• News/
  • https://www.bleepingcomputer.com/news/security/iranian-pleads-guilty-to-robbinhood-ransomware-attacks-faces-30-years/

Iranian pleads guilty to RobbinHood ransomware attacks, faces 30 years

BleepingComputer
·
Lawrence Abrams
·
Published May 27, 2025
·
Updated

An Iranian national has pleaded guilty to participating in the Robbinhood ransomware operation, which was used to breach the networks, steal data, and encrypt devices of U.S. cities and organizations in an attempt to extort millions of dollars over a five-year span. According to a U.S. Department of Justice and an unsealed indictment, 39-year-old man named Sina Gholinejad, also known as "Sina Ghaaf," and his conspirators deployed the Robbinhood ransomware on breached networks from at least January 2019 through March 2024. The attacks targeted local governments, healthcare providers, and nonprofit organizations, encrypting files and demanding Bitcoin ransoms in return for a decryptor and to prevent data leaks. Victims included the cities of Baltimore, Greenville (North Carolina), Gresham (Oregon), and Yonkers (New York), as well as organizations such as Meridian Medical Group and Berkshire Farm Center. Gholinejad and his co-conspirators often accessed victim networks using administrator accounts or vulnerabilities, deployed the ransomware manually, and demanded payment through Tor dark web sites. However, it wasn't until May 2019 that the Robbinhood gang gained notoriety after disrupting Baltimore's IT systems for weeks. The ransomware gang also conducted data theft in later campaigns, using the stolen data and the threat of leaks as additional leverage against victims. Robbinhood stood out at the time for using a legitimate but vulnerable Gigabyte driver (gdrv.sys) in Bring ...

Read full article

Affected Software

2 affected components
GIGABYTE driver=gdrv.sys
Robbinhood ransomware
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an Iranian national who pleaded guilty to participating in RobbinHood ransomware attacks.

2

What security implications are discussed?

The article highlights the threat of ransomware operations that target U.S. cities and organizations to steal data and demand extortion payments.

3

What products or software are affected?

The affected software includes RobbinHood ransomware and a specific driver from Gigabyte identified as gdrv.sys.

4

What potential penalties does the individual face?

The individual faces up to 30 years in prison for their involvement in the ransomware attacks.

5

What are the methods used by the RobbinHood ransomware operation?

The RobbinHood ransomware operation involves breaching networks, stealing data, and encrypting devices for extortion purposes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Iranian pleads guilty to RobbinHood ransomware attacks, faces 30 years - SecAlerts