Home Cyber Security News Ransomware Operator Behind Robbinhood Charged for Targeting Government and Private Networks

Ransomware Operator Behind Robbinhood Charged for Targeting Government and Private Networks

0

Iranian national has pleaded guilty to orchestrating a sophisticated international ransomware operation that targeted critical infrastructure across the United States, causing tens of millions of dollars in damages and severely disrupting essential public services.

Sina Gholinejad, 37, admitted to his role in deploying the Robbinhood ransomware variant against cities, corporations, and healthcare organizations, marking a significant victory for federal prosecutors in their ongoing battle against cybercriminals operating from overseas.

Sina Gholinejad entered a guilty plea today on charges of computer fraud and abuse and conspiracy to commit wire fraud, acknowledging his participation in a ransomware scheme that began in January 2019.

Working alongside overseas co-conspirators, Gholinejad systematically compromised computer networks belonging to various entities throughout the United States, employing sophisticated techniques to maintain unauthorized access to victim systems.

The criminal operation involved copying sensitive information from infected networks to virtual private servers controlled by the conspirators before deploying the Robbinhood ransomware to encrypt victims’ files.

The attackers then demanded Bitcoin payments in exchange for the private keys necessary to restore access to the encrypted data.

To obscure their criminal activities and evade detection, the conspirators employed various technical countermeasures, including virtual private networks, cryptocurrency mixing services, and a practice known as “chain-hopping,” which involves moving assets between different types of cryptocurrencies to launder ransom payments.

Devastating Impact on Municipal Services

The ransomware attacks orchestrated by Gholinejad and his associates caused catastrophic disruptions to essential city services, with the City of Baltimore, Maryland, suffering particularly severe consequences.

Baltimore experienced losses exceeding $19 million due to the attack, which forced the city to take hundreds of computers offline and prevented normal operations for several months.

Critical municipal functions, including online services for processing property taxes, water bills, parking citations, and other revenue-generating activities, remained disrupted for an extended period.

Beyond Baltimore, the criminal network targeted multiple other municipalities, including the City of Greenville, North Carolina, the City of Gresham, Oregon, and the City of Yonkers, New York.

The conspirators strategically used the damage inflicted on these cities as leverage to threaten and extort subsequent victims, demonstrating the calculated nature of their criminal enterprise.

Federal Investigation and International Cooperation

The FBI Charlotte Field Office spearheaded the investigation with substantial assistance from the FBI Baltimore Field Office, demonstrating the coordinated federal response to transnational cybercrime.

According to the Report, Healthcare organizations and private businesses also fell victim to the scheme, highlighting the indiscriminate nature of the attacks against critical infrastructure

International cooperation proved crucial to the case’s success, with Bulgarian judicial and law enforcement partners providing valuable assistance in evidence collection, underscoring the global nature of modern cybercrime investigations.

Gholinejad faces a maximum penalty of 30 years in prison and is scheduled for sentencing in August. The prosecution involves multiple Justice Department divisions, with Senior Counsels from the Criminal Division’s Computer Crime and Intellectual Property Section, Assistant U.S.

Attorneys from the Eastern District of North Carolina, and support from the National Security Division’s National Security Cyber Section working collaboratively on the case.

This conviction represents a significant milestone in federal efforts to hold overseas cybercriminals accountable for attacks on American infrastructure, demonstrating that geographic distance provides no sanctuary from prosecution for those who target U.S. cities, healthcare systems, and businesses.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version