Baltimore City Government Ransomware Attack – RobbinHood

On May 7, 2019, Baltimore City’s government systems were crippled by a major ransomware attack known as RobbinHood. The malware locked critical files and shut down most city servers, bringing many day-to-day operations to a halt. Only essential emergency services, such as police and fire departments, were able to continue functioning.

The attackers demanded 13 Bitcoin, worth about $76,000 at the time, in exchange for restoring access to the systems. After consulting with the FBI and the U.S. Secret Service, city leaders chose not to pay the ransom, instead beginning a lengthy and costly recovery process to rebuild and secure their systems.

1. Executive Technical Summary

  • Victim: Baltimore City Government
  • Threat Actor / Malware: RobbinHood ransomware
  • Attack Type: Targeted ransomware (not commodity spray-and-pray)
  • Initial Compromise Window: Likely weeks before detonation
  • Impact:
    • ~10,000 city workstations
    • Email, payment systems, real estate, utilities, courts disrupted
  • Ransom Demand: ~13 BTC (~$76k at the time)
  • Estimated Recovery Cost: >$18 million
  • Key Failure Point: Unpatched SMB vulnerabilities + weak internal segmentation

2. Attack Chain (MITRE ATT&CK Mapping)

Phase 1 – Initial Access

Likely Vector:

  • Exploitation of unpatched SMB vulnerabilities
  • Possibly EternalBlue (MS17-010) or similar lateral SMB exploit

MITRE:

  • T1190 – Exploit Public-Facing Application
  • T1210 – Exploitation of Remote Services

Phase 2 – Privilege Escalation & Lateral Movement

Once inside:

  • Attacker gained domain-level privileges
  • Used SMB + PsExec + scheduled tasks
  • Moved laterally across flat network segments

MITRE:

  • T1078 – Valid Accounts
  • T1021.002 – SMB/Windows Admin Shares
  • T1053 – Scheduled Task/Job

Phase 3 – Defense Evasion

RobbinHood is highly evasive:

  • Kills security services
  • Disables Windows Defender
  • Stops backup-related processes
  • Executes from non-standard directories
  • Uses delayed execution

MITRE:

  • T1562 – Impair Defenses
  • T1070 – Indicator Removal on Host

Phase 4 – Payload Execution (Ransomware)

  • Custom RobbinHood.exe
  • Uses AES-256 for file encryption
  • RSA used for key protection
  • Drops ransom note per directory

MITRE:

  • T1486 – Data Encrypted for Impact


3. IOCS – Indicators of Compromise (Detailed)

A. File-Based IOCs

Common Filenames:

  1. RobbinHood.exe
  2. run32.exe
  3. taskhostsvc.exe (masquerading)

Ransom Note Files:

  1. README.txt
  2. READ_IT.txt
  3. HOW_TO_RECOVER_FILES.txt

Encrypted File Extension:

.<random or .robbinhood>

B. Hash-Based IOCs (Example)

  • 07a133bda8f5039c30b4118167d1c2e79906c79ea52ed73f1767921ce146d97d
  • 3bc78141ff3f742c5e942993adfbef39c2127f9682a303b5e786ed7f9a8d184b
  • 47d892da6a49b02a2904bdc0d03ecef66c076481d19ab19251d86d11be494765
  • 7c7ef3ab31ab91a7379bc2e3f32473dfa7adf662d0c640ef994103f6022a092b
  • 9ffacdba165181e10bedbecce31143bb65b7e59e560e36e561b149295742d085
  • cda83bc9958f3f82e41ad5bb1816e936df7dfdf4630937d6636d0ad725759784
  • e2ae71899ee9cd748c95b4ce3df103106b9d943bd69e657f6d194ac33790f261
  • e9188ace227b00cbf1f6fba3ceb32af8e4d456c3a0815300a224a9d9e00778a8

C. Registry-Based IOCs

Persistence mechanisms:

  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run

The following registry keys are auto-start extensibility points (ASEPs) in Windows.
Any executable or script referenced here is launched automatically when a user logs in.

Added values pointing to malicious executables in temp or admin shares.


D. Process & Memory IOCs

Suspicious process activity:

  • vssadmin delete shadows /all /quiet
  • wbadmin delete catalog -quiet
  • sc stop WinDefend
  • net stop backup services

Abnormal parent-child relationships:

  • services.exe → RobbinHood.exe
  • svchost.exe → cmd.exe → psexec.exe

E. Network IOCs

Lateral Movement:

  • TCP 445 (SMB)
  • RPC over 135
  • Admin shares:
    • \\C$\Windows\Temp
    • \\ADMIN$
  • hxxps://xbt4titax4pzza6w[.]onion
  • hxxps://xbt4titax4pzza6w[.]onion.pet
  • hxxps://xbt4titax4pzza6w[.]onion.to

C2 Characteristics:

  • No long-term C2 beaconing
  • Mostly offline execution
  • Limited outbound traffic (harder to detect)

4. IR (Incident Response) – Technical Walkthrough

Phase 1 – Identification

Indicators observed:

  • Mass file encryption
  • Ransom notes appearing simultaneously
  • Spike in SMB traffic
  • Endpoint AV disabled

Failures:

  • No early EDR telemetry
  • Lack of centralized log correlation
  • Attack went undetected until detonation

Phase 2 – Containment

Immediate Actions Required (Best Practice):

  • Disconnect infected hosts from network
  • Disable SMB across segments
  • Block lateral admin credentials
  • Shutdown domain controllers (if compromised)

Baltimore Reality:

  • Network-wide shutdowns
  • Email systems taken offline
  • Manual operations initiated

Phase 3 – Eradication

Steps Taken / Should Have Been Taken:

  • Full re-imaging of systems (no trust in cleanup)
  • Reset all domain credentials
  • Patch SMB vulnerabilities
  • Remove malicious scheduled tasks
  • Audit GPOs for persistence

Key Insight:

Ransomware at domain level = assume total compromise


Phase 4 – Recovery

Recovery Challenges:

  • Backups were outdated or inaccessible
  • Many systems had no offline backups
  • Legacy systems could not be restored quickly

Actions:

  • Gradual restoration of critical services
  • Migration to new infrastructure
  • Manual processing of city services for weeks

Phase 5 – Post-Incident Lessons Learned

  • Technical Failures
  • Flat network architecture
  • Weak patch management
  • No EDR
  • Inadequate backup strategy
  • Excessive admin privileges
  • Required Improvements
  • Network segmentation (Zero Trust)
  • SMB hardening
  • EDR + SIEM
  • Immutable, offline backups
  • Regular tabletop IR exercises

5. Key Takeaways (Defender Perspective)

  • RobbinHood was not sophisticated malware—it succeeded due to:

  • Poor hygiene
  • Legacy infrastructure
  • Slow detection

Ransomware impact cost >200x the ransom

  • IOC-based detection alone is insufficient
    Behavioral detection is mandatory