CoomingProject is a Russian-aligned criminal extortion group known for stealing victim data and coercing payment by threatening to publish or expose the stolen information rather than relying on widespread file encryption. It has been described as a data-hostage or leak-based extortion operation and has publicly declared support for the Russian government in the context of Russia’s invasion of Ukraine, including statements indicating willingness to assist Russia if cyber operations were conducted against it. The group has been identified alongside other Russia-aligned cybercriminal collectives viewed as potential threats to foreign critical infrastructure and organizations perceived as supporting Ukraine. High-confidence reporting characterizes its core activity as data theft followed by extortion through threatened disclosure, placing it in the category of encryption-less data-theft extortion rather than conventional ransomware deployment. Known aliases include The CoomingProject and the_coomingproject.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian cybercriminal group highlighted in the alert as part of the broader Russian cyber threat landscape.
Russian cybercrime group listed as posing a threat to foreign critical infrastructure targets in the context of the Ukraine war.
CoomingProject is a data extortion group that steals data (without deploying ransomware) and has pledged allegiance to Russia.
Ransomware group mentioned as pledging support to the Russian government in the context of potential retaliatory cyber activity related to the Russia-Ukraine war.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.