Pro-Russian hacktivist group NoName057(16) intensified distributed denial-of-service attacks against government and private-sector targets across Europe, including Dutch public services disrupted around the NATO Summit in The Hague. Reported incidents in the Netherlands included attacks on municipal and provincial websites and an earlier strike on Logius that temporarily affected DigiD and access to services used by the Belastingdienst, UWV, DUO, and hospital portals. The group has also targeted organizations in Ukraine, Israel, and other European countries, often timing attacks to politically significant events and focusing on sectors such as government, transportation, banking, defense, media, and energy.
The group’s operations relied on Telegram for propaganda, recruitment, and coordination, while the DDoSia platform distributed encrypted attack parameters to volunteers who could be rewarded with cryptocurrency. Reporting also linked the ecosystem to malware including Bobik and RedLine Stealer, which were used to support involuntary participation in attacks. An international law-enforcement action, Operation Eastwood, led by Europol and Eurojust, disrupted more than 100 servers tied to the network and resulted in arrests, warrants, and notifications to participants, dealing a significant blow to the group’s infrastructure even as its public claims were described as overstating real-world impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
An international law-enforcement action led by Europol and Eurojust targeted NoName057 and resulted in arrests, warrants, participant notifications, and the disruption of more than 100 servers linked to the group. The operation represented a major coordinated takedown effort against the network.
After initially targeting Ukrainian media, NoName057 broadened its targeting to government, transportation, banking, defense, media, and energy organizations across Europe, Israel, and Ukraine. The group especially timed attacks around politically significant events.
An earlier DDoS attack on Logius temporarily disrupted DigiD and access to services from the Belastingdienst, UWV, DUO, and hospital portals in the Netherlands. The incident is highlighted as part of NoName057(16)'s activity affecting Dutch institutions.
The group intensified politically motivated DDoS operations against Dutch public institutions and private organizations, including municipal and provincial websites, around the NATO Summit 2025 in The Hague. The activity marked a notable extension of its campaign into the Netherlands.
The group emerged in March 2022 and began operating as a pro-Russian hacktivist collective focused primarily on distributed denial-of-service attacks. Its activity was tied to Telegram-based recruitment and the DDOSIA ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
mrtiepolo.medium.com
Open sourcehuntandhackett.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.