Uptime Hamster: 31d 4h 11mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza robinhood

robinhood

2 incidentes 1 paises 0 sectores ransomware IR Ultimo: 2026-06-29
Aliases: HelpYemen
Ver en IntelTracker → APTTrail →
The threat actor referred to as robinhood, often identified in cybersecurity reports by the common misspelling "RobbinHood" with two 'b's, is a ransomware group that first emerged in March 2019. It operates with the primary motivation of financial gain, demanding significant ransom payments in Bitcoin. The group is notable for its tactical focus on exploiting vulnerable systems, particularly within municipal governments and healthcare organizations. A distinguishing characteristic of robinhood is its use of a vulnerable, legitimate Gigabyte kernel driver (gdrv.sys) to disable system security features before deploying its ransomware. While initially perceived as less sophisticated, the group demonstrated an evolution in its attack methodology, employing custom-built ransomware variants often coded in Go (Golang) and later adopting double extortion tactics. The group gained notoriety through high-profile attacks on U.S. cities such as Baltimore and Greenville, North Carolina. While the f

Aliases del actor

HelpYemen

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: robinhood
Tecnicas MITRE
T1562, T1070, T1187, T1036, T1106, T1547.001
CVEs relacionadas
CVE-2021-26855
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (2)

Paises objetivo (SOCRadar)

AfghanistanSpainUnited StatesSouth Africa

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceOtherPublic AdministrationData Processing Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com