RobinHood
Aliases: HelpYemen, RobbinHood
- First seen
- 2019-04-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-14 21:59:23
- Profile updated
- 2026-07-07 12:40:50
Targeted industries: government-and-public-sector
Targeted regions: country_code:us
Context
Detected in April 2019. Known for paralyzing the cities of Baltimore and Greenville. Probably also exfiltrate data
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
- statescoop.com — Baltimore Ransomware Crowdstrike Extortion (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- Microsoft — Microsoft Digital Defense Report 2020 September (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- boll.ch — Wg Threat Report En (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
- Microsoft — Ransomware Groups Continue To Target Healthcare Critical Services Heres How To Reduce Risk (report)
- arstechnica.com — Baltimore City Government Hit By Robbinhood Ransomware (report)
- blogs.quickheal.com — A New Ransomware Goodwill Hacks The Victims For Charity Read More To Know More About This Ransomware And How It Affects Its Victims (report)
- goggleheadedhacker.com — 12 (report)
- krebsonsecurity.com — Report No Eternal Blue Exploit Found In Baltimore City Ransomware (report)
- news.sophos.com — Living Off Another Land Ransomware Borrows Vulnerable Driver To Remove Security Software (report)
- twitter.com — 1121440931759128576 (report)
- bleepingcomputer.com — A Closer Look At The Robbinhood Ransomware (report)
- bleepingcomputer.com — Ransomware Exploits Gigabyte Driver To Kill Av Processes (report)
- sentinelone.com — Robinhood Ransomware Coolmaker Function Not Cool (report)
- ESET — Signed Kernel Drivers Unguarded Gateway Windows Core (report)
- ransomlook.io — Robinhood (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Robinhood (report)