Reporting described multiple, unrelated threat activities rather than a single cohesive incident. SOCRadar assessed a sustained DDoS campaign by NoName057(16) using the DDoSia toolset during March 2–8, 2026, logging 7,512 attack entries against 169 domains and 153 IPs, with Germany as the primary target (65.6% of entries) and Israel as a major secondary target (19.7%). The most notable pattern was heavy, systematic disruption of Germany’s public procurement ecosystem, including at least 17 procurement portals (974 entries), alongside Israeli targeting across defense industry, finance, telecom, and municipal services.
Separately, Flare reported an active phishing campaign using fraudulent domains impersonating Canadian institutions (including the Government of British Columbia and Hydro-Québec) to harvest personal and payment data; the infrastructure was linked to RouterHosting LLC / Cloudzy, a provider previously accused (in 2023) of supporting services used by multiple state-sponsored groups, including Iran-aligned actors. Two other items were not incident-specific: Hackmageddon published aggregated February 2026 attack statistics, and DataBreaches.Net summarized research on offender age distribution in cybercrime; both are higher-level analysis and do not materially add to the DDoS or phishing reporting.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Flare's analysis connected multiple phishing domains through shared hosting IPs and SSL certificate data, repeatedly tying the infrastructure to RouterHosting LLC, rebranded as Cloudzy. A broader scan found more than 28,000 RouterHosting-hosted domains, including 134 .ca domains, many with suspicious Canada-themed naming patterns.
By March 2026, researchers observed an active phishing campaign using fraudulent domains impersonating institutions including the Government of British Columbia and Hydro-Québec to steal personal and payment-card information from Canadian residents. The phishing flow accepted obviously invalid personal data before requesting card details, indicating weak or absent validation.
On March 3, 2026, the campaign reached its peak volume, with Germany's public procurement ecosystem emerging as a major focus. At least 17 procurement portals were attacked for 974 entries, an unprecedented concentration by this actor against a single government function.
During March 2–8, 2026, the pro-Russian hacktivist group NoName057(16) conducted a sustained DDoS campaign using DDoSia, generating 7,512 recorded attack entries. Germany was the main target and Israel a major secondary target, with the activity described as geopolitically motivated.
In 2023, public reporting by Halcyon and Reuters alleged that Cloudzy/RouterHosting had provided services to numerous state-sponsored hacking groups. The March 2026 phishing infrastructure assessment cites these earlier allegations as relevant context for the current campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.