On May 7, 2019, Baltimore City’s government systems were crippled by a major ransomware attack known as RobbinHood. The malware locked critical files and shut down most city servers, bringing many day-to-day operations to a halt. Only essential emergency services, such as police and fire departments, were able to continue functioning.
The attackers demanded 13 Bitcoin, worth about $76,000 at the time, in exchange for restoring access to the systems. After consulting with the FBI and the U.S. Secret Service, city leaders chose not to pay the ransom, instead beginning a lengthy and costly recovery process to rebuild and secure their systems.
1. Executive Technical Summary
- Victim: Baltimore City Government
- Threat Actor / Malware: RobbinHood ransomware
- Attack Type: Targeted ransomware (not commodity spray-and-pray)
- Initial Compromise Window: Likely weeks before detonation
- Impact:
- ~10,000 city workstations
- Email, payment systems, real estate, utilities, courts disrupted
- Ransom Demand: ~13 BTC (~$76k at the time)
- Estimated Recovery Cost: >$18 million
- Key Failure Point: Unpatched SMB vulnerabilities + weak internal segmentation
2. Attack Chain (MITRE ATT&CK Mapping)
Phase 1 – Initial Access
Likely Vector:
- Exploitation of unpatched SMB vulnerabilities
- Possibly EternalBlue (MS17-010) or similar lateral SMB exploit
MITRE:
- T1190 – Exploit Public-Facing Application
- T1210 – Exploitation of Remote Services
Phase 2 – Privilege Escalation & Lateral Movement
Once inside:
- Attacker gained domain-level privileges
- Used SMB + PsExec + scheduled tasks
- Moved laterally across flat network segments
MITRE:
- T1078 – Valid Accounts
- T1021.002 – SMB/Windows Admin Shares
- T1053 – Scheduled Task/Job
Phase 3 – Defense Evasion
RobbinHood is highly evasive:
- Kills security services
- Disables Windows Defender
- Stops backup-related processes
- Executes from non-standard directories
- Uses delayed execution
MITRE:
- T1562 – Impair Defenses
- T1070 – Indicator Removal on Host
Phase 4 – Payload Execution (Ransomware)
- Custom RobbinHood.exe
- Uses AES-256 for file encryption
- RSA used for key protection
- Drops ransom note per directory
MITRE:
-
T1486 – Data Encrypted for Impact
3. IOCS – Indicators of Compromise (Detailed)
A. File-Based IOCs
Common Filenames:
Ransom Note Files:
Encrypted File Extension:
B. Hash-Based IOCs (Example)
07a133bda8f5039c30b4118167d1c2e79906c79ea52ed73f1767921ce146d97d3bc78141ff3f742c5e942993adfbef39c2127f9682a303b5e786ed7f9a8d184b47d892da6a49b02a2904bdc0d03ecef66c076481d19ab19251d86d11be4947657c7ef3ab31ab91a7379bc2e3f32473dfa7adf662d0c640ef994103f6022a092b9ffacdba165181e10bedbecce31143bb65b7e59e560e36e561b149295742d085cda83bc9958f3f82e41ad5bb1816e936df7dfdf4630937d6636d0ad725759784e2ae71899ee9cd748c95b4ce3df103106b9d943bd69e657f6d194ac33790f261e9188ace227b00cbf1f6fba3ceb32af8e4d456c3a0815300a224a9d9e00778a8
C. Registry-Based IOCs
Persistence mechanisms:
Added values pointing to malicious executables in temp or admin shares.
D. Process & Memory IOCs
Suspicious process activity:

Abnormal parent-child relationships:
E. Network IOCs
Lateral Movement:
- TCP 445 (SMB)
- RPC over 135
- Admin shares:
\\C$\Windows\Temp
\\ADMIN$
hxxps://xbt4titax4pzza6w[.]onionhxxps://xbt4titax4pzza6w[.]onion.pethxxps://xbt4titax4pzza6w[.]onion.to
C2 Characteristics:
- No long-term C2 beaconing
- Mostly offline execution
- Limited outbound traffic (harder to detect)
4. IR (Incident Response) – Technical Walkthrough
Phase 1 – Identification
Indicators observed:
- Mass file encryption
- Ransom notes appearing simultaneously
- Spike in SMB traffic
- Endpoint AV disabled
Failures:
- No early EDR telemetry
- Lack of centralized log correlation
- Attack went undetected until detonation
Phase 2 – Containment
Immediate Actions Required (Best Practice):
- Disconnect infected hosts from network
- Disable SMB across segments
- Block lateral admin credentials
- Shutdown domain controllers (if compromised)
Baltimore Reality:
- Network-wide shutdowns
- Email systems taken offline
- Manual operations initiated
Phase 3 – Eradication
Steps Taken / Should Have Been Taken:
- Full re-imaging of systems (no trust in cleanup)
- Reset all domain credentials
- Patch SMB vulnerabilities
- Remove malicious scheduled tasks
- Audit GPOs for persistence
Key Insight:
Ransomware at domain level = assume total compromise
Phase 4 – Recovery
Recovery Challenges:
- Backups were outdated or inaccessible
- Many systems had no offline backups
- Legacy systems could not be restored quickly
Actions:
- Gradual restoration of critical services
- Migration to new infrastructure
- Manual processing of city services for weeks
Phase 5 – Post-Incident Lessons Learned
- Technical Failures
- Flat network architecture
- Weak patch management
- No EDR
- Inadequate backup strategy
- Excessive admin privileges
- Required Improvements
- Network segmentation (Zero Trust)
- SMB hardening
- EDR + SIEM
- Immutable, offline backups
- Regular tabletop IR exercises
5. Key Takeaways (Defender Perspective)
-
RobbinHood was not sophisticated malware—it succeeded due to:
- Poor hygiene
- Legacy infrastructure
- Slow detection
Ransomware impact cost >200x the ransom
-
IOC-based detection alone is insufficient
→ Behavioral detection is mandatory
