NoName057(16): Threat Intelligence Brief

NoName057(16): Threat Intelligence Brief
NoName057(16) Threat Intelligence Brief
Hunter Strategy
TLP: WHITECYBER THREAT INTELLIGENCE BRIEF

HACKTIVIST THREAT SERIES

NoName057(16)

A pro-Russian hacktivist collective pairs Telegram-based recruitment and propaganda with DDoSia, a volunteer-driven attack platform, to sustain persistent, crowd-funded DDoS campaigns against government, financial, and infrastructure targets across NATO-aligned countries.

Prepared by: Cyber Threat Intelligence07 August 2026
EXECUTIVE SUMMARY

NoName057(16) is a pro-Russian hacktivist collective active since March 2022. Its primary capability is DDoS activity directed at public-facing services, especially government, banking, media, transportation, communications, and utility targets in NATO member states and countries supporting Ukraine.

The group pairs public Telegram-based propaganda and target announcements with DDoSia, a volunteer-driven attack platform that rewards contributors with cryptocurrency. The model makes the actor persistent, highly visible, and able to rebuild participation even when infrastructure is disrupted.

2022
ACTIVE SINCE, TARGETING UKRAINIAN NEWS SITES FIRST
13,000+
TELEGRAM MEMBERS AT PEAK GROWTH, JUNE 2023
4+
ALIGNED HACKTIVIST BRANDS OPERATING IN COORDINATION

ASSESSMENT

Organizations with publicly exposed web services should treat NoName057(16) as an availability and reputational risk, not primarily an intrusion or data theft actor. Campaign timing is often reactive to geopolitical developments, so elevated monitoring should follow prominent policy, aid, sanctions, or NATO-related announcements. The actor's public claims should be validated independently because claimed outages may overstate impact or conflate temporary availability issues with confirmed compromise.

1 Threat Profile

NoName057(16) operates as a pro-Russian, politically motivated hacktivist brand. It uses a public Telegram presence to amplify political messaging, announce targets, claim responsibility for disruptions, recruit participants, and sustain community engagement. Reporting describes coordination or overlaps with other Russia-aligned hacktivist brands, including Cyber Army of Russia Reborn, Z-Pentest, ServerKillers, and Sector16. Relationships and specific operational roles should be treated as assessed unless independently confirmed.

Targeting Priorities

PriorityObserved / Stated TargetsWhy It Matters
HighGovernment websites, public administration portals, online banking and financial servicesHigh public visibility and direct disruption of citizen and customer services
MediumMedia, communications, transport, utilitiesOperational disruption and propaganda value, especially during geopolitical events
OpportunisticAny public-facing web or API serviceDDoS does not require exploitation of a specific product or vulnerability

Operational Context

The actor's operational impact comes less from technical sophistication than from scale, repeatability, and audience participation. By lowering participation barriers and paying contributors by performance, DDoSia converts politically aligned volunteers into distributed attack capacity. This model can create fast traffic surges without relying exclusively on a traditional compromised device botnet.

2 Attack Chain and Tradecraft

NoName057(16) activity centers on availability attacks against internet-facing services. Earlier reporting linked the group to the Bobik botnet, while subsequent campaigns have used DDoSia as a volunteer-distributed alternative. DDoSia has been reported to support Windows, macOS, Linux, and Android, with Windows representing a significant distribution focus.

1. TRIGGER & TARGET SELECTION
Political or military event
2. VOLUNTEER ACTIVATION
DDoSia distributed to contributors
3. COMMAND & CONFIG
Encrypted C2 retrieves targets
4. DDOS EXECUTION
Volumetric and app layer floods
5. AMPLIFICATION
Telegram claims and propaganda
PhaseActor ActivityDefensive Observation
Trigger and target selectionPolitical or military event is followed by target selection and public coordination, often through Telegram.Monitor actor channels and sector mentions after high-profile geopolitical events.
Volunteer activationParticipants obtain DDoSia and receive target instructions. Contributor payment is tied to activity or rankings.Watch for distributed, heterogeneous traffic rather than assuming a single botnet signature.
Command and configurationReported versions use encrypted communications to retrieve target configuration and report attack statistics.Block validated C2 and distribution indicators. Hunt for unexpected outbound connections on managed endpoints.
DDoS executionVolumetric and application layer request floods attempt to exhaust bandwidth, server capacity, or application resources.Use CDN, scrubbing, WAF, rate limits, origin protection, and capacity runbooks.
AmplificationTelegram claims, screenshots, and propaganda magnify perceived impact and support continued recruitment.Validate availability impact before public attribution. Coordinate communications and recovery messaging.

Key Tactics Observed

Multi-Platform DDoSia Client

The client has reportedly evolved through multiple major versions, adding encrypted C2 traffic, proxy support, user agent rotation, and basic anti-analysis features across Windows, macOS, Linux, and Android builds.

