What’s happening right now?
According to Bitsight Threat Intelligence, NoName057(16) remains one of the most visible pro-Russian hacktivist groups conducting distributed denial-of-service (DDoS) attacks against countries and organizations perceived as supporting Ukraine. This matters because the risk can extend beyond direct business ties to Ukraine, and the group may also target organizations that do business with vendors, suppliers, partners, or service providers perceived as supporting Ukraine. In other words, even if an organization has no direct connection to Ukraine, its third-party ecosystem may still create exposure.
While coordinated law enforcement activity, including Operation Eastwood in July 2025, disrupted parts of the group’s infrastructure and support network, the threat has not disappeared.
The group continues to leverage a crowdsourced model that is easy to join, scalable, and difficult to fully eliminate. By recruiting supporters through public channels and incentivizing participation, NoName057(16) can rapidly mobilize DDoS campaigns against public-facing services, especially during periods of heightened geopolitical tension or on symbolic dates.
Who is NoName057(16)?
NoName057(16)—also tracked as NoName057, 05716nm, 05716nnm, Nnm05716, NoName, and NoName05716—is a pro-Russian hacktivist group that emerged in March 2022.
The group is primarily known for conducting DDoS attacks using the DDoSia platform to disrupt access to websites and online services. Its operations are politically motivated and focused on defending Russian interests by targeting Western governments, public institutions, critical infrastructure, and organizations perceived as supporting Ukraine.
Previous targets have included Germany and Israel in a joint effort with Muddy Water and CyberAv3ngers, two pro-Iranian groups. During this attack, an estimated 6,000 attack entries were observed across 143 domains. They heavily targeted the telecommunications sector as well. In February 2026, the group targeted Italy and the Milano Cortina Winter Olympics with DDoS attacks. In January through February of 2026, NoName057(16) worked with ServerKillers, another pro-Russia group, to attack government websites in Spain, and other websites associated with the European Union.
NoName057(16) released the following manifesto on its Telegram channel:
Targeted organizations and locations
Per Bitsight Threat Intelligence reporting, NoName057(16) has been observed targeting: government agencies, national cybersecurity centers, transportation authorities, banks, telecommunications providers, military and defense entities, energy and utility providers, media outlets, election-related websites, and organizations such as NATO.
The group’s geographical targeting has included Ukraine, the Czech Republic, Poland, Lithuania, Latvia, Estonia, Germany, Denmark, Italy, France, Spain, the Netherlands, Sweden, Cyprus, Greenland, Israel, India, Japan, the United States, and the United Kingdom.
Key sectors include government and politics, aerospace and defense, energy and resources, utilities, tourism and hospitality, business services, transportation, banking, and telecommunications.
Threat landscape
NoName057(16) operates within the broader pro-Russian hacktivist ecosystem. Its activity is centered on disruption rather than data theft or long-term intrusion. The goal is often to create public pressure, generate media attention, and signal retaliation against countries viewed as hostile to Russian interests.
The group uses a crowdsourced DDoS platform known as DDoSia, distributed and coordinated through Telegram. Participants are given target lists and instructions, and in some cases are incentivized with cryptocurrency. Bitsight Threat Intelligence tracks NoName057(16)’s use of malware-infected systems, including Bobik, to help generate attack traffic.
Recent NoName057(16) activity
NoName057(16) has claimed or been associated with several notable campaigns, including:
- DDoS attacks against websites connected to the 2024 European Parliamentary Elections.
- Large-scale DDoS activity against Romanian government websites, including the Constitutional Court of Romania and the Ministry of Foreign Affairs.
- A wave of DDoS attacks against UK municipalities, which the group framed as retaliation for the UK’s support of Ukraine.
- Operations such as Operation Eastwood, OpCyprus, and OpDenmark, reflecting the group’s continued focus on countries aligned against Russia.
Tactics, techniques, and procedures
NoName057(16)’s primary tactic is service disruption through DDoS attacks in which the group floods their target with HTTP requests to overwhelm the system. The group uses botnets, volunteer participants, and crowdsourced tools to overwhelm web servers with traffic.
Its typical process includes announcing targets on Telegram or social media, distributing operational instructions through DDoSia, encouraging supporters to participate, and then claiming responsibility publicly for successful disruptions.
Associated tools and malware include DDoSia, Dosia, mySingleMessenger, Bobik, and other DDoS-enabling infrastructure.