An Iranian national has admitted his role in orchestrating one of the most damaging ransomware campaigns against U.S. infrastructure, marking a significant victory in international cybercrime prosecution.
Sina Gholinejad, 37, pleaded guilty Tuesday in North Carolina federal court to charges stemming from a sophisticated cyber operation that caused tens of millions of dollars in losses across multiple sectors.
Gholinejad’s guilty plea on charges of computer fraud and abuse and conspiracy to commit wire fraud represents a breakthrough in the investigation of the RobbinHood ransomware scheme that terrorized American cities and organizations from January 2019 through March 2024.
The operation targeted critical infrastructure, including municipal governments, healthcare organizations, and private corporations, with the City of Baltimore suffering the most devastating blow.
The Justice Department said the Baltimore attack alone resulted in over $19 million in damages, crippling essential city services for months.
Citizens were unable to access online systems for processing property taxes, water bills, and parking citations, while the city’s email and voicemail systems were completely paralyzed.
The attackers demanded 13 Bitcoins, worth approximately $76,000 at the time, to restore access to encrypted systems.
Beyond Baltimore, the scheme targeted numerous other municipalities, including Greenville, North Carolina; Gresham, Oregon; and Yonkers, New York, demonstrating the campaign’s broad scope and devastating impact on American communities.
The RobbinHood ransomware distinguished itself through unprecedented technical sophistication, employing a “bring-your-own-vulnerability” tactic that exploited legitimate software to bypass security protections.
The malware utilized a vulnerable Gigabyte motherboard driver (GDRV.SYS) with a known security flaw tracked as CVE-2018-19320 to gain kernel-level access to victim systems.
This technique allowed attackers to temporarily disable Windows driver signature enforcement by modifying kernel memory, enabling them to install their own malicious unsigned driver (RBNL.SYS).
The secondary driver systematically eliminated antivirus and security software processes, creating a clear path for file encryption without interference.
The ransomware employed dual-layer encryption using AES for individual files and RSA-4096 for encrypting the AES keys, making decryption virtually impossible without the attackers’ private keys.
Before beginning encryption, the malware would disconnect all network shares using the command cmd.exe /c net use * /DELETE /Y, ensuring each system was targeted individually.
Gholinejad’s arrest at Raleigh-Durham International Airport on January 10, 2025, culminated years of international investigation involving multiple federal agencies.
The case demonstrates the global reach of modern cybercrime, with conspirators operating sophisticated infrastructure including virtual private networks, cryptocurrency mixing services, and “chain-hopping” techniques to launder Bitcoin payments.
The prosecution relied heavily on international cooperation, with Bulgarian authorities providing crucial evidence collection assistance.
FBI Charlotte Field Office led the investigation with support from the Baltimore Field Office and the Justice Department’s National Security Cyber Section.
Facing a maximum sentence of 30 years in prison, Gholinejad’s case sends a clear message that geographic distance provides no sanctuary for cybercriminals targeting American infrastructure.
The conviction represents a significant milestone in combating ransomware operations that continue to threaten critical services nationwide.
Try in-depth sandbox malware analysis for your SOC team. Get ANY.RUN special offer only until May 31 -> Try Here
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…