Robinhood is a closed-circle ransomware group targeting US government entities since 2019.
Analyst brief
Robinhood is a ransomware group first observed in April–May 2019, primarily targeting US government entities such as the city of Baltimore. It operates under a limited closed-circle model without a broad public affiliate program. Key TTPs include ransomware deployment, demanding large Bitcoin ransoms, and causing prolonged disruption to critical city services. Defenders should focus on robust system backups, network segmentation, and monitoring for suspicious file encryption operations.
robinhood
crime
RobbinHood is a ransomware group first observed in April–May 2019, responsible for high-profile attacks on US cities including Baltimore, Maryland — demanding 13 BTC and causing months of disruption to city services — believed to operate as a limited closed-circle model rather than a broad public affiliate program.