NoName057(16) Hackers Launch DDoSia Driven DDoS Campaign Against Organizations Associated With NATO Across Europe

Pro-Russia hacktivist group NoName057(16), also known as 05716nnm or NoName057, has intensified its distributed denial-of-service (DDoS) attacks against organizations across Europe aligned with NATO interests.

The group, active since March 2022, primarily targets government websites, logistics networks, and telecommunication firms in nations supportive of Ukraine.

According to threat analysis, the group originated from a covert initiative within Russia’s Centre for the Study and Network Monitoring of the Youth Environment (CISM). CISM reportedly provided the team with infrastructure, operational guidance, and technical tools.

The group is heavily aligned with pro-Kremlin objectives and coordinates its campaigns through Telegram channels, distributing attack tools and updates to an expanding volunteer base.

Their primary weapon, the DDoSia Project, is a crowdsourced successor to the “Bobik” botnet. The malware is written in Go, designed for ease of use, and enables volunteers with minimal technical knowledge to participate in coordinated DDoS operations.

Participants, known as “volunteers,” are incentivized with cryptocurrency rewards for contributing computing power to attacks.

Inside the DDoSia Attack Chain and Infrastructure

The DDoSia client communicates with a command-and-control (C2) infrastructure using a secure, two-stage process.

During the first stage, the infected client registers with the C2 server via an encrypted HTTP POST request, transmitting system and user data protected by AES-GCM.

Upon authentication, it receives a time-stamped confirmation. In the second stage, clients retrieve target configurations via an encrypted GET request that includes target hosts, IP addresses, and the attack protocol type (e.g., HTTP/2 floods).

DDoSia employs a multi-tier architecture to evade detection. The first tier comprises short-lived proxy servers that communicate directly with infected clients, while the second tier hosts the main infrastructure and the target data repositories.

This layered setup complicates takedown efforts and ensures operational resilience even if surface servers are blocked.

From July 2024 to July 2025, analysts recorded an average of 50 attacks per day, primarily during Russian business hours.

Most operations focus on Ukraine (29.47%), France (6.09%), and Italy (5.39%), with government agencies accounting for more than 41% of total targets.

Attack vectors include HTTP GET floods, SYN floods, and Slow Loris-style connection exhaustion, targeting web services on ports 80 and 443.

The group’s influence grew further through its partnership with the Cyber Army of Russia Reborn (CARR), eventually leading to the 2024 formation of Z-Pentest, an alliance targeting Western critical infrastructure.

Despite international arrests during Operation Eastwood in July 2025, NoName057(16) remains active, continuing to promote cyber operations in support of Russian interests via its Telegram network.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories