand payment for decryption keys. OUTLAW SPIDER's approach indicates a preference for high-profile yet potentially less-targeted sectors where 피해 복구에 대한압박이 큰곳을 공략한다. The actor's strategy focuses on maximizing financial gain while minimizing operational risk by targeting municipalities with limited cybersecurity resources.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
OUTLAW SPIDER's campaign patterns include targeting municipal networks during weekends or holidays to minimize immediate disruption and maximize payout chances. Their operational tempo suggests they are patient, waiting for victims to exhaust recovery options before demanding payment. Notable past operations include the Baltimore attack in May 2019, where over 10,000 systems were affected. This indicates a preference for high-impact targets with limited incident response capabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence level is moderate due to the limited availability of detailed information about OUTLAW SPIDER's full capabilities and TTPs. The actor's exact origins, long-term goals beyond financial gain, and toolset remain unclear. Further analysis of their recent campaigns would be necessary to build a more comprehensive understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics