NoName057(16) is a pro-Russian hacktivist collective active since March 2022 that primarily conducts politically motivated distributed denial-of-service operations against Ukraine, NATO members, and other governments, public institutions, and private-sector organizations perceived as supporting Ukraine or opposing Russian interests. The group is widely tracked under aliases including NoName057, NoName05716, nnm05716, Nnm05716, and 05716nnm. The actor emerged shortly after Russia’s full-scale invasion of Ukraine, initially targeting Ukrainian media and later expanding across Europe and other NATO-aligned states. Reported victim sectors have included government and public administration, transportation and logistics, banking and financial services, telecommunications, defense-related organizations, media, and energy. Campaigns frequently align with geopolitical flashpoints such as military aid announcements, diplomatic visits, elections, NATO events, and other symbolic moments, indicating a strong propaganda and coercive component in target selection. NoName057(16)’s core tradecraft centers on disruptive DDoS activity rather than stealthy intrusion or long-term espionage. The group publicly claims attacks through Telegram and uses those channels for recruitment, messaging, and amplification of pro-Russian and anti-Western narratives. A defining feature of its operations is the DDoSia ecosystem, a volunteer-driven attack platform that distributes targets and attack parameters to participants and incentivizes contribution with cryptocurrency rewards. Reporting has also linked the group to earlier use of Bobik malware to support involuntary participation in DDoS operations, though its better-known model relies on mobilizing sympathizers and low-skill participants at scale. Technical reporting describes DDoSia as a multi-platform tool that evolved over time and supports common Layer 7 and Layer 4 flooding methods. The group’s infrastructure has used rotating command-and-control tiers and rapid server turnover to sustain operations and complicate disruption. Operational tempo has been high, with thousands of claimed or observed attacks since 2022 and sustained targeting of thousands of hosts across Europe, especially government and public-sector entities. NoName057(16) is generally assessed as less sophisticated than state espionage or sabotage units, but it remains operationally relevant because it can generate repeated service disruption, media attention, and psychological impact at low cost. Multiple assessments characterize the group as closely aligned with Kremlin interests, and some reporting has described it as a Kremlin-linked covert project using Telegram and the DDoSia toolchain. At the same time, public reporting does not uniformly establish formal command-and-control by the Russian state. The actor is best understood as part of the broader pro-Russian hacktivist ecosystem that overlaps with influence operations and, at times, with other Russia-aligned groups such as Cyber Army of Russia Reborn, Killnet affiliates, and Z-Pentest. Law-enforcement action has targeted the group’s infrastructure and participants, including a multinational disruption effort known as Operation Eastwood that reportedly affected more than 100 servers and generated arrests, warrants, and participant notifications. Despite these actions, NoName057(16) has continued to claim attacks and remains one of the most active pro-Russian DDoS-focused hacktivist actors targeting Western and NATO-aligned organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
59 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacktivist activity targeting host-city and government infrastructure with DDoS and reputational disruption during the World Cup.
Groupe hacktiviste pro-russe cité comme l’un des groupes auxquels le suspect arrêté en Espagne serait affilié.
Pro-Russian hacktivist group known for disruptive DDoS attacks against governments and organizations supporting Ukraine. European law enforcement previously disrupted much of its infrastructure, but the group has continued to claim attacks against countries backing Ukraine.
Pro-Russian hacktivist group tied in this reference to claimed operations used to spread pro-Russian and anti-Western narratives and linked to attacks alongside Cyber Army of Russia Reborn.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.