Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

RobbinHood—also written RobinHood or Robinhood—was a Windows ransomware family first observed in 2019 and associated with targeted attacks against organizations including Baltimore and Greenville. The analyzed sample did more than encrypt files: it stopped security and business services, deleted recovery data, cleared event logs, disconnected mapped shares, and weakened Windows recovery.

It should not be described as an EternalBlue worm. Available technical analysis found no evidence that the ransomware itself autonomously spread through EternalBlue or BlueKeep. The more important lesson is that RobbinHood appears to have been deployed after attackers obtained sufficient access to organizational systems.

RobbinHood ransomware at a glance

Detail What is known
Family RobbinHood, also reported as RobinHood or Robinhood
Platform Windows
First observed activity Spring 2019
MITRE ATT&CK S0400
Known associations Baltimore, Greenville, and other public- and private-sector victims
Typical file suffix .enc_robbinhood

RobbinHood became widely known after the City of Baltimore attack on May 7, 2019, but Baltimore was not the only affected organization. The later criminal case described by the U.S. Department of Justice connected the broader operation to additional cities, corporations, health-care organizations, and other U.S. entities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the analyzed sample prepared a system

The 2019 sample documented by BleepingComputer’s technical analysis used a deliberate preparation sequence designed to make encryption more effective and recovery more difficult.

It disconnected mapped network shares

cmd.exe /c net use * /DELETE /Y

This behavior is important. The sample did not behave like a conventional network worm that crawled through every available share. Instead, it removed mapped-share connections before operating locally. That supports the view that an attacker may have separately deployed the payload to multiple systems after obtaining administrative control.

It stopped security and business services

The sample attempted to stop 181 Windows services. The list included services associated with:

  • Antivirus and endpoint-security products
  • Microsoft SQL Server and other databases
  • Microsoft Exchange and mail systems
  • IIS web services
  • Veeam, Acronis, and Backup Exec
  • Sophos, Symantec, and McAfee products

Stopping services can release files held open by applications and prevent databases, mail systems, and backup software from protecting or recovering data. It also illustrates why endpoint protection alone is insufficient when an attacker has obtained high privileges.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It deleted shadow copies and weakened recovery

vssadmin.exe delete shadows /all /quiet
WMIC shadowcopy delete
Bcdedit.exe /set {default} recoveryenabled no
Bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures

These commands delete Volume Shadow Copies and change Windows boot-recovery behavior. The result is fewer local recovery options after encryption.

It cleared event logs

wevtutil.exe cl Application
wevtutil.exe cl Security
wevtutil.exe cl System

Clearing the Application, Security, and System logs can remove valuable evidence. However, centralized logging, domain-controller telemetry, EDR records, firewall logs, and backup-platform logs may still preserve parts of the attack timeline.

The pub.key prerequisite

One unusual implementation detail was the sample’s requirement for a public RSA key at:

C:WindowsTemppub.key

If the file was absent, the analyzed sample displayed an error and exited. This suggests that the executable was not completely self-contained: another deployment step had to place or generate the required key file.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That abort condition is useful for understanding the sample, but it is not a safe operational workaround. Defenders should not casually create, delete, or modify files on a suspected production host. A variant may behave differently, and changing the machine can destroy evidence or trigger additional damage.

How RobbinHood encrypted files

The analyzed ransomware used a hybrid encryption design:

  1. It generated an AES key for an individual file.
  2. It encrypted the file’s contents with AES.
  3. It encrypted the AES key and original filename with an RSA public key.
  4. It renamed the encrypted file with a name resembling Encrypted_[randomstring].enc_robbinhood.

RSA was therefore used to protect the per-file AES keys, not to encrypt entire large files directly. The ransom note and the FBI’s technical summary described the RSA component as RSA-4096. That should be treated as a report of the observed implementation and sample claims, not as a blanket guarantee about every RobbinHood variant or its cryptographic quality.

Directories the sample skipped

The reported sample avoided several system and application paths:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
ProgramData
Windows
bootmgr
Boot
$WINDOWS.~BT
Windows.old
Temp
tmp
Program Files
Program Files (x86)
AppData
$Recycle.bin
System Volume Information

This suggests an attempt to leave enough of Windows running to display the ransom demand and keep the machine operational. It does not mean applications, databases, or business data were safe. The malware separately attempted to stop services that could keep valuable files open.

