Ransomware group profile · #397 by claimed victims
Cooming ransomware
CoomingProject is a ransomware group that emerged around 2021 and operated a double-extortion scheme with multiple Tor-based leak sites; six members were identified by French authorities in February 2022, after which the group's infrastructure went offline.
Tactics, techniques and procedures
ATT&CK technique mapping for Cooming is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Cooming ransomware still active?
How many victims has Cooming claimed?
Which industries does Cooming target?
Which countries are most affected by Cooming?
Where does VULONE get Cooming victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].