NoName057(16): Threat Intelligence Brief
| TLP: WHITE | CYBER THREAT INTELLIGENCE BRIEF |
HACKTIVIST THREAT SERIES
NoName057(16)
A pro-Russian hacktivist collective pairs Telegram-based recruitment and propaganda with DDoSia, a volunteer-driven attack platform, to sustain persistent, crowd-funded DDoS campaigns against government, financial, and infrastructure targets across NATO-aligned countries.
| Prepared by: Cyber Threat Intelligence | 07 August 2026 |
NoName057(16) is a pro-Russian hacktivist collective active since March 2022. Its primary capability is DDoS activity directed at public-facing services, especially government, banking, media, transportation, communications, and utility targets in NATO member states and countries supporting Ukraine.
The group pairs public Telegram-based propaganda and target announcements with DDoSia, a volunteer-driven attack platform that rewards contributors with cryptocurrency. The model makes the actor persistent, highly visible, and able to rebuild participation even when infrastructure is disrupted.
2022 ACTIVE SINCE, TARGETING UKRAINIAN NEWS SITES FIRST | 13,000+ TELEGRAM MEMBERS AT PEAK GROWTH, JUNE 2023 | 4+ ALIGNED HACKTIVIST BRANDS OPERATING IN COORDINATION |
ASSESSMENT
Organizations with publicly exposed web services should treat NoName057(16) as an availability and reputational risk, not primarily an intrusion or data theft actor. Campaign timing is often reactive to geopolitical developments, so elevated monitoring should follow prominent policy, aid, sanctions, or NATO-related announcements. The actor's public claims should be validated independently because claimed outages may overstate impact or conflate temporary availability issues with confirmed compromise.
NoName057(16) operates as a pro-Russian, politically motivated hacktivist brand. It uses a public Telegram presence to amplify political messaging, announce targets, claim responsibility for disruptions, recruit participants, and sustain community engagement. Reporting describes coordination or overlaps with other Russia-aligned hacktivist brands, including Cyber Army of Russia Reborn, Z-Pentest, ServerKillers, and Sector16. Relationships and specific operational roles should be treated as assessed unless independently confirmed.
Targeting Priorities
| Priority | Observed / Stated Targets | Why It Matters |
|---|---|---|
| High | Government websites, public administration portals, online banking and financial services | High public visibility and direct disruption of citizen and customer services |
| Medium | Media, communications, transport, utilities | Operational disruption and propaganda value, especially during geopolitical events |
| Opportunistic | Any public-facing web or API service | DDoS does not require exploitation of a specific product or vulnerability |
Operational Context
The actor's operational impact comes less from technical sophistication than from scale, repeatability, and audience participation. By lowering participation barriers and paying contributors by performance, DDoSia converts politically aligned volunteers into distributed attack capacity. This model can create fast traffic surges without relying exclusively on a traditional compromised device botnet.
NoName057(16) activity centers on availability attacks against internet-facing services. Earlier reporting linked the group to the Bobik botnet, while subsequent campaigns have used DDoSia as a volunteer-distributed alternative. DDoSia has been reported to support Windows, macOS, Linux, and Android, with Windows representing a significant distribution focus.
1. TRIGGER & TARGET SELECTION Political or military event | 2. VOLUNTEER ACTIVATION DDoSia distributed to contributors | 3. COMMAND & CONFIG Encrypted C2 retrieves targets | 4. DDOS EXECUTION Volumetric and app layer floods | 5. AMPLIFICATION Telegram claims and propaganda |
| Phase | Actor Activity | Defensive Observation |
|---|---|---|
| Trigger and target selection | Political or military event is followed by target selection and public coordination, often through Telegram. | Monitor actor channels and sector mentions after high-profile geopolitical events. |
| Volunteer activation | Participants obtain DDoSia and receive target instructions. Contributor payment is tied to activity or rankings. | Watch for distributed, heterogeneous traffic rather than assuming a single botnet signature. |
| Command and configuration | Reported versions use encrypted communications to retrieve target configuration and report attack statistics. | Block validated C2 and distribution indicators. Hunt for unexpected outbound connections on managed endpoints. |
| DDoS execution | Volumetric and application layer request floods attempt to exhaust bandwidth, server capacity, or application resources. | Use CDN, scrubbing, WAF, rate limits, origin protection, and capacity runbooks. |
| Amplification | Telegram claims, screenshots, and propaganda magnify perceived impact and support continued recruitment. | Validate availability impact before public attribution. Coordinate communications and recovery messaging. |
Key Tactics Observed
Multi-Platform DDoSia Client
The client has reportedly evolved through multiple major versions, adding encrypted C2 traffic, proxy support, user agent rotation, and basic anti-analysis features across Windows, macOS, Linux, and Android builds.
