Iranian Hacker Pleads Guilty in $19 Million Robbinhood Ransomware Attack on Baltimore

3 Min Read
3 Min Read

An Iranian nationwide has pleaded responsible within the U.S. over his involvement in a global ransomware and extortion scheme involving the Robbinhood ransomware.

Sina Gholinejad (aka Sina Ghaaf), 37, and his co-conspirators are mentioned to have breached the pc networks of assorted organizations in the USA and encrypted information with Robbinhood ransomware to demand Bitcoin ransom funds.

Gholinejad, who was arrested in North Carolina in early January, pleaded responsible to at least one depend of pc fraud and abuse and one depend of conspiracy to commit wire fraud. He faces a most penalty of 30 years in jail. He’s scheduled for sentencing in August 2025.

“These cyber assaults brought on important disruptions and tens of hundreds of thousands in losses, together with to the Metropolis of Greenville, North Carolina, and the Metropolis of Baltimore, Maryland,” the U.S. Division of Justice (DoJ) mentioned.

“Baltimore misplaced greater than $19 million from the injury brought on to their pc networks and the ensuing disruption to a number of important metropolis companies, together with on-line companies for processing property taxes, water payments, parking citations, and different revenue-generating capabilities, which lasted many months.”

Based on court docket paperwork, Gholinejad and others infiltrated and maintained unauthorized entry to sufferer pc networks between January 2019 and March 2024, after which delicate data was copied to digital non-public servers below their management and deployed the ransomware pressure.

The ill-gotten proceeds have been laundered by means of cryptocurrency mixing companies and by transferring belongings between several types of cryptocurrencies, a method referred to as chain-hopping. The risk actors additionally hid their identities and actions through the use of digital non-public networks and servers.

Robbinhood was one of many cybercrime actors to latch onto carry your individual susceptible driver (BYOVD) assaults, using a reputable however susceptible Gigabyte driver (gdrv.sys) to escalate privileges and disarm safety software program.

See also  EncryptHub Deploys Ransomware and Stealer via Trojanized Apps, PPI Services, and Phishing

“Cybercrime shouldn’t be a victimless offense – it’s a direct assault on our communities, as seen on this case. Gholinejad and his co-conspirators orchestrated a ransomware scheme that disrupted lives, companies, and native governments, and resulted in losses of tens of hundreds of thousands of {dollars} from unsuspecting victims and establishments,” mentioned performing U. S. Legal professional Daniel P. Bubar for the Jap District of North Carolina.

Share This Article
Leave a comment