Home/Threat Actor/NoName057(16)
Threat Actor

NoName057(16)

noname057_16 · russia_aligned_hacktivism · active since 2022

NoName057(16) (DDoSIA / Storm-1314 / Russian Crowdsourced DDoS Hacktivism Project) is one of the most prolific Russia-aligned hacktivism clusters in the contemporary publicly-tracked record , a politically-motivated cluster that emerged in March 2022 following Russia's February 24, 2022 invasion of Ukraine and has conducted sustained DDoS operations against NATO-country government infrastructure since (thousands of DDoS attacks against European-government targets across 2022-2025)

defining cluster operational signature the DDoSIA crowdsourced volunteer- recruitment platform (volunteer operators "DDoSIA Project Volunteers" install DDoSIA software clients on their own computers and contribute bandwidth to coordinated DDoS attacks in exchange for cryptocurrency payments graduated by attack contribution volume, operationally innovative among Russia-aligned hacktivism operations)

Western analytical consensus treats NoName057(16) as freelance hacktivism with apparent Russian state tolerance rather than direct state-tasking, consistent with broader analytical framing for Killnet.

operationally more focused than Killnet, sustained DDoS targeting of Lithuanian + Polish + German + Italian + French + Spanish + Czech government infrastructure with selective operations during Western political events (EU parliament sessions, NATO summits, Ukraine-Russia war policy decisions including Western military aid packages and sanctions announcements, Ukrainian leader visits to Western capitals)

most operationally significant counter-cluster action the July 16, 2024 Operation Endgame Europol-led coordinated international operation with participation by German BKA + Spanish National Police + Polish Police + Lithuanian Cyber Police + Latvian State Police + Estonian Police + Italian Police + Czech NUKIB + Finnish Police + Swiss Federal Office of Police + FBI, documented results: 2 arrests (Switzerland + Italy), identification of ~30 additional alleged DDoSIA Project Volunteers across 15 countries, seizure of DDoSIA servers, disruption of volunteer-recruitment and cryptocurrency-payment infrastructure.

despite disruption, operations continued through late 2024 and into 2025 with reorganized DDoSIA infrastructure reflecting broader challenge of disrupting hacktivism operations operating predominantly through crowdsourced volunteer infrastructure (operational difficulty of attributing distributed volunteer-operators across multiple jurisdictions creates substantial counter-operation complexity).

russia_aligned_hacktivism confidence: high 18 aliases
Sigma rules93 YARA rules0 Live IOCs0 CVEs exploited0

Profile

NoName057(16) (also tracked as DDoSIA, Storm-1314, and the broader Russian Crowdsourced DDoS Hacktivism Project) is one of the most prolific Russia-aligned hacktivism clusters in the contemporary publicly-tracked record, a politically-motivated cluster that emerged in March 2022 following Russia's February 24, 2022 invasion of Ukraine and has conducted sustained DDoS operations against NATO-country government infrastructure since. The cluster's defining operational signature is the DDoSIA crowdsourced volunteer-recruitment platform. Volunteer operators ("DDoSIA Project Volunteers") install DDoSIA software clients on their own computers and contribute their bandwidth to coordinated DDoS attacks against cluster-selected targets in exchange for cryptocurrency payments graduated by attack contribution volume.

The DDoSIA model is operationally innovative among Russia-aligned hacktivism operations and distinguishes NoName057(16) from peer Russia-aligned hacktivism operations including Killnet (already covered as killnet.yaml). Western analytical consensus treats NoName057(16) as freelance hacktivism with apparent Russian state tolerance rather than direct state-tasking, consistent with the broader analytical framing applied to Killnet.

