| NoName057(16) | |
|---|---|
| 🐻 Volunteer collective emblem (illustrative) | |
| Also known as | NoName057 · NoName · DDoSia |
| Formation | March 2022 |
| Type | Crowdsourced hacktivist collective |
| Purpose | DDoS, Political influence |
| Target Sectors | Government, Finance, Transportation, Logistics |
| Alleged parent org. | Pro-Russian (Self-organized) |
| Attribution confidence | High |
| Status | ● Highly Active |
| Core Project | DDoSia (Volunteer Botnet) |
NoName057(16) is a pro-Russian hacktivist collective that launched in March 2022. The group primarily targets government and financial websites in NATO-aligned nations. Furthermore, they are widely recognized for their “DDoSia” project, which crowdsources cyberattacks through a volunteer-driven botnet.[1]
Unlike traditional hacker groups, NoName057(16) incentivizes its followers. Consequently, volunteers receive rewards for participating in coordinated attacks. This model has allowed the group to sustain a high volume of operations against critical European infrastructure.[2]
DDoSia (Attack platform) · NoName057(16) Support (Community arm)
Overview
NoName057(16) emerged shortly after the escalation of the conflict in Ukraine. The group serves as a highly active component of Russia’s broader information warfare strategy. They use public Telegram channels to communicate their ideology and claim responsibility for outages. Additionally, the group often mocks its targets through inflammatory messaging.[1]
The DDoSia Project
The DDoSia project is the group’s most significant development. In short, it is a toolkit that volunteers install on their personal computers. These volunteers then join a botnet that targets specific IP addresses provided by the group. To encourage participation, NoName057(16) offers a ranking system and cryptocurrency rewards for top contributors.[3]
Targets and Victimology
The group maintains a strict focus on countries that provide support to Ukraine. Their target list frequently includes:
- Government Portals — Websites of national parliaments and regional administrations.
- Financial Institutions — Major banks and stock exchanges in Poland, the Baltics, and the Czech Republic.
- Transport Systems — Port authorities, railway networks, and airline booking services.
- Critical Utilities — Power and water management portals.
Tactics and Procedures
The collective focuses on simplicity and volume. While their attacks rarely cause permanent damage, they successfully create public frustration.
| Tactic | Technique | Description |
|---|---|---|
| Initial Access | T1584.005 | Botnet: Crowdsourced participants using the DDoSia client. |
| C2 | Telegram API | Directing attack orders through encrypted messaging channels. |
| Impact | T1498.001 | HTTP Flooding: Overwhelming web applications with fake requests. |
Notable Attacks
| Date | Campaign | Description |
|---|---|---|
| Jan 2023 | Czech Election | Attacks on government and candidate websites during the presidential election. |
| June 2023 | Swiss Government | Widespread disruption of Swiss federal websites during high-level meetings. |
| 2024 | Baltic Ports | Sustained targeting of maritime logistics in Estonia and Latvia. |
References
- Radware Research, “NoName057(16) and the DDoSia Project” (2023).
- SentinelOne, “The Gamification of DDoS: A Deep Dive into NoName057(16)” (2023).
- Sekoia.io, “Tracking DDoSia: The Pro-Russian Volunteer Botnet” (2023).
- AVAST Threat Labs, “DDoSia Attack Infrastructure Analysis” (2024).
