CoomingProject is a Russian-aligned cybercriminal extortion group known primarily for data-theft and leak-based extortion rather than conventional file-encrypting ransomware deployment. The group has been described as a data hostage operation that steals victim information and pressures organizations into payment by threatening public exposure of the stolen data. CoomingProject emerged in public reporting during the period surrounding Russia’s 2022 invasion of Ukraine, when it publicly declared support for the Russian government and indicated willingness to assist Russia in the event of cyber operations against Russian interests. It has consequently been included in multiple government and industry overviews of Russia-aligned cybercriminal groups that may pose a threat to organizations supporting Ukraine or operating in critical infrastructure sectors. The actor is commonly referenced as CoomingProject or The CoomingProject, with observed aliases including coomingproject and the_coomingproject. It has been grouped alongside other Russia-aligned criminal or hacktivist actors such as Killnet, Wizard Spider, Mummy Spider, Salty Spider, Scully Spider, Smokey Spider, and XakNet Team in strategic threat reporting. High-confidence reporting characterizes CoomingProject as financially motivated, using extortion through exposure or threatened exposure of stolen data. Publicly available information in this context does not establish a broader, distinctive malware toolkit or a well-documented operational history beyond its extortion model and pro-Russian alignment statements. Its significance is therefore primarily as a Russia-aligned criminal threat actor whose public political positioning increased concern about opportunistic retaliatory cyber activity against foreign organizations during the Ukraine conflict.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian cybercriminal group highlighted in the alert as part of the broader Russian cyber threat landscape.
Russian cybercrime group listed as posing a threat to foreign critical infrastructure targets in the context of the Ukraine war.
CoomingProject is a data extortion group that steals data (without deploying ransomware) and has pledged allegiance to Russia.
Ransomware group mentioned as pledging support to the Russian government in the context of potential retaliatory cyber activity related to the Russia-Ukraine war.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.