RobbinHood Ransomware
First observed in April 2019, RobbinHood is a ransomware tool targeted at business networks.
Summary
First observed in April 2019, RobbinHood is a ransomware tool targeted at business networks.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, RobbinHood appears to be delivered directly to target systems over remote desktop services or as a secondary payload dropped by other malware.
Once installed, RobbinHood will terminate over 180 services associated with anti-virus, database and mail applications, as well as any others that may keep files open. It will also attempt to disconnect from all shared locations before checking for the presence of an RSA key in the Temp folder. If present, RobbinHood will begin encrypting all local non-system files using an AES algorithm. Each encrypted file is assigned a unique AES key, which is then itself encrypted along with the filename using the RSA key, before being appended to the encrypted file.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:43 pm