Ransom notes and demands

The sample created four HTML notes:

_Decrypt_Files.html
_Decryption_ReadMe.html
_Help_Help_Help.html
_Help_Important.html

Associated temporary files included:

C:WindowsTemppub.key
C:WindowsTemprf_s
C:WindowsTempro_l
C:WindowsTempro_s

The 2019 ransom note demanded three Bitcoin per affected system or 13 Bitcoin for the entire network. It threatened an additional $10,000 per day after the fourth day. These were historical terms from 2019, not current prices.

Did RobbinHood spread through network shares?

Not according to the analyzed sample. The sample disconnected mapped shares rather than crawling and encrypting them directly. The most defensible interpretation is:

  1. An attacker gained access to an organization.
  2. The attacker obtained administrative control or moved laterally.
  3. The ransomware was pushed to individual systems, potentially through administrative tooling.
  4. Each host disconnected shares, stopped services, and encrypted local target files.

Researchers discussed tools and methods such as PsExec, PowerShell frameworks, or domain-controller-assisted deployment, but the sample alone did not establish which tool or initial-access method was used in every incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Correction: RobbinHood was not an EternalBlue worm

Some early reporting connected the Baltimore incident with EternalBlue. However, analysis of the ransomware executable found no EternalBlue or BlueKeep propagation function. SentinelLabs later described those claims as incorrect and reported that Baltimore had confirmed the ransomware was not exploiting those vulnerabilities.

That does not prove that the attackers could not have exploited a vulnerability before deploying the ransomware. It means the payload itself should not be characterized as an autonomous EternalBlue or BlueKeep worm. Initial access, lateral movement, and ransomware execution are separate stages and require separate evidence.

Baltimore, Greenville, and the broader campaign

Baltimore

Baltimore’s government systems were attacked on May 7, 2019. Hundreds of computers were taken offline, disrupting services including property-tax, water-bill, parking-citation, and other revenue-related systems. The city did not pay the ransom.

The reported demand was approximately 13 Bitcoin. Contemporary dollar estimates varied with the Bitcoin price and the date of calculation; they describe the attackers’ demand, not a payment made by Baltimore. In May 2025, the U.S. Department of Justice said Baltimore suffered more than $19 million in losses, including damage and service disruption.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Greenville

Greenville, North Carolina, was another publicly identified victim associated with RobbinHood. An FBI alert said three U.S. cities were victims between April 7 and May 7, 2019, but did not establish one universal infection route for all cases.

What later law-enforcement findings add

The DOJ’s 2025 announcement said Sina Gholinejad pleaded guilty to participating in an international RobbinHood ransomware scheme. According to the DOJ, the operators compromised networks, copied information to attacker-controlled virtual private servers, deployed ransomware, and caused tens of millions of dollars in losses.

This expands the historical picture beyond a Baltimore-specific encryption event. It also shows why an organization must investigate possible data theft even when the visible impact is encrypted files and unavailable systems.

Was data stolen as well as encrypted?

The original reverse engineering primarily documented encryption and system disruption. The later DOJ case described information being copied from victim networks to infrastructure controlled by the conspirators.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those findings should not be applied automatically to every RobbinHood sample or every associated incident. For a particular victim, exfiltration must be established through network, authentication, cloud, endpoint, and server evidence. Nevertheless, a RobbinHood investigation should treat data theft as a possibility rather than assuming the incident was encryption-only.

Indicators and hunting leads

The following indicators come from specific samples and reports. They are useful hunting leads, not complete family-wide detection rules.

File extension

.enc_robbinhood

Reported sample hash

3bc78141ff3f742c5e942993adfbef39c2127f9682a303b5e786ed7f9a8d184b

A hash identifies one documented sample. Repacked or modified variants will have different hashes.

Notable commands

net use * /DELETE /Y
vssadmin.exe delete shadows /all /quiet
WMIC shadowcopy delete
wevtutil.exe cl Application
wevtutil.exe cl Security
wevtutil.exe cl System
Bcdedit.exe /set {default} recoveryenabled no
Bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
sc.exe stop <service-name> /y

These are dual-use Windows administration commands. Their presence alone does not prove RobbinHood infection. Investigate timing, parent processes, account context, command-line history, mass file changes, ransom notes, and other correlated telemetry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do if RobbinHood is suspected

  1. Isolate affected systems. Disconnect network cables or disable network connectivity. If volatile evidence matters and responders are available, avoid indiscriminate shutdowns until an evidence-preservation plan is agreed.
  2. Protect unaffected systems. Segment them from suspected hosts, restrict administrative shares and remote access, and review privileged-account activity.
  3. Preserve evidence. Save ransom notes, encrypted samples, suspected executables, available logs, process information, hostnames, and timestamps. Consider memory capture where appropriate.
  4. Protect backups. Disconnect reachable backup repositories and verify restoration points are clean. A backup server is not automatically safe merely because its data has not yet been encrypted.
  5. Investigate initial access. Review exposed RDP and VPN services, privileged logons, PowerShell, PsExec, domain-controller events, credential reuse, and lateral movement preceding encryption.
  6. Reset credentials. Prioritize domain administrators, local administrators, service accounts, backup accounts, and any credentials exposed during the intrusion.
  7. Report the incident. In the United States, the FBI advises reporting ransomware regardless of whether a ransom is paid. Preserve the indicators requested in the FBI IC3 guidance and relevant FBI alert.
  8. Restore cautiously. Rebuild compromised systems where appropriate, remove attacker access, patch exposed services, and restore only after confirming that persistence has been addressed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What not to do

  • Do not assume that one encrypted computer is the only affected system.
  • Do not reconnect mapped shares immediately after isolating a host.
  • Do not run an unofficial decryptor downloaded from an unknown forum.
  • Do not delete ransom notes, encrypted samples, or malware artifacts.
  • Do not assume a test decryption proves that payment will recover all files or remove stolen data.
  • Do not label an incident an EternalBlue infection without incident-specific evidence.

Can RobbinHood-encrypted files be decrypted?

The 2019 analysis reported no known weakness and no free decryptor for the analyzed sample at that time. That is not a permanent statement about every variant or future recovery development.

Organizations should preserve encrypted files and ransom notes, check reputable ransomware-recovery resources for the exact variant, and consult law enforcement or qualified incident responders. Restore from clean offline or otherwise protected backups when possible. Treat any purported decryptor as untrusted until independently verified.

Backup recovery is strongest when copies are offline or immutable, use separate credentials, predate the compromise, and have been tested. Recovery is harder when backups were online, reachable with production credentials, or when attackers had months to access systems and steal data.

Defensive lessons for modern organizations

RobbinHood demonstrates why ransomware resilience requires a stack rather than one antivirus product:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Multifactor authentication and privileged-access management
  • Network segmentation that limits administrative movement
  • RDP and VPN access restricted through secure gateways, MFA, and least privilege
  • EDR tamper protection and centralized monitoring
  • Immutable, offline, or logically isolated backups
  • Separate backup credentials and tested restoration procedures
  • Centralized logs that attackers cannot easily clear
  • Rapid isolation procedures and a documented incident-response plan

NHS England’s contemporary guidance similarly emphasized isolating infected systems, contacting IT support, and maintaining multiple backups, including an off-network copy.

Evaluating security and recovery products

Organizations considering commercial controls should evaluate the complete recovery chain rather than select a single “best” RobbinHood product.

  • Endpoint detection and response: Can it detect mass file changes, service stopping, shadow-copy deletion, credential abuse, and suspicious administrative tools? Can attackers disable it?
  • Backup and recovery: Are copies immutable or isolated? Are backup credentials separate? Can restored data be scanned and recovery tested?
  • Managed detection and response: Does the provider monitor continuously, and who has authority to isolate hosts or reset accounts?
  • Incident response: Can the provider preserve evidence, investigate exfiltration, support restoration, and coordinate with legal and law-enforcement teams?

Products from Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, Sophos, Veeam, Rubrik, Commvault, Acronis, and managed-response providers may address parts of this problem. Fit depends on the organization’s Windows, database, virtualization, cloud, staffing, compliance, and recovery requirements. Quote-based pricing and service scope vary, so a product name alone is not evidence of protection.

MITRE ATT&CK behavior mapping

Reported behavior aligns with techniques including Data Encrypted for Impact, Service Stop, Inhibit System Recovery, Disable or Modify Tools, Windows Command Shell, and network-share disconnection. The MITRE ATT&CK S0400 profile is a useful starting point, but defenders should combine it with organization-specific telemetry and incident evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.