NoName057(16)
Pro-Russian hacktivist group (state-aligned, formal relationship unconfirmed) · Political / ideological -- retaliation against NATO and Western governments perceived as hostile to Russia
Tactics, Techniques & Procedures (TTPs)
- High-volume DDoS campaigns against public-facing government and infrastructure websites
- DDoSia volunteer toolkit enabling distributed attack participation
- Use of hosting infrastructure in EU member states to evade sanctions (Stark Industries, WorkTitans)
- Coordinated campaign timing during elections, diplomatic events, and military aid announcements
- Targeting of financial institutions, transport operators, and port infrastructure
Known Targets
Analyst Notes
Active since Russia's invasion of Ukraine, February 2022. Conducts sustained DDoS campaigns against governments and organisations in countries perceived as supporting Ukraine. Primary hosting infrastructure (Stark Industries, WorkTitans B.V.) was seized by Dutch FIOD authorities in May 2026 -- 800+ servers seized, two suspects arrested. Sanctions evasion via shell company transfers (Stark Industries IP ranges moved to WorkTitans after EU sanctions) demonstrated deliberate circumvention of law enforcement pressure. Group has consistently reconstituted after prior disruptions.
Also Known As