Skip to main content
Mallory
🇷🇺 RU2 malware families

NoName057(16)

Also known asnnm05716noname057noname057(16)noname05716

NoName057(16) is a pro-Russian hacktivist threat actor focused primarily on distributed denial-of-service operations in support of Russia’s geopolitical interests. The group is also referenced as NoName, nnm05716, noname057, and noname05716. Multiple sources in the provided content describe it as Russia-linked or pro-Russian, and U.S. indictments allege it was a state-sanctioned project administered in part by Russia’s Center for the Study and Network Monitoring of the Youth Environment (CISM). Danish authorities further assessed that NoName057(16) has links to the Russian state. The group has targeted governments, political institutions, financial institutions, public railways, ports, utilities, and other critical infrastructure, especially in Ukraine-supporting European and NATO countries. Reported victims and target sets in the content include European government agencies and political institutions, Danish websites ahead of the November 2025 elections, Swedish authorities and banks, Swiss organizations during Ukraine-related political events, Dutch targets during a NATO summit, Italian entities during the Milano Cortina 2026 Winter Games, and broader campaigns against European financial institutions. The content also states that since 2022 the group has conducted more than 3,700 verified DDoS attacks against governments and critical sectors in NATO member states. Operationally, NoName057(16) relies heavily on Telegram for recruitment, propaganda, target distribution, and claims of responsibility. The group regularly posts proof of downtime, pushes daily target lists, and uses gamified participation mechanisms such as leaderboards, badges, and public recognition. U.S. indictment material in the content states that the group primarily uses its proprietary DDoSia tool, and that it recruits volunteers worldwide to download the tool and participate in attacks, rewarding top participants with cryptocurrency. The content also describes DDoSia as a Go-based volunteer-driven client and notes verified uptime checking as part of the group’s campaign workflow. The group has shown a pattern of timing attacks around symbolic or geopolitical events. Examples in the content include activity around the NATO Summit, the Ukraine Peace Summit, the Bürgenstock summit, the Danish elections, and the Milano Cortina 2026 Winter Games. It has also used geopolitical triggers to open new campaigns such as #OpDenmark and has been described as conducting coordinated multi-country sweep campaigns. Beyond its core anti-Ukraine-supporter targeting, the content says NoName057(16) joined broader anti-Israel and pro-Iran cyber activity in March 2026 while still pursuing Russia-linked objectives. It reportedly cooperated with the Cyber Islamic Resistance in DDoS attacks against an Israeli defense contractor and municipal governments, and formed alliances or joint activity with groups including Hider_Nex, Keymous+, Mr Hamza, AnonSec, Moroccan Dragons, Russian Legion, DarkStorm Team, and RuskiNet. The content also references companion or related pro-Russian groups such as Z-Pentest, Sector 16, Dark Engine, and CyberArmyofRussia_Reborn in adjacent reporting, but does not establish them as sub-groups of NoName057(16). Law enforcement action against the group is documented in the content. Operation Eastwood, coordinated by Europol and Eurojust between 14 and 17 July, disrupted more than 100 systems worldwide, took a major part of NoName057(16)’s central infrastructure offline, resulted in arrests, arrest warrants, house searches, and interviews, and identified more than 4,000 supporters and several hundred servers in its botnet. Despite this disruption, the content states the group continued operations into 2026. The content also links infrastructure associated with Stark Industries, WorkTitans, THE.Hosting, and related entities to traffic transit or support for attacks attributed to NoName057(16), including attacks on European institutions and Danish government systems. Overall, the provided material consistently characterizes NoName057(16) as one of the most active pro-Russian DDoS collectives targeting European and NATO-aligned organizations, using volunteer-driven tooling, Telegram-based coordination, and politically timed disruptive campaigns.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Banks
  • Utilities

Where they target

Geographies tied to known operations.

  • 🇮🇹 Italy
  • 🇹🇼 Taiwan
  • 🇺🇦 Ukraine

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics30 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
3 techniques
T1591×2
Gather Victim Org Information
T1592
Gather Victim Host Information
T1595
Active Scanning
T1595.002×2
Vulnerability Scanning
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.003×2
Virtual Private Server
T1584
Compromise Infrastructure
T1584.005
Botnet
TA0001
Initial Access
1 technique
T1133×2
External Remote Services
TA0002
Execution
1 technique
T1651
Cloud Administration Command
TA0003
Persistence
1 technique
T1133×2
External Remote Services
TA0005
Stealth
1 technique
T1027
Obfuscated Files or Information
TA0006
Credential Access
1 technique
T1110
Brute Force
T1110.003×3
Password Spraying
TA0007
Discovery
1 technique
T1046
Network Service Discovery
TA0008
Lateral Movement
1 technique
T1021×3
Remote Services
T1021.005×3
VNC
TA0011
Command and Control
2 techniques
T1071×2
Application Layer Protocol
T1102
Web Service
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
TA0040
Impact
5 techniques
T1486
Data Encrypted for Impact
T1491×3
Defacement
T1491.001
Internal Defacement
T1498×49
Network Denial of Service
T1498.001×8
Direct Network Flood
T1499×5
Endpoint Denial of Service
T1499.001
OS Exhaustion Flood
T1499.002×2
Service Exhaustion Flood
T1499.004
Application or System Exploitation
T1657
Financial Theft
IOCS

Observables

29 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

scworldNews
Jun 5, 2026
Pro-Russian hacker group launches ‘Patriotic Online Games’ campaign targeting European organizations | brief | SC Media

Running the "Patriotic Online Games" campaign to recruit volunteers via Telegram for disruptive cyber operations against European organizations supporting Ukraine, including DDoS attacks, information gathering, and ransomware operations.

Read more
palo alto networks unit 42 blogNews
May 28, 2026
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

Pro-Russian hacktivist group focused on high-volume DDoS campaigns keyed to politically symbolic events, with continued operations into 2026 and expansion toward OT-related targeting.

Read more
dark readingNews
May 28, 2026
Dutch Raid Fails to Dent Russian Bulletproof Host

Pro-Russian group linked in the content to disinformation campaigns and attacks on Danish government systems during the November 2025 elections.

Read more
xakepNews
May 26, 2026
Правоохранительные органы Нидерландов изъяли 800 серверов из-за нарушения санкций ЕС - Хакер

Пророссийская хак-группа, известная атаками на европейские организации и государственные структуры; в материале утверждается, что хостинговая инфраструктура Stark Industries, WorkTitans и Mirhosting использовалась для транзита ее трафика.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping27

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables29

Domains, IPs, and hashes tied to this actor, refreshed continuously.