Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationoperational-disruptionphishing-campaign-intelligencegovernment-diplomatic-threat

DDoS and Phishing Activity Targeting Germany, Israel, and Canadian Residents

Updated 3mo agoFirst seen Mar 12, 20262 sources

Reporting described multiple, unrelated threat activities rather than a single cohesive incident. SOCRadar assessed a sustained DDoS campaign by NoName057(16) using the DDoSia toolset during March 2–8, 2026, logging 7,512 attack entries against 169 domains and 153 IPs, with Germany as the primary target (65.6% of entries) and Israel as a major secondary target (19.7%). The most notable pattern was heavy, systematic disruption of Germany’s public procurement ecosystem, including at least 17 procurement portals (974 entries), alongside Israeli targeting across defense industry, finance, telecom, and municipal services.

Separately, Flare reported an active phishing campaign using fraudulent domains impersonating Canadian institutions (including the Government of British Columbia and Hydro-Québec) to harvest personal and payment data; the infrastructure was linked to RouterHosting LLC / Cloudzy, a provider previously accused (in 2023) of supporting services used by multiple state-sponsored groups, including Iran-aligned actors. Two other items were not incident-specific: Hackmageddon published aggregated February 2026 attack statistics, and DataBreaches.Net summarized research on offender age distribution in cybercrime; both are higher-level analysis and do not materially add to the DDoS or phishing reporting.

Share:
DDoS and Phishing Activity Targeting Germany, Israel, and Canadian Residents
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 10, 20263mo ago

Infrastructure analysis links phishing domains to RouterHosting/Cloudzy

Flare's analysis connected multiple phishing domains through shared hosting IPs and SSL certificate data, repeatedly tying the infrastructure to RouterHosting LLC, rebranded as Cloudzy. A broader scan found more than 28,000 RouterHosting-hosted domains, including 134 .ca domains, many with suspicious Canada-themed naming patterns.

Active phishing campaign targets Canadians via fake government and utility domains

By March 2026, researchers observed an active phishing campaign using fraudulent domains impersonating institutions including the Government of British Columbia and Hydro-Québec to steal personal and payment-card information from Canadian residents. The phishing flow accepted obviously invalid personal data before requesting card details, indicating weak or absent validation.

Mar 3, 20264mo ago

DDoS activity peaks and German procurement portals are heavily targeted

On March 3, 2026, the campaign reached its peak volume, with Germany's public procurement ecosystem emerging as a major focus. At least 17 procurement portals were attacked for 974 entries, an unprecedented concentration by this actor against a single government function.

Mar 2, 20264mo ago

NoName057(16) launches coordinated DDoS campaign against Germany and Israel

During March 2–8, 2026, the pro-Russian hacktivist group NoName057(16) conducted a sustained DDoS campaign using DDoSia, generating 7,512 recorded attack entries. Germany was the main target and Israel a major secondary target, with the activity described as geopolitically motivated.

Jan 1, 20233y ago

Prior public allegations tie Cloudzy to state-sponsored hacking groups

In 2023, public reporting by Halcyon and Reuters alleged that Cloudzy/RouterHosting had provided services to numerous state-sponsored hacking groups. The March 2026 phishing infrastructure assessment cites these earlier allegations as relevant context for the current campaign.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Threat actors
1 linked
Affected products
1 linked
Telegram
Organizations
27 linked
Elron VenturesElbit SystemsSOCRadarDeutsche BörseMizrahi Tefahot BankBank LeumiDelek GroupBezeqIsrael Aerospace IndustriesCellcomAeronauticsCargalMekorotUrban AeronauticsMaarivBazan GroupIsrael RailwaysSting TVFirst International Bank of IsraelFraunhofer InstituteRafael Advanced Defense SystemsCFI CapitalHOT MobileThe Jerusalem PostCamtekElectra AfikimIsrael Electric Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.