RobbinHood is a human-operated ransomware family written in Go that targets Windows enterprise environments, including municipal and corporate networks. It became widely known through disruptive attacks against organizations such as the City of Baltimore and is associated with targeted big-game-hunting style intrusions rather than broad self-propagating outbreaks. Available reporting indicates it is typically deployed manually after attackers have already obtained privileged access within a victim network, often following compromise of exposed remote access infrastructure and subsequent lateral movement.
RobbinHood encrypts files on individual Windows systems and has been observed requiring a pre-positioned public RSA key before encryption begins, indicating a staged deployment model. It uses per-file symmetric encryption with asymmetric protection of key material and original filename metadata, then renames encrypted files and drops ransom notes. The malware also impairs recovery by deleting shadow copies and disabling Windows recovery features, and it clears event logs to hinder investigation.
A notable characteristic of RobbinHood is aggressive defense evasion. It stops numerous Windows services associated with antivirus, backup, database, and mail software to unlock files and reduce interference. In documented incidents, its operators used a bring-your-own-vulnerable-driver technique: a legitimate signed Gigabyte driver vulnerable to CVE-2018-19320 was abused to disable Windows driver signature enforcement and load an unsigned malicious kernel driver. That kernel driver was then used from kernel space to terminate endpoint security processes and delete their files, bypassing tamper-protection mechanisms before ransomware execution. This made RobbinHood one of the earlier ransomware families publicly documented using a trusted third-party vulnerable driver to neutralize defenses at kernel level.
RobbinHood does not appear to contain worm-like self-spreading capability and is generally assessed to be pushed to hosts individually, for example through administrative tooling after domain-level compromise. Reporting has also described it as a possible ransomware-as-a-service or multi-tenant offering based on customizable ransom infrastructure and templates, though attribution to a specific long-term threat actor remains unclear. High-confidence observations support RobbinHood as a Windows-focused, manually deployed ransomware family optimized for enterprise disruption, defense evasion, and recovery inhibition.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Media publications have cited sources saying the Robbinhood version that hit Baltimore city computers was powered by “Eternal Blue,” a hacking tool developed by the U.S. National Security Agency (NSA) and leaked online in 2017... But new analysis suggests that while Eternal Blue could have been used to spread the infection, the Robbinhood malware itself contains no traces of it. | For almost the past month, key computer systems serving the government of Baltimore, Md. have been held hostage by a ransomware strain known as “Robbinhood.”
The signed driver, part of a now-deprecated software package published by Taiwan-based motherboard manufacturer Gigabyte, has a known vulnerability, tracked as CVE-2018-19320. ... The properly signed third party GDRV.SYS driver contains a privilege escalation vulnerability as it allows reading and writing of arbitrary memory. The malware authors abuse this vulnerability in order to (temporarily) disable driver signature enforcement in Windows. | The ransomware that was being installed in both instances calls itself RobbinHood.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
this could indicate that the payload is being pushed to each individual machine via a domain controller or through a framework like Empire PowerShell and PSExec.
Once disabled, they can install a custom malicious kernel driver that is used to terminate antivirus and security software processes.
wevtutil.exe cl Application wevtutil.exe cl Security wevtutil.exe cl System
This ransomware is not being distributed through spam but rather through other methods, which could include hacked remote desktop services or other Trojans that provide access to the attackers.
Finally, it also important to make sure that your network does not make Remote Desktop Services publicly accessible via the Internet.
RobbinHood disconnects all network shares from the computer using the following command: cmd.exe /c net use * /DELETE /Y
Media publications have cited sources saying the Robbinhood version that hit Baltimore city computers was powered by “Eternal Blue,” a hacking tool developed by the U.S. National Security Agency (NSA) and leaked online in 2017. But new analysis suggests that while Eternal Blue could have been used to spread the infection, the Robbinhood malware itself contains no traces of it.
Stewart said in a typical breach that leads to a ransomware outbreak, the intruders will attempt to leverage a single infection and use it as a jumping-off point to compromise critical systems on the breached network that would allow the malware to be installed on a large number of systems simultaneously.
For almost the past month, key computer systems serving the government of Baltimore, Md. have been held hostage by a ransomware strain known as “Robbinhood.” | the tweets from @Robinhkjn have grown more frequent and profanity-laced, directed at Baltimore’s leaders.
Once the files are deleted, STEEL.EXE kills all the processes associated with the files. Again, it uses its malicious kernel driver to terminate the processes.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
the Twitter account could be seen posting links to documents allegedly stolen from Baltimore city government systems, ostensibly to both prove that those behind the Twitter account were responsible for the attack, and possibly to suggest what may happen to more of those documents if the city refuses to pay up
This second driver then goes to great lengths to kill processes and files belonging to endpoint security products, bypassing tamper protection, to enable the ransomware to attack without interference.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used in intrusions against U.S. organizations (including Baltimore incident referenced) to encrypt files for extortion.
Ransomware used in a BYOVD campaign to disable EDR products via abuse of a legitimate signed vulnerable driver.
Ransomware family observed deploying a legitimate but vulnerable signed Gigabyte driver (GDRV.SYS) to disable Windows driver signature enforcement, load an unsigned malicious kernel driver (RBNL.SYS), kill endpoint security processes and delete their files from kernel space, and then encrypt files unhindered.
Ransomware preceded by abuse of a legitimate signed driver to remove security software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.