NoName is a pro-Russia hacktivist threat actor primarily associated with disruptive cyber operations against Ukraine and other countries supporting Ukraine. The group is widely known for high-volume distributed denial-of-service activity and coordinated campaigns against government and critical-sector organizations. Reporting also links NoName to targeting telecommunications providers in Ukraine and to broad waves of attacks against Ukrainian government and critical-sector web resources. NoName has been identified among the most active groups targeting Ukraine, where its operations have focused on disruption of public-facing services and pressure against state institutions and critical infrastructure. Targeting has included government entities, telecommunications, and other critical sectors. The group has also been named by Western authorities among pro-Russia hacktivist collectives targeting critical infrastructure organizations worldwide. In addition to disruptive operations, NoName has been linked to unauthorized access affecting municipal water infrastructure in Quebec in October 2025, indicating activity beyond simple denial-of-service and suggesting at least occasional intrusion capability against operationally sensitive environments. The actor is best characterized as a politically aligned hacktivist group supporting Russian interests, with operations centered on disruption, opportunistic intrusion, and targeting of public-sector and critical-infrastructure organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist activity involving unauthorized access to a municipal water treatment facility in Quebec.
NoName is a pro-Russia hacktivist group known for targeting European critical infrastructure with disruptive cyberattacks, including ransomware operations.
NoName is a pro-Russia hacktivist group targeting critical infrastructure organizations worldwide.
Pro-Russia hacktivist group actively targeting critical infrastructure organizations worldwide.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.