DDoSia is a custom distributed denial-of-service platform associated with the pro-Russian hacktivist group NoName057(16) and active since 2022. It was developed as the successor to the earlier Bobik-based attack capability and is designed to let low-skill supporters participate in coordinated denial-of-service operations against targets selected by the group. Rather than relying solely on a traditional botnet, DDoSia operates as a volunteer-driven attack ecosystem in which participants obtain the client through channels such as Telegram and, in some periods, GitHub-hosted distribution, authenticate through a Telegram bot, receive centrally managed target lists, and contribute bandwidth and compute resources from their own systems. Public reporting and legal allegations also describe cryptocurrency-based incentives and leaderboards used to reward top contributors and sustain participation.
The malware has been observed in Python and Go implementations, with later Go-based builds compiled for Windows, Linux, and macOS, including x64 and ARM variants. It communicates with command-and-control infrastructure to retrieve target configurations and attack parameters, and later versions have used encrypted communications. DDoSia supports multiple application-layer and transport-layer flooding modes, including HTTP-based floods, slow-connection attacks, and TCP flooding, enabling sustained pressure against web services and other exposed network services. Analysis of the client shows it downloads encrypted target data, decrypts it locally, and then launches attack threads based on centrally supplied instructions.
DDoSia has been used extensively in politically motivated campaigns aligned with Russian geopolitical objectives, especially against Ukraine, NATO member states, and other countries perceived as supporting Ukraine. Reported targets have included government agencies, public-sector services, transportation and logistics organizations, financial institutions, telecommunications providers, defense-related entities, and other critical infrastructure. Campaigns using DDoSia have repeatedly coincided with diplomatic events, elections, military aid announcements, and major international gatherings, reflecting its role as a disruption and propaganda tool within a broader hacktivist mobilization model.
Although DDoSia is not generally characterized as a highly sophisticated intrusion platform, it has enabled persistent, large-scale, and rapidly retargeted DDoS activity through centralized coordination and mass participation. Multiple assessments and indictments have linked the broader DDoSia project to NoName057(16), with some alleging support or administration by Russian state-linked structures, though such state ties are partly based on assessments and legal allegations rather than universally established public proof.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NoName057(16) was assessed as a Kremlin-linked covert project using Telegram and the DDoSia toolchain.
“Noname057(16) developed a project—malicious software called Ddosia”
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than operating a traditional botnet, the group leverages a volunteer-based system, mobilizing supporters - referred to as “heroes” - via Telegram. These individuals install the DDoSia client on their personal devices to participate in coordinated DDoS attacks. | To gain greater support for their activities and effectively mobilize their community, NoName strategically leverages DDoSia... These individuals install the DDoSia client on their personal devices to participate in coordinated DDoS attacks.
The C2 server uses HTTP for communication, distributing JSON configurations that include encrypted attack parameters. During the login phase, DDOSIA executes the following POST request: POST /client/login HTTP/1.1
http | L7 | Classical HTTP GET/POST request generation, but with advanced customization and request randomization support... http2 | L7 | Similar to the HTTP module but utilizes the modern HTTP/2 protocol for enhanced capabilities.
NoName057(16) is performing DDoS attacks on websites belonging to governments, news agencies, armies, suppliers, telecommunications companies, transportation authorities, financial institutions, and more in Ukraine and neighboring countries supporting Ukraine
The DDOSIA samples and configuration files we analyzed indicate that the malware supports the request types http, http2, and tcp, and the request methods – HTTP verbs – GET and POST (for the request types http or http2) and syn (for the request type tcp). | DDOSIA is a multi-threaded application that conducts denial-of-service attacks against target sites by repeatedly issuing network requests.
DDoS attacks at this layer are often designed to overwhelm application logic rather than saturate network bandwidth, as they can more easily bypass traditional firewalls because the requests look like normal user behavior.
tcp | L4 | Classic TCP-SYN flooding. Bots forge TCP segments with the SYN flag set and spoof source addresses with randomized source ports to overwhelm the target.
"Most common methods this week: GET: 2,375 ... POST: 1,172" / "Top port: 443 (HTTPS)"
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DDoS toolchain used to coordinate and conduct distributed denial-of-service attacks against NATO and European targets.
A DDoS platform associated with NoName057(16) that was identified as a key tool used in the attack campaigns targeting Italian infrastructure during the Milano Cortina 2026 Winter Games period.
A homegrown DDoS platform used to conduct attacks against Italian domains, using HTTP/HTTPS/HTTP2 floods, TCP floods on ports 80, 443, 2222, 8080, and slowloris-style resource exhaustion attacks.
Malware/botnet family referenced as part of the malicious ecosystem hosted by the provider.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.