RobinHood is a ransomware-associated threat actor known for marketing and operating the Golang-based Kuiper ransomware. The actor advertised Kuiper on underground forums as a multi-platform ransomware offering for Windows, Linux, and macOS, with claims of operational support and double-extortion capability via a leak site. Analysis of the malware and associated infrastructure indicates that many of the actor’s promotional claims were exaggerated, while the malware itself showed active development but comparatively poor code quality and limited operational maturity. Kuiper’s Windows variants are the most feature-rich and implement common ransomware tradecraft including deletion of backups and recovery artifacts, termination of security and business-critical processes and services, interference with Microsoft Defender, file encryption, ransom note deployment, wallpaper changes, and attempted self-deletion. Later versions added safe-mode execution logic, privilege elevation attempts, and persistence mechanisms to continue execution after reboot. The malware also incorporated weak sandbox-evasion checks. RobinHood’s Kuiper development progressed across multiple versions, with later builds adding network propagation and post-compromise expansion features. These included local subnet discovery, scanning for SMB-accessible hosts, copying the ransomware to reachable systems, remote execution via WMIC, and mounting shared drives for encryption. The actor therefore demonstrated not only ransomware deployment capability but also lateral movement and defense-evasion behavior intended to maximize impact across victim environments. RobinHood has also been linked to weaponization of an exploit into an endpoint security killer in 2020, indicating an interest in disabling defensive tooling during ransomware operations. Overall, RobinHood is best characterized as a financially motivated ransomware actor centered on development, promotion, and use of the Kuiper ransomware family.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced historically as an earlier ransomware group that weaponized a vulnerable driver exploit into an EDR killer.
Developer/operator behind the Kuiper ransomware, advertising it for criminal use and offering operational help for a commission. Associated with ransomware development, cross-platform builds, double-extortion ambitions, and network-spreading capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.