Europol Disrupts NoName057(16) Hacking Group, Seizes 100+ Servers Worldwide

A coordinated international operation codenamed “Eastwood” successfully disrupted the NoName057(16) cybercrime network between July 14-17, 2025, targeting a pro-Russian group responsible for extensive distributed denial-of-service (DDoS) attacks against Ukraine and its supporting nations.

The operation, coordinated by Europol and Eurojust, involved law enforcement agencies from 12 countries and resulted in significant infrastructure takedowns and arrest warrants.

International Coalition Dismantles Attack Infrastructure

The joint operation involved simultaneous actions across multiple jurisdictions, with core participation from Czechia, France, Finland, Germany, Italy, Lithuania, Poland, Spain, Sweden, Switzerland, the Netherlands, and the United States.

Technical support was provided by ENISA, alongside assistance from Belgium, Canada, Estonia, Denmark, Latvia, Romania, and Ukraine.

Private sector partners ShadowServer and abuse.ch contributed crucial technical expertise to the operation.

Law enforcement successfully disrupted over 100 computer systems worldwide that comprised the attack infrastructure, while taking offline a major portion of the group’s central server infrastructure.

The operation yielded substantial results: 2 arrests (1 preliminary arrest in France and 1 in Spain), 7 arrest warrants issued (6 by Germany, 1 by Spain), and 24 house searches conducted across participating countries.

Germany specifically issued six warrants targeting Russian Federation residents, with two individuals identified as the main instigators of NoName057(16) activities.

Gamified Recruitment Tactics Target Young Supporters

Investigations revealed NoName057(16) employed sophisticated psychological manipulation techniques to recruit and motivate participants.

The network utilized gamification elements, including leader boards, badges, and regular recognition, to provide volunteers with status recognition.

These tactics specifically targeted younger offenders through emotionally reinforced narratives of defending Russia or avenging political events.

The group leveraged platforms like DDoSia to simplify technical processes and provide operational guidelines, enabling rapid recruitment deployment.

Participants received cryptocurrency payments as incentives, attracting both ideological supporters and opportunistic actors.

The network comprised an estimated 4,000 supporters who utilized automated tools for DDoS attacks, operating without a formal leadership structure but motivated by ideology and financial rewards.

Coordinated Response Yields Arrests and Disruptions

National authorities documented numerous cyberattacks linked to NoName057(16), including 14 separate attack waves in Germany targeting over 250 companies and institutions since November 2023.

The network attacked Swedish authorities and banking websites in 2023-2024 and conducted operations during high-profile events, including the Ukrainian Peace Summit at BĂĽrgenstock and the recent NATO summit in the Netherlands.

Europol facilitated extensive coordination through over 30 meetings and two operational sprints, while providing analytical support, cryptocurrency tracing, and forensic expertise.

The Joint Cybercrime Action Taskforce (J-CAT) delivered specialized support throughout the investigation.

Additionally, authorities contacted several hundred suspected network supporters via messaging applications, informing them of their criminal liability under national legislation.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories