robinhood logo

robinhood

1 incidentes 1 paises 0 sectores ransomware IR Ultimo: 2026-06-25
Aliases: HelpYemen
Ver en IntelTracker → APTTrail →
The threat actor referred to as robinhood, often identified in cybersecurity reports by the common misspelling "RobbinHood" with two 'b's, is a ransomware group that first emerged in March 2019. It operates with the primary motivation of financial gain, demanding significant ransom payments in Bitcoin. The group is notable for its tactical focus on exploiting vulnerable systems, particularly within municipal governments and healthcare organizations. A distinguishing characteristic of robinhood is its use of a vulnerable, legitimate Gigabyte kernel driver (gdrv.sys) to disable system security features before deploying its ransomware. While initially perceived as less sophisticated, the group demonstrated an evolution in its attack methodology, employing custom-built ransomware variants often coded in Go (Golang) and later adopting double extortion tactics. The group gained notoriety through high-profile attacks on U.S. cities such as Baltimore and Greenville, North Carolina. While the f
Tecnicas MITRE
T1562, T1070, T1187, T1036, T1106, T1547.001
CVEs relacionadas
CVE-2021-26855

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

AfghanistanSpainUnited StatesSouth Africa

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceOtherPublic AdministrationData Processing Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com