An Iranian national has pleaded guilty to participating in the Robbinhood ransomware operation, which was used to breach the networks, steal data, and encrypt devices of U.S. cities and organizations in an attempt to extort millions of dollars over a five-year span. According to a U.S. Department of Justice and an unsealed indictment, 39-year-old man named Sina Gholinejad, also known as "Sina Ghaaf," and his conspirators deployed the Robbinhood ransomware on breached networks from at least January 2019 through March 2024. The attacks targeted local governments, healthcare providers, and nonprofit organizations, encrypting files and demanding Bitcoin ransoms in return for a decryptor and to prevent data leaks. Victims included the cities of Baltimore, Greenville (North Carolina), Gresham (Oregon), and Yonkers (New York), as well as organizations such as Meridian Medical Group and Berkshire Farm Center. Gholinejad and his co-conspirators often accessed victim networks using administrator accounts or vulnerabilities, deployed the ransomware manually, and demanded payment through Tor dark web sites. However, it wasn't until May 2019 that the Robbinhood gang gained notoriety after disrupting Baltimore's IT systems for weeks. The ransomware gang also conducted data theft in later campaigns, using the stolen data and the threat of leaks as additional leverage against victims. Robbinhood stood out at the time for using a legitimate but vulnerable Gigabyte driver (gdrv.sys) in Bring ...
Iranian pleads guilty to RobbinHood ransomware attacks, faces 30 years
BleepingComputer
·Lawrence Abrams
·Published May 27, 2025
·Updated
Affected Software
2 affected components
GIGABYTE driver=gdrv.sys
Robbinhood ransomware
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses an Iranian national who pleaded guilty to participating in RobbinHood ransomware attacks.
2
What security implications are discussed?
The article highlights the threat of ransomware operations that target U.S. cities and organizations to steal data and demand extortion payments.
3
What products or software are affected?
The affected software includes RobbinHood ransomware and a specific driver from Gigabyte identified as gdrv.sys.
4
What potential penalties does the individual face?
The individual faces up to 30 years in prison for their involvement in the ransomware attacks.
5
What are the methods used by the RobbinHood ransomware operation?
The RobbinHood ransomware operation involves breaching networks, stealing data, and encrypting devices for extortion purposes.