Encrypted Configuration Retrieval

The reported client workflow includes an initial system information exchange, retrieval of encrypted target configuration, and periodic activity reporting for contributor tracking.

Volunteer Gamification and Payment

Contributor payment tied to activity or rankings converts politically aligned volunteers into distributed attack capacity, lowering the barrier to participation compared to a traditional botnet.

Propaganda-Driven Amplification

Public-facing web, API, DNS, and identity endpoints are the most relevant exposed assets. Telegram claims and screenshots are used to magnify perceived impact independent of actual outage severity.

3 Detection and Response

DDoS detection should be based on baselines and service health rather than on a single actor signature. Prioritize telemetry that shows request rate, source diversity, geographic distribution, HTTP characteristics, cache hit ratio, origin saturation, and upstream provider mitigation events.

Priority Detection Signals

SignalResponse ConsiderationSeverity
Rapid increase in HTTP/S requests, connections, or bandwidth to public servicesCompare against normal events and campaign patterns. Engage CDN or scrubbing provider early.HIGH
High volume requests with repetitive paths, unusual user agents, or low session qualityApply scoped WAF rules, request challenges, caching, and rate limiting. Protect the origin.HIGH
Traffic concentrated from geographies not relevant to the serviceUse risk-based geo controls where business and legal requirements permit.MEDIUM
Mentions of the organization, brand, country, or sector in actor communicationsIncrease monitoring and confirm asset readiness. Do not treat a claim alone as proof of impact.MEDIUM
Validated DDoSia distribution or C2 indicators in endpoint or network telemetryBlock, investigate affected hosts, preserve evidence, and update detections from trusted threat intelligence feeds.HIGH

Response Principles

  • Escalate to the ISP, CDN, and DDoS mitigation provider before capacity is exhausted.
  • Preserve web, firewall, CDN, and application telemetry so the event can be characterized after restoration.
  • Separate service degradation confirmed DDoS activity, and actor attribution in internal and external communications.
  • Test degraded service procedures for customer communications, alternate channels, failover, and emergency rate controls.
4 Mitigation Priorities

The following actions are ordered for public-facing service resilience against NoName057(16)-style campaigns. They are broadly applicable to availability threats and should be adapted to business requirements, service criticality, and permitted traffic sources.

1Place DDoS protection in front of exposed services.

Use a reputable CDN or scrubbing service capable of absorbing volumetric traffic and enforcing application layer controls.

2Protect and conceal origin infrastructure.

Restrict origin access to trusted proxy networks, remove direct exposure, and review DNS, certificates, and historical records that may reveal origin IPs.

3Tune WAF, rate limiting, and caching.

Define normal request baselines. Rate limit expensive endpoints, cache static content, and use challenges or rules for anomalous request patterns.

4Prepare a DDoS-specific runbook.

Document escalation contacts, mitigation provider procedures, change authority, failover options, communications templates, and service restoration criteria.

5Use event-driven threat monitoring.

Monitor actor channels and trusted reporting for sector or organization mentions, particularly following Ukraine-related political and military developments.

6Validate intelligence-driven blocks.

Use only vetted, current indicators for C2, domains, and IPs. Expired or unverified block lists may disrupt legitimate traffic and miss changing infrastructure.

5 Timeline and Outlook
DateReported Development
March 2022NoName057(16) emerges and claims DDoS activity against Ukrainian news sites.
September 2022Public reporting identifies use of the Bobik botnet for DDoS campaigns.
Late 2022DDoSia is launched as a volunteer-driven successor model, supported by Telegram recruitment.
June 2023Reported Telegram membership growth exceeds 13,000 after substantial expansion.
June 2025DDoS activity reportedly targets services associated with the NATO Summit in the Netherlands.
15 to 17 July 2025Operation Eastwood reportedly disrupts elements of the group's infrastructure.
December 2025CISA advisory AA25-343A addresses opportunistic pro-Russia hacktivist activity against U.S. and global critical infrastructure.
February 2026DDoS activity reportedly affects targets in Italy and services associated with the Milan-Cortina Winter Olympics.

Analytic Outlook

Next 30 DaysNext 60 DaysNext 90 Days
Continued availability attacks tied to Ukraine aid, sanctions, or NATO-related news are likely. No structural change to the established DDoS pattern is expected.Further investigative or law enforcement action is plausible, but infrastructure disruption alone is unlikely to eliminate the volunteer-driven model.Collaboration and co-claiming with aligned hacktivist brands may continue. Any claimed pivot beyond DDoS should be treated as a distinct and higher consequence risk.

CTI JUDGMENT

Any claimed pivot beyond DDoS, particularly toward operational technology or industrial control system environments, should be treated as a distinct and higher consequence risk requiring independent validation before action.

Read more