NoName057(16), also known as NoName057, NoName05716, nnm05716, and 05716nnm, is a pro-Russian hacktivist collective that emerged in March 2022 shortly after Russia’s full-scale invasion of Ukraine. The group is widely tracked for sustained, politically motivated distributed denial-of-service activity against Ukraine and countries perceived as supporting Ukraine, especially NATO and European states. Its operations are aligned with pro-Kremlin and anti-Western narratives, and multiple assessments describe it as Russia-linked or Kremlin-linked, although public reporting does not uniformly establish formal state control. The group primarily targets government institutions, public administration, transportation and logistics providers, financial institutions, media organizations, telecommunications, defense-related entities, and energy or other critical infrastructure-adjacent organizations. Targeting has repeatedly expanded beyond Ukraine to European countries including France, Italy, the Netherlands, Spain, Lithuania, Denmark, Sweden, Poland, Germany, and Japan-linked government services, with attacks often timed to geopolitical events such as military aid announcements, NATO summits, high-profile diplomatic visits, elections, and other symbolic moments. NoName057(16)’s core tradecraft centers on disruptive DDoS operations intended to cause temporary service outages, generate publicity, and amplify psychological and propaganda effects. The group publicly claims operations through Telegram and related propaganda channels, framing attacks as retaliation against governments or organizations viewed as hostile to Russian interests. Reporting consistently indicates that the group often seeks visibility and narrative impact as much as technical effect, and some claims may exaggerate operational consequences. A defining feature of NoName057(16) is its volunteer-driven DDoS ecosystem built around the DDoSia project, also referred to in some reporting as DDOSIA. Through Telegram-based recruitment and coordination, supporters are encouraged to run attack software on their own systems, receive targeting instructions from command infrastructure, and in some cases obtain cryptocurrency-based rewards tied to participation or performance. Technical reporting describes DDoSia as a multi-platform tool that evolved over time, including a shift to Go-based implementations and more structured command-and-control, enabling broad participation by low-skill supporters. Earlier reporting also linked the group to Bobik malware and involuntary botnet-style participation supporting DDoS activity. Observed attack methods are predominantly application-layer and network-layer flooding techniques, including HTTP-focused attacks and TCP SYN flooding, with emphasis on publicly exposed web services. The group’s operational model relies on rapid mobilization, frequent target rotation, and sustained campaign tempo rather than stealth, persistence, or advanced intrusion tradecraft. Government and public-sector entities appear to be the most consistently targeted sector. NoName057(16) has been associated with campaigns against organizations in Europe and Israel, and has been repeatedly cited as one of the most active pro-Russian hacktivist actors since 2022. It has targeted entities connected to support for Ukraine directly or indirectly, including ministries, municipalities, digital identity and public-service platforms, transport operators, banks, defense-related firms, and other civilian infrastructure. Some reporting also attributes access claims and surveillance-related compromise claims to the group, but its best-established activity remains disruptive DDoS operations. Law-enforcement action has targeted the group’s infrastructure and participants. International disruption efforts, including Operation Eastwood, reportedly led to arrests, warrants, participant notifications, and the disruption of more than 100 servers associated with its attack infrastructure. Despite these actions, the group has continued to claim attacks and remains a persistent hybrid threat actor in the pro-Russian hacktivist ecosystem. NoName057(16) is frequently discussed alongside other pro-Russian hacktivist or cyber-militia brands such as Killnet, Cyber Army of Russia Reborn, and Z-Pentest. It should be understood as a high-tempo, propaganda-oriented disruptive actor whose significance lies less in sophisticated intrusion capability than in its ability to mobilize supporters quickly, sustain politically themed DDoS campaigns, and contribute to broader Russian information and coercive pressure operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
59 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting sustained pro-Russian hacktivist operations against French targets, including DDoS, CCTV/data access claims, and defacement tied to France's support for Ukraine.
Pro-Russian hacktivist activity targeting host-city and government infrastructure with DDoS and reputational disruption during the World Cup.
Groupe hacktiviste pro-russe cité comme l’un des groupes auxquels le suspect arrêté en Espagne serait affilié.
Pro-Russian hacktivist group known for disruptive DDoS attacks against governments and organizations supporting Ukraine. European law enforcement previously disrupted much of its infrastructure, but the group has continued to claim attacks against countries backing Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.