NoName057(16) is a pro-Russian hacktivist collective that emerged in 2022 after Russia’s invasion of Ukraine and became one of the most visible disruptive actors in the pro-Kremlin ecosystem. The group is widely tracked under aliases including NoName057, NoName05716, and Nnm05716. Its operations are primarily directed at countries, institutions, and companies perceived as supporting Ukraine, especially NATO members and European governments. Targeting has included government bodies, public administration, media, transportation services, telecommunications providers, financial institutions, defense-related organizations, and critical infrastructure operators. The group is best known for large-scale distributed denial-of-service campaigns conducted through the DDoSia project, a Telegram-centered mobilization and attack framework that combines volunteer participation with malware-assisted traffic generation. NoName057(16) uses Telegram extensively for recruitment, propaganda, target selection, and claims of responsibility, and has used GitHub and related distribution channels to broaden access to its tooling. Reporting also links the group to the DDoSia/Dosia malware family and to a broader ecosystem of pro-Russian disruptive actors. Some assessments characterize it as Kremlin-linked or as a covert project aligned with Russian interests, although the degree of formal state control is not uniformly established across reporting. Operationally, NoName057(16) specializes in disruptive attacks and information effects rather than stealthy espionage. Campaigns have repeatedly targeted Ukraine and European states backing Kyiv, including Estonia, Lithuania, Norway, Poland, France, the Netherlands, and other NATO-aligned countries. The group has also claimed attacks against Israeli political and defense-related targets and has been associated with activity around major geopolitical events such as NATO summits and other high-visibility political moments. Public claims have often been used to amplify pro-Russian and anti-Western narratives, and multiple assessments note that the group’s real-world impact is sometimes exaggerated for psychological and propaganda effect. Although historically centered on DDoS, reporting by 2026 indicates operational evolution beyond purely symbolic disruption. High-confidence references describe the group as having incorporated data exfiltration and monetization activity, reflecting broader convergence between hacktivism and cybercrime. It has also been linked in some reporting to access claims against surveillance systems and internal data at targeted organizations. Law-enforcement actions in multiple countries disrupted parts of its infrastructure, including an international operation that affected more than 100 servers and generated arrests, warrants, and participant notifications, but the group continued to claim operations afterward. NoName057(16) should be understood as a persistent pro-Russian disruptive actor whose core value lies in rapid mobilization, scalable DDoS capability, propaganda amplification, and pressure campaigns against governments and organizations aligned against Russian geopolitical interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
60 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacktivist collective conducting large-scale DDoS attacks against NATO-aligned governments and Ukrainian supporters, with evolution into data exfiltration and monetization.
Russian hacktivist group previously associated with disruptive DDoS activity; notably absent in Q2 after law-enforcement pressure.
Active hacktivist group highlighted in the report’s hacktivism section.
An opportunistic anti-Western actor providing symbolic support, amplification, and target selection within the coalition.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.