Netskope Threat Labs

RobinHood

ATP Sandbox Adv. HeuristicsAV

RobinHood is a ransomware family that used signed kernel drivers to gain access to the Windows kernel, an unusual and dangerous technique for bypassing security products. Its campaigns included the high profile attack on the city of Baltimore.

First seen
February 2022
Last seen
September 2026
Alert Name
Gen:Heur.Ransom.RobinHood.2
Trojan.Ransom.RobinHood.A
Win32.Ransomware.RobinHood