NoName057(16) — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    NoName057(16)

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    NoName057(16)
    🐻
    Volunteer collective emblem (illustrative)
    Also known asNoName057 · NoName · DDoSia
    FormationMarch 2022
    TypeCrowdsourced hacktivist collective
    PurposeDDoS, Political influence
    Target SectorsGovernment, Finance, Transportation, Logistics
    Alleged parent org.Pro-Russian (Self-organized)
    Attribution confidenceHigh
    Status● Highly Active
    Core ProjectDDoSia (Volunteer Botnet)

    NoName057(16) is a pro-Russian hacktivist collective that launched in March 2022. The group primarily targets government and financial websites in NATO-aligned nations. Furthermore, they are widely recognized for their “DDoSia” project, which crowdsources cyberattacks through a volunteer-driven botnet.[1]

    Unlike traditional hacker groups, NoName057(16) incentivizes its followers. Consequently, volunteers receive rewards for participating in coordinated attacks. This model has allowed the group to sustain a high volume of operations against critical European infrastructure.[2]

    Key Projects and Aliases:
    DDoSia (Attack platform) · NoName057(16) Support (Community arm)

    Overview

    NoName057(16) emerged shortly after the escalation of the conflict in Ukraine. The group serves as a highly active component of Russia’s broader information warfare strategy. They use public Telegram channels to communicate their ideology and claim responsibility for outages. Additionally, the group often mocks its targets through inflammatory messaging.[1]

    The DDoSia Project

    The DDoSia project is the group’s most significant development. In short, it is a toolkit that volunteers install on their personal computers. These volunteers then join a botnet that targets specific IP addresses provided by the group. To encourage participation, NoName057(16) offers a ranking system and cryptocurrency rewards for top contributors.[3]

    “NoName057(16) has successfully gamified the process of cyber warfare. By rewarding volunteers, they have built a resilient and constantly evolving threat to European digital services.”
    — European Cyber Defense Briefing, 2024[4]

    Targets and Victimology

    The group maintains a strict focus on countries that provide support to Ukraine. Their target list frequently includes:

    • Government Portals — Websites of national parliaments and regional administrations.
    • Financial Institutions — Major banks and stock exchanges in Poland, the Baltics, and the Czech Republic.
    • Transport Systems — Port authorities, railway networks, and airline booking services.
    • Critical Utilities — Power and water management portals.

    Tactics and Procedures

    The collective focuses on simplicity and volume. While their attacks rarely cause permanent damage, they successfully create public frustration.

    TacticTechniqueDescription
    Initial AccessT1584.005Botnet: Crowdsourced participants using the DDoSia client.
    C2Telegram APIDirecting attack orders through encrypted messaging channels.
    ImpactT1498.001HTTP Flooding: Overwhelming web applications with fake requests.

    Notable Attacks

    DateCampaignDescription
    Jan 2023Czech ElectionAttacks on government and candidate websites during the presidential election.
    June 2023Swiss GovernmentWidespread disruption of Swiss federal websites during high-level meetings.
    2024Baltic PortsSustained targeting of maritime logistics in Estonia and Latvia.

    References

    1. Radware Research, “NoName057(16) and the DDoSia Project” (2023).
    2. SentinelOne, “The Gamification of DDoS: A Deep Dive into NoName057(16)” (2023).
    3. Sekoia.io, “Tracking DDoSia: The Pro-Russian Volunteer Botnet” (2023).
    4. AVAST Threat Labs, “DDoSia Attack Infrastructure Analysis” (2024).
    Categories: Hacktivism · Pro-Russian Hacking · DDoS · DDoSia · Cyberwarfare
    This page was last updated August 2026. Data is based on active threat monitoring.