NoName057(16), also known as NoName, NoName057, NoName05716, Nnm05716, and nnm05716, is a pro-Russian hacktivist group active since March 2022. It conducts politically motivated distributed denial-of-service campaigns against Ukraine and governments, institutions, and commercial entities in countries supporting Ukraine or aligned with NATO. U.S. criminal indictments characterize NoName as a state-sanctioned project involving employees of Russia's Center for the Study and Network Monitoring of the Youth Environment (CISM), using infrastructure created by CISM personnel to advance Russian geopolitical interests. The group has claimed hundreds of attacks against government agencies, financial institutions, public railways and ports, military-related organizations, media outlets, telecommunications providers, and freight and transportation entities. NoName057(16) operates the DDoSia project, which recruits international volunteers to run a proprietary DDoS tool against centrally selected targets. It manages and incentivizes participation through public messaging channels, daily leaderboards, military-style rankings, and cryptocurrency rewards. The group combines service disruption with extensive public attribution claims and propaganda-oriented messaging intended to amplify the perceived effect of attacks. Law-enforcement operations, including Operation Eastwood and Operation Red Circus, disrupted its infrastructure in 2025, resulting in server takedowns, arrests, searches, and criminal charges against alleged participants.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
81 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pro-Russian DDoS-focused threat group whose infrastructure was taken down during Operation Eastwood in July 2025.
A Russian-linked hacktivist group associated with CISM and online information operations; cited as a comparable and linked group supporting the assessment that Server Killers may be Russian state-led.
A Russian hacktivist group linked to Server Killers; the article assesses similarities in messaging and characteristics as supporting possible Russian state direction of Server Killers.
Reportedly conducted a cyberattack against Danish websites ahead of the 2025 local elections.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.