Malware.View on attack.mitre.org
RobbinHood is ransomware that was first observed being used in an attack against the Baltimore city government's computer network.
| Technique | Procedure example |
|---|---|
| T1059.003 Windows Command Shell |
RobbinHood uses cmd.exe on the victim's computer. |
| T1070.005 Network Share Connection Removal |
RobbinHood disconnects all network shares from the computer with the command |
| T1486 Data Encrypted for Impact |
RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files. |
| T1489 Service Stop |
RobbinHood stops 181 Windows services on the system before beginning the encryption process. |
| T1490 Inhibit System Recovery |
RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily. |
| T1685 Disable or Modify Tools |
RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.