ATT&CKSoftwareRobbinHood

RobbinHood

S0400

Malware.View on attack.mitre.org

About this malware

RobbinHood is ransomware that was first observed being used in an attack against the Baltimore city government's computer network.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1059.003
Windows Command Shell

RobbinHood uses cmd.exe on the victim's computer.

T1070.005
Network Share Connection Removal

RobbinHood disconnects all network shares from the computer with the command net use * /DELETE /Y.

T1486
Data Encrypted for Impact

RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files.

T1489
Service Stop

RobbinHood stops 181 Windows services on the system before beginning the encryption process.

T1490
Inhibit System Recovery

RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily.

T1685
Disable or Modify Tools

RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. BaltimoreSun RobbinHood May 2019 Open source
    Duncan, I., Campbell, C. (2019, May 7). Baltimore city government computer network hit by ransomware attack. Retrieved July 29, 2019.
  2. CarbonBlack RobbinHood May 2019 Open source
    Lee, S. (2019, May 17). CB TAU Threat Intelligence Notification: RobbinHood Ransomware Stops 181 Windows Services Before Encryption. Retrieved July 29, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.