An international law enforcement operation disrupted NoName057(16), a pro-Russian hacktivist network accused of launching distributed denial-of-service attacks against Ukraine and countries supporting Kyiv, including EU and NATO members. Europol and Eurojust said Operation Eastwood took more than 100 servers offline, dismantled a significant portion of the group’s infrastructure, and led to arrests, arrest warrants, house searches, and interviews across multiple countries with U.S. support. Investigators said the group relied on automated tooling, botnet infrastructure, and the DDoSia platform, while recruiting participants through social media, messaging channels, cryptocurrency payments, and gamified incentives such as leaderboards and badges.
U.S. authorities later tied the disruption to broader action against Russian state-backed cyber actors, unsealing indictments against Victoria Eduardovna Dubranova for allegedly supporting both NoName057(16) and CyberArmyofRussia_Reborn (CARR). The Justice Department said the groups carried out hundreds of attacks worldwide, including activity targeting U.S. critical infrastructure such as public water systems and election infrastructure, and described NoName as a state-sanctioned project linked to Russian organization CISM. A related CISA advisory warned that pro-Russia hacktivists were conducting attacks against critical infrastructure, reinforcing concerns that ideologically branded DDoS campaigns are being used to advance Russian geopolitical objectives.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
As part of the Operation Eastwood action, authorities notified more than 1,000 supporters, including 15 administrators, via a messaging application of their potential criminal liability.
During Operation Eastwood, authorities made two arrests in France and Spain, issued seven arrest warrants, conducted 24 house searches across six countries, and questioned 13 individuals.
Between 14 and 17 July 2025, Europol and Eurojust coordinated Operation Eastwood against NoName057(16), disrupting more than 100 computer systems worldwide and taking a major part of the group's central server infrastructure offline.
Victoria Eduardovna Dubranova was extradited to the United States earlier in 2025 on an indictment related to her alleged support for CyberArmyofRussia_Reborn.
According to the indictment, CyberArmyofRussia_Reborn attacked a meat processing facility in Los Angeles in November 2024, spoiling thousands of pounds of meat and triggering an ammonia leak.
Authorities linked NoName057(16) to attacks in Switzerland in June 2024 during the Peace Summit for Ukraine at Bürgenstock.
Investigations into NoName057(16) had begun by November 2023, after which Germany recorded 14 separate waves of attacks targeting more than 250 companies and institutions.
Authorities linked NoName057(16) to attacks in Switzerland in June 2023 during a Ukrainian video message to the Joint Parliament.
The Center for the Study and Network Monitoring of the Youth Environment (CISM), later described in the indictment as tied to NoName057(16), was established by order of the President of Russia in October 2018.
Dubranova was arraigned on a second indictment related to her alleged support for NoName057(16) and pleaded not guilty in both federal cases.
The U.S. Department of Justice announced that two indictments against Victoria Eduardovna Dubranova were unsealed in Los Angeles, alleging she supported both CyberArmyofRussia_Reborn and NoName057(16). Prosecutors said the groups conducted hundreds of cyberattacks worldwide in support of Russia’s geopolitical interests.
Dutch authorities confirmed that an attack linked to NoName057(16) occurred during the latest NATO summit in the Netherlands. The attacks were reported as mitigated without substantial interruptions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourceeuropol.europa.eu
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.