Encrypted Configuration Retrieval
The reported client workflow includes an initial system information exchange, retrieval of encrypted target configuration, and periodic activity reporting for contributor tracking.
Volunteer Gamification and Payment
Contributor payment tied to activity or rankings converts politically aligned volunteers into distributed attack capacity, lowering the barrier to participation compared to a traditional botnet.
Propaganda-Driven Amplification
Public-facing web, API, DNS, and identity endpoints are the most relevant exposed assets. Telegram claims and screenshots are used to magnify perceived impact independent of actual outage severity.
DDoS detection should be based on baselines and service health rather than on a single actor signature. Prioritize telemetry that shows request rate, source diversity, geographic distribution, HTTP characteristics, cache hit ratio, origin saturation, and upstream provider mitigation events.
Priority Detection Signals
| Signal | Response Consideration | Severity |
|---|---|---|
| Rapid increase in HTTP/S requests, connections, or bandwidth to public services | Compare against normal events and campaign patterns. Engage CDN or scrubbing provider early. | HIGH |
| High volume requests with repetitive paths, unusual user agents, or low session quality | Apply scoped WAF rules, request challenges, caching, and rate limiting. Protect the origin. | HIGH |
| Traffic concentrated from geographies not relevant to the service | Use risk-based geo controls where business and legal requirements permit. | MEDIUM |
| Mentions of the organization, brand, country, or sector in actor communications | Increase monitoring and confirm asset readiness. Do not treat a claim alone as proof of impact. | MEDIUM |
| Validated DDoSia distribution or C2 indicators in endpoint or network telemetry | Block, investigate affected hosts, preserve evidence, and update detections from trusted threat intelligence feeds. | HIGH |
Response Principles
- Escalate to the ISP, CDN, and DDoS mitigation provider before capacity is exhausted.
- Preserve web, firewall, CDN, and application telemetry so the event can be characterized after restoration.
- Separate service degradation confirmed DDoS activity, and actor attribution in internal and external communications.
- Test degraded service procedures for customer communications, alternate channels, failover, and emergency rate controls.
The following actions are ordered for public-facing service resilience against NoName057(16)-style campaigns. They are broadly applicable to availability threats and should be adapted to business requirements, service criticality, and permitted traffic sources.
1Place DDoS protection in front of exposed services.
Use a reputable CDN or scrubbing service capable of absorbing volumetric traffic and enforcing application layer controls.
2Protect and conceal origin infrastructure.
Restrict origin access to trusted proxy networks, remove direct exposure, and review DNS, certificates, and historical records that may reveal origin IPs.
3Tune WAF, rate limiting, and caching.
Define normal request baselines. Rate limit expensive endpoints, cache static content, and use challenges or rules for anomalous request patterns.
4Prepare a DDoS-specific runbook.
Document escalation contacts, mitigation provider procedures, change authority, failover options, communications templates, and service restoration criteria.
5Use event-driven threat monitoring.
Monitor actor channels and trusted reporting for sector or organization mentions, particularly following Ukraine-related political and military developments.
6Validate intelligence-driven blocks.
Use only vetted, current indicators for C2, domains, and IPs. Expired or unverified block lists may disrupt legitimate traffic and miss changing infrastructure.
| Date | Reported Development |
|---|---|
| March 2022 | NoName057(16) emerges and claims DDoS activity against Ukrainian news sites. |
| September 2022 | Public reporting identifies use of the Bobik botnet for DDoS campaigns. |
| Late 2022 | DDoSia is launched as a volunteer-driven successor model, supported by Telegram recruitment. |
| June 2023 | Reported Telegram membership growth exceeds 13,000 after substantial expansion. |
| June 2025 | DDoS activity reportedly targets services associated with the NATO Summit in the Netherlands. |
| 15 to 17 July 2025 | Operation Eastwood reportedly disrupts elements of the group's infrastructure. |
| December 2025 | CISA advisory AA25-343A addresses opportunistic pro-Russia hacktivist activity against U.S. and global critical infrastructure. |
| February 2026 | DDoS activity reportedly affects targets in Italy and services associated with the Milan-Cortina Winter Olympics. |
Analytic Outlook
| Next 30 Days | Next 60 Days | Next 90 Days |
|---|---|---|
| Continued availability attacks tied to Ukraine aid, sanctions, or NATO-related news are likely. No structural change to the established DDoS pattern is expected. | Further investigative or law enforcement action is plausible, but infrastructure disruption alone is unlikely to eliminate the volunteer-driven model. | Collaboration and co-claiming with aligned hacktivist brands may continue. Any claimed pivot beyond DDoS should be treated as a distinct and higher consequence risk. |
CTI JUDGMENT
Any claimed pivot beyond DDoS, particularly toward operational technology or industrial control system environments, should be treated as a distinct and higher consequence risk requiring independent validation before action.