- Home
 - Detectable Ransomware
 - RobinHood HT
 
Ransomware Research
RobinHood HT Ransomware
RobinHood HT is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on April 1, 2019, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: RobinHood HT, Proyecto X, RobinHood-SystemR, RobinHood-Turkish.
Quick Facts
- Ransomware Family
 - RobinHood HT
 - First Seen
 - April 1, 2019
 - Known Aliases
 - RobinHood HTProyecto XRobinHood-SystemRRobinHood-Turkish
 
How RobinHood HT Ransomware Works
File Encryption Patterns
RobinHood HT modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..robinhoodRansom Note and Payment Demands
After encrypting files, RobinHood HT displays ransom notes demanding payment for file recovery:
LEEAME.txtRansom message:
notes/LEEAME.txt
Note locations:
DesktopREAD_IT.txtRansom message:
notes/READ_IT.txt
Note locations:
DesktopReadmeRobinhood.txtNote locations:
DesktopTechnical Indicators
Associated Executable Files
The following executable files are associated with RobinHood HT ransomware:
Proyecto X.exeSystemR.exeTrojan.Ransom.RobinHood.exeRansomware RobinHood.exeRobinHood.exed36e6282363c0f9c05b7b04412d10249323d8b0000f2c25f96c6f9de207eedf8_uOUzNsTRJb.exeeee.exe
Elastio Can Help You
Don't let RobinHood HT ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This RobinHood HT ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like RobinHood HT.
Last updated: October 30, 2025
Recent Ransomware
Explore other threats in our database