RobbinHood is a Go-based ransomware family targeting Windows systems in enterprise and municipal government networks. It is associated with targeted, human-operated ransomware attacks, including the May 2019 attack on Baltimore, Maryland. The malware lacks built-in network propagation and is deployed to individual endpoints rather than autonomously spreading across network shares.
RobbinHood requires a public RSA key to be present on the target before encryption begins. It generates a unique AES key for each file, encrypts the file contents, and uses RSA to protect the AES key and original filename. It renames encrypted files and creates HTML ransom notes demanding Bitcoin payment. Before encryption, it disconnects network shares and stops services associated with security products, databases, backup software, and mail servers. It also deletes volume shadow copies, disables Windows recovery features, and clears event logs, hindering restoration and investigation.
RobbinHood operators have used bring-your-own-vulnerable-driver techniques to neutralize endpoint defenses. Observed attacks exploited CVE-2018-19320 in a legitimate, digitally signed Gigabyte driver to obtain arbitrary kernel-memory access and disable Windows driver signature enforcement. This enabled an unsigned malicious kernel driver to terminate security processes and delete their backing files, bypassing endpoint tamper protection before ransomware deployment. The technique was observed against Windows 7, Windows 8, and Windows 10.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BlackByte follows RobbinHood and AvosLocker, described as having weaponized bugs in gdrv.sys (CVE-2018-19320) and asWarPot.sys to terminate processes associated with endpoint protection software.
Media publications have cited sources saying the Robbinhood version that hit Baltimore city computers was powered by “Eternal Blue,” a hacking tool developed by the U.S. National Security Agency (NSA) and leaked online in 2017... But new analysis suggests that while Eternal Blue could have been used to spread the infection, the Robbinhood malware itself contains no traces of it. | For almost the past month, key computer systems serving the government of Baltimore, Md. have been held hostage by a ransomware strain known as “Robbinhood.”
20 distinct techniques documented for this family, organized by ATT&CK tactic.
this could indicate that the payload is being pushed to each individual machine via a domain controller or through a framework like Empire PowerShell and PSExec.
Once disabled, they can install a custom malicious kernel driver that is used to terminate antivirus and security software processes.
This ransomware is not being distributed through spam but rather through other methods, which could include hacked remote desktop services or other Trojans that provide access to the attackers.
Finally, it also important to make sure that your network does not make Remote Desktop Services publicly accessible via the Internet.
RobbinHood disconnects all network shares from the computer using the following command: cmd.exe /c net use * /DELETE /Y
Media publications have cited sources saying the Robbinhood version that hit Baltimore city computers was powered by “Eternal Blue,” a hacking tool developed by the U.S. National Security Agency (NSA) and leaked online in 2017. But new analysis suggests that while Eternal Blue could have been used to spread the infection, the Robbinhood malware itself contains no traces of it.
Stewart said in a typical breach that leads to a ransomware outbreak, the intruders will attempt to leverage a single infection and use it as a jumping-off point to compromise critical systems on the breached network that would allow the malware to be installed on a large number of systems simultaneously.
For almost the past month, key computer systems serving the government of Baltimore, Md. have been held hostage by a ransomware strain known as “Robbinhood.” | the tweets from @Robinhkjn have grown more frequent and profanity-laced, directed at Baltimore’s leaders.
Once the files are deleted, STEEL.EXE kills all the processes associated with the files. Again, it uses its malicious kernel driver to terminate the processes.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
the Twitter account could be seen posting links to documents allegedly stolen from Baltimore city government systems, ostensibly to both prove that those behind the Twitter account were responsible for the attack, and possibly to suggest what may happen to more of those documents if the city refuses to pay up
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used in intrusions against U.S. organizations (including Baltimore incident referenced) to encrypt files for extortion.
Ransomware used in a BYOVD campaign to disable EDR products via abuse of a legitimate signed vulnerable driver.
Ransomware family observed deploying a legitimate but vulnerable signed Gigabyte driver (GDRV.SYS) to disable Windows driver signature enforcement, load an unsigned malicious kernel driver (RBNL.SYS), kill endpoint security processes and delete their files from kernel space, and then encrypt files unhindered.
Ransomware preceded by abuse of a legitimate signed driver to remove security software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.