Ransomware Group intelligence
Robbinhood
InactiveTrack Robbinhood with 2 published victims in a single intelligence view.
Overview
Robbinhood is tracked by Breach House as a ransomware group with 2 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (1)
Typical Attacks (6)
▼How Robbinhood typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via RobbinHood.
-
T1059.003 Windows Command Shell Execution
What they do: RobbinHood uses cmd.exe on the victim's computer.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1070.005 Network Share Connection Removal Stealth
What they do: RobbinHood disconnects all network shares from the computer with the command net use * /DELETE /Y.
What that means: Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1486 Data Encrypted for Impact Impact
What they do: RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: RobbinHood stops 181 Windows services on the system before beginning the encryption process.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (1)
▼Software Robbinhood has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (2)
Search, filter and paginate the victim timeline for Robbinhood. Showing 1–2 of 2.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | City of Baltimore id273 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Greenville, NC id267 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||