OUTLAW SPIDER is the group behind RobbinHood ransomware targeting government entities.
Analyst brief
OUTLAW SPIDER is the threat actor behind the RobbinHood ransomware. It primarily targets government and administration entities, as seen in the 2019 attack on the City of Baltimore. Their main TTP involves infiltrating networks, encrypting systems with RobbinHood ransomware, and demanding ransom in Bitcoin. Defenders should focus on network segmentation, maintaining offline backups of critical systems, and monitoring initial infection vectors such as phishing or RDP exploitation.
OUTLAW SPIDER
unknown
On May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced via Twitter1. This infection was later confirmed to be conducted by OUTLAW SPIDER, which is the actor behind the RobbinHood ransomware. The actor demanded to be paid 3 BTC (approximately $17,600 USD at the time) per infected system, or 13 BTC (approximately $76,500 USD at the time) for all infected systems to recover the city’s files.
What ransomware is the OUTLAW SPIDER group known for?+
The OUTLAW SPIDER group is the threat actor behind RobbinHood ransomware.
What ransom did the OUTLAW SPIDER group demand during the 2019 Baltimore city attack?+
The actor demanded 3 BTC (approximately $17,600 USD at the time) per infected system, or 13 BTC (approximately $76,500 USD at the time) for all infected systems.