CSIDB logo
Threat actor

CoomingProject

Attribution profile

Type
Activist
Location
Russia
Known incidents
3 incidents
First seen
2021-09-09
Last seen
2022-02-24
Updated
2026-07-31 00:49
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

CoomingProject is a threat actor identified by that alias and is associated with Russia. The group claims to have a list of victims spanning multiple countries. It states on its site that it is not a ransomware group and does not issue ransom demands. Their observed activity involves the removal of data from victim systems and its subsequent public release.

In September 2021 CoomingProject targeted the Mexican government health agency Instituto Nacional de Medicina Genómica (Inmegen), which conducts COVID‑19 research. They claimed to have exfiltrated about 50 gigabytes of data, including patient names, dates of birth, contact information and COVID‑19 test results. Also in September 2021 the group claimed responsibility for a breach of the South African National Space Agency (SANSA). The SANSA incident resulted in a roughly 16‑terabyte data dump that appeared on a Russian‑language forum.

For the Inmegen attack the attackers released a portion of the data publicly, which included a folder with more than two dozen PDF reports and a README file that referenced the Telegram channel KelvinSecTeam. The SANSA leak was simultaneously claimed by another threat actor, GhostSec, who asserted responsibility for the same 16‑terabyte dump on the forum. No public acknowledgment or response was received from Inmegen regarding the incident at the time of reporting. The SANSA data was later removed from the attackers’ site, though the forum copy remained accessible.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB