// THREAT ACTOR
ROOK_
DormantROOK is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of ROOK — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2022 1
- 2021 10
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
gamol6n6p2p4c3ad7gxmx3ur7wwdwlywebo2azv3vv5qlmjmole2zbyd.onionWe Are Rook!!! snapshot · 2022-01-25 10:14
Recent victims
The 50 most recent victims claimed by ROOK. Total in the index: 11.
| Date listed | Victim | Description |
|---|---|---|
| 2022-01-08 | Abdi ibrahim | |
| 2021-12-29 | "Отбасы" Тұрғын үй құрылыс жинақ банкі АҚ | |
| 2021-12-28 | Evalueserve | |
| 2021-12-28 | DENSO | |
| 2021-12-28 | Data breach summary | |
| 2021-12-18 | Rossell Techsys(Data will be given tomorrow) | |
| 2021-12-18 | KMG Prestige, Inc. (Data will be given tomorrow) | |
| 2021-12-18 | KMG Prestige, Inc. | |
| 2021-12-14 | Rosendahl Design Group | |
| 2021-12-14 | Rossell Techsys | |
| 2021-12-07 | KMG Prestige, Inc. |