DDoSia is a custom, volunteer-driven distributed denial-of-service platform associated with the pro-Russian hacktivist group NoName057(16) and active since early 2022. It is described as the successor to the earlier Bobik botnet and is used to coordinate crowdsourced DDoS attacks rather than a traditional botnet-only model. NoName057(16) distributes DDoSia primarily via Telegram, and has also used GitHub and other repositories to host the tool and related materials. Volunteers register through a Telegram bot, obtain a client ID or user hash, install the client on their own devices, and contribute computing resources to attacks; participants may receive cryptocurrency-based rewards, public recognition, and leaderboard placement.
The malware/tooling has evolved from early Python implementations to Go-based versions to improve performance and cross-platform support. Reported builds support Windows, Linux, and macOS, including x64, ARM, and ARM64 variants. The platform has also been referred to as Dosia, Go Stresser, and in one current form as “People Go Stresser 2.0.” DDoSia communicates with centralized command-and-control infrastructure to authenticate clients and retrieve target lists and attack parameters. Earlier communications were reportedly in cleartext, while since 2024 communications have used AES-GCM encryption. Retrieved configurations have included target identifiers, host IPs, request types, ports, and other settings. Analysis of Windows samples showed the client downloads encrypted target lists, decrypts them in memory, and then launches attack threads.
DDoSia supports both application-layer and transport-layer DDoS techniques. Reported attack modes and methods include HTTP, HTTP2, HTTP/3, nginx_loris/slow-rate attacks, TCP floods including SYN, ACK, and SYN-ACK flooding, UDP floods, ICMP/PING attacks, and HTTP GET and POST floods. Reporting states that attacks heavily target HTTPS services on port 443, with additional targeting of ports 80/8080 and smaller volumes against services such as SSH, FTP, and secure email ports. The tool is designed to allow individuals with minimal technical skill to participate in coordinated attacks.
The platform has been used extensively in politically motivated campaigns aligned with Russian geopolitical objectives, especially against Ukraine, NATO member states, and other European countries supporting Ukraine. Reported targets include government and public-sector entities, transportation and logistics, financial institutions, telecommunications, defense-related organizations, ports, railways, media, energy, tourism, and other critical infrastructure. Multiple reports tie DDoSia to sustained campaigns across Europe and beyond, including attacks against Dutch institutions, Danish financial entities, Czech election-related targets, Italian infrastructure, Spanish public services, UK organizations, Japanese infrastructure, Greenland entities, and Ukrainian government and defense-related targets.
Several sources cited in the content assess that NoName057(16) operates DDoSia as part of a Kremlin-linked or state-sanctioned project. A joint advisory cited in the content states that the Center for the Study and Network Monitoring of the Youth Environment (CISM), established on behalf of the Kremlin, created NoName057(16) as a covert project, and that senior executives and employees within CISM developed and customized DDoSia, paid for infrastructure, administered Telegram channels, and selected DDoS targets. U.S. Department of Justice allegations referenced in the content similarly state that NoName used DDoSia and global infrastructure created by CISM employees to attack victims worldwide. High-confidence observables directly mentioned in the content include the GitHub Pages site dddosia.github[.]io, GitHub profiles dddosia and kintechi341, the C2 hostname zig35m48zur14nel40[.]myftp.org resolving to 31.13.195.87, and Windows sample SHA-256 hashes 726c2c2b35cb1adbe59039193030f23e552a28226ecf0b175ec5eba9dbcd336e and 1b53443ebaabafd6f511d4cf7cb85ddf9fa32540c5dd5621f04a3c5eefa663a9.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NoName057(16) was assessed as a Kremlin-linked covert project using Telegram and the DDoSia toolchain.
“Noname057(16) developed a project—malicious software called Ddosia”
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than operating a traditional botnet, the group leverages a volunteer-based system, mobilizing supporters - referred to as “heroes” - via Telegram. These individuals install the DDoSia client on their personal devices to participate in coordinated DDoS attacks. | To gain greater support for their activities and effectively mobilize their community, NoName strategically leverages DDoSia... These individuals install the DDoSia client on their personal devices to participate in coordinated DDoS attacks.
The C2 server uses HTTP for communication, distributing JSON configurations that include encrypted attack parameters. During the login phase, DDOSIA executes the following POST request: POST /client/login HTTP/1.1
http | L7 | Classical HTTP GET/POST request generation, but with advanced customization and request randomization support... http2 | L7 | Similar to the HTTP module but utilizes the modern HTTP/2 protocol for enhanced capabilities.
While NoName057(16) is known for its persistent and disruptive DDoS attacks targeting Western entities... In the run-up to the NATO summit, various Dutch public entities were being confronted with the disruption of NoName’s DDoS attacks. This involves directing large volumes of traffic at a website or online service, causing it to slow down or crash.
The DDOSIA samples and configuration files we analyzed indicate that the malware supports the request types http, http2, and tcp, and the request methods – HTTP verbs – GET and POST (for the request types http or http2) and syn (for the request type tcp). | DDOSIA is a multi-threaded application that conducts denial-of-service attacks against target sites by repeatedly issuing network requests.
DDoS attacks at this layer are often designed to overwhelm application logic rather than saturate network bandwidth, as they can more easily bypass traditional firewalls because the requests look like normal user behavior.
tcp | L4 | Classic TCP-SYN flooding. Bots forge TCP segments with the SYN flag set and spoof source addresses with randomized source ports to overwhelm the target.
"Most common methods this week: GET: 2,375 ... POST: 1,172" / "Top port: 443 (HTTPS)"
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DDoS toolchain used to coordinate and conduct distributed denial-of-service attacks against NATO and European targets.
A DDoS platform associated with NoName057(16) that was identified as a key tool used in the attack campaigns targeting Italian infrastructure during the Milano Cortina 2026 Winter Games period.
A homegrown DDoS platform used to conduct attacks against Italian domains, using HTTP/HTTPS/HTTP2 floods, TCP floods on ports 80, 443, 2222, 8080, and slowloris-style resource exhaustion attacks.
Malware/botnet family referenced as part of the malicious ecosystem hosted by the provider.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.