RobbinHood

MITRE ATT&CK: S0400 View on attack.mitre.org

Aliases: RobbinHood

Malware type
ransomware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:28:59

Targeted industries: government-and-public-sector

Targeted regions: country_code:us

Context

RobbinHood is ransomware that was first observed being used in an attack against the Baltimore city government's computer network.

Detection coverage

  • 238 Sigma rules

Malware & tools used

  • Inhibit System Recovery (attack-pattern)
  • Service Stop (attack-pattern)
  • Network Share Connection Removal (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Windows Command Shell (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0400 (report)
  • baltimoresun.com — Bs Md Ci It Outage 20190507 Story (report)
  • carbonblack.com — Cb Tau Threat Intelligence Notification Robbinhood Ransomware Stops 181 Windows Services Before Encryption (report)

External references