NoName057(16) is a pro-Russian hacktivist collective active since March 2022 that is primarily known for politically motivated distributed denial-of-service operations against Ukraine and countries supporting Ukraine, especially NATO and European states. Widely used aliases include NoName057, NoName05716, Nnm05716, 05716nnm, and NoName. The group publicly frames its activity as retaliation against governments, institutions, and companies it portrays as hostile to Russian interests, and it consistently amplifies pro-Russian and anti-Western narratives alongside attack claims. The actor’s core tradecraft centers on disruptive DDoS campaigns rather than stealthy intrusion or long-term espionage. Its targeting has included government agencies, public administration, transportation and logistics providers, banks and financial institutions, defense-related organizations, media outlets, telecommunications, and energy-sector entities across Ukraine and Europe, with additional activity reported against organizations in Israel and other NATO-aligned countries. Operations often surge around politically significant events such as military aid announcements, diplomatic visits, elections, NATO summits, and major international sporting events. Public reporting has tied the group to thousands of claimed or verified attacks and to sustained campaigns against several thousand unique hosts over multi-month periods. NoName057(16) relies heavily on Telegram for recruitment, propaganda, target announcement, claims of responsibility, and community management. Its operational ecosystem is closely associated with the DDoSia project, a volunteer-driven attack platform that enables low-skill supporters to participate in coordinated DDoS activity from their own systems. Reporting also describes cryptocurrency-based incentive mechanisms for participants, making the group notable for combining hacktivist branding, crowdsourced disruption, and gamified rewards. Earlier activity has also been linked to Bobik-based involuntary participation, but the group is most strongly associated with the DDoSia volunteer model. Technically, the group is generally assessed as less sophisticated than state espionage operators, but still capable of causing meaningful short-lived service disruption at scale through persistent, coordinated flooding activity. Observed methods include Layer 7 HTTP flooding, HTTP/2 abuse, slow-rate techniques, and Layer 4 TCP SYN flooding. The actor’s infrastructure has used rotating command-and-control tiers to distribute target lists and attack parameters to participants, and reporting indicates continued development of cross-platform tooling for Windows, Linux, and macOS. NoName057(16) is best understood as a disruptive pro-Russian cyber-mobilization actor rather than a classic advanced persistent threat. Multiple assessments describe it as Kremlin-aligned or Kremlin-linked, and some reporting characterizes it as part of a broader Russian hybrid influence and disruption ecosystem. At the same time, high-confidence public reporting most consistently supports describing the group as a pro-Russian hacktivist collective with a strong propaganda component and a deniable relationship to Russian state interests, rather than conclusively as a formal state unit. The group has been associated in reporting with other pro-Russian hacktivist actors and ecosystems, including Cyber Army of Russia Reborn, KillNet affiliates, Z-Pentest, UserSec, and Server Killers. Law-enforcement action has targeted its infrastructure and participants, including the multinational Operation Eastwood disruption, arrests, arrest warrants, and participant notifications. Despite these disruptions, NoName057(16) has continued to claim attacks and remains one of the most visible pro-Russian DDoS-focused threat actors in the European geopolitical cyber landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
59 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Groupe hacktiviste pro-russe cité comme l’un des groupes auxquels le suspect arrêté en Espagne serait affilié.
Pro-Russian hacktivist group known for disruptive DDoS attacks against governments and organizations supporting Ukraine. European law enforcement previously disrupted much of its infrastructure, but the group has continued to claim attacks against countries backing Ukraine.
Pro-Russian hacktivist group tied in this reference to claimed operations used to spread pro-Russian and anti-Western narratives and linked to attacks alongside Cyber Army of Russia Reborn.
Pro-Russian hacktivist group conducting operations later claimed on geopolitical websites to spread pro-Russian and anti-Western narratives.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.