The cluster operates with operationally more focused targeting than Killnet
  • Sustained DDoS operations against NATO-country government infrastructure (particularly active against Lithuanian, Polish, German, Italian, French, Spanish, and Czech government targets)
  • Selective operations during Western political events (EU parliament sessions, NATO summits, Ukraine-Russia war policy decisions including Western military aid packages, sanctions announcements, Ukrainian leader visits to Western capitals)
  • Less brand-marketing and information-operations activity than Killnet, NoName057(16) operations are more operationally-focused and less narrative-focused The cluster has conducted thousands of DDoS attacks against European-government targets over the 2022-2025 operational lifespan, substantially higher operational tempo than peer Russia-aligned hacktivism operations. Operations are typically coordinated through Telegram-channel target-announcements with same-day or next-day DDoS execution by DDoSIA Project Volunteers. The cluster has received the most operationally significant European-government formal public attribution among Russia- aligned hacktivism operations through the July 16, 2024 Operation Endgame Europol-led coordinated international action. The operation involved Europol coordination with German BKA, Spanish National Police, Polish Police, Lithuanian Cyber Police, Latvian State Police, Estonian Police, Italian Police, Czech NUKIB, Finnish Police, Swiss Federal Office of Police, and FBI.
Documented results
  • Two arrests (one Switzerland, one Italy)
  • Identification of approximately 30 additional alleged DDoSIA Project Volunteers across 15 countries.
  • Searches conducted in multiple European countries.
  • Seizure of NoName057(16) operational infrastructure including DDoSIA servers.
  • Disruption of DDoSIA volunteer-recruitment and cryptocurrency- payment infrastructure Operation Endgame represented one of the most operationally consequential counter-Russia-aligned-hacktivism coordinated international actions in the publicly-tracked record. Despite the disruption, NoName057(16) operations have continued through late 2024 and into 2025 with reorganized DDoSIA infrastructure under the same cluster brand identity. The cluster's resilience reflects the broader challenge of disrupting hacktivism operations operating predominantly through crowdsourced volunteer infrastructure, the operational difficulty of attributing distributed volunteer-operators across multiple jurisdictions creates substantial counter-operation complexity. A handful of operational notes: First, the cluster represents the central reference for understanding crowdsourced DDoS hacktivism operational tradecraft. The DDoSIA volunteer-recruitment-and-payment model is operationally innovative and may inform future hacktivism cluster operational models. Defender threat-modeling should account for the crowdsourced volunteer-attacker model as a distinct DDoS threat category, defenders cannot simply attribute and disrupt centralized cluster infrastructure because operational capability is distributed across volunteer- operators. Second, the cluster's operationally-focused targeting tradecraft (particularly the selective operations during Western political events) represents a meaningful operational-doctrine signal. Either explicit Russian-state coordination signal-following or shared political-motivation-driven operational targeting, the pattern of operations timed to specific Western political- decision-cycles is consistent across the operational lifespan. Third, the cluster should be analytically distinguished from Killnet despite similar Russia-aligned hacktivism positioning. Modern vendor consensus tracks NoName057(16) as separate cluster identity with distinct operational structure (DDoSIA volunteer recruitment model vs Killnet multi-subgroup collective structure) and operational focus (concentrated DDoS targeting of European- government infrastructure vs Killnet's broader DDoS-and-doxxing- and-narrative-operations portfolio). Fourth, no formal individual-operator attribution at the named- Russian-national tier has been publicly issued for NoName057(16) core administrators despite the Operation Endgame disruption. The Operation Endgame arrests targeted DDoSIA Project Volunteers rather than NoName057(16) administrators, consistent with the operational pattern where cluster administrators remain in Russia while volunteer-operators are distributed across multiple jurisdictions including some accessible to Western law-enforcement.

Aliases

18
noname057noname 057noname_057noname057_16noname057(16)noname 057 16noname_057_16noname05716ddosiaddo siaddo_siaddosia platformddosia_platformstorm-1314storm 1314storm_1314russian crowdsourced ddos hacktivismrussian_crowdsourced_ddos_hacktivism

Notable Campaigns

8
2024-2025Continued Post-Operation-Endgame Operations (July 2024 onward)
2024Operation Endgame Europol-Led DDoSIA Disruption (July 16, 2024)
2023-2024Spanish + Italian Critical Infrastructure Attacks (2023-2024)
2023Czech Government Attacks (2023)
2022-2024Lithuanian + Polish + German + Italian + French Government Targeting (2022-2024)
2022-2024European Political Event Selective Targeting (2022-2024)
2022NoName057(16) Emergence (March 2022)
2022DDoSIA Volunteer-Recruitment Platform Launch (2022)

Attribution & Reporting

Attributed by
Europol European Cybercrime Centre (EC3)German Federal Criminal Police Office (BKA)Spanish National Cryptologic Centre (CCN)Polish Government Plenipotentiary for CybersecurityLithuanian National Cyber Security Centre (NKSC)Latvian CERTEstonian Information System Authority (RIA)Italian National Cybersecurity Agency (ACN)Czech NUKIBFinnish Transport and Communications Agency Traficom NCSC-FISwiss Federal Office for Cybersecurity NCSC-CHFBI Cyber DivisionCISA (US Cybersecurity and Infrastructure Security Agency)UK National Cyber Security Centre (NCSC)French National Cybersecurity Agency (ANSSI)Mandiant / Google Cloud Threat IntelligenceMicrosoft Threat Intelligence CenterCrowdStrikeRecorded Future Insikt GroupSentinelOneTrend MicroKaspersky GReATGroup-IBCheck Point ResearchSekoia.ioRadwareCloudflareAkamaiFlashpointSearchlight CyberIntel 471
Key reporting
reportEuropol: Disruption Operation Against Pro-Russian Hacktivist Group NoName057(16) (July 16, 2024), most operationally significant counter-cluster action, Operation Endgame DDoSIA disruption
reportSekoia.io: NoName057(16), The DDoSIA Project Detailed Analysis (multiple analyses), seminal cluster operational disclosure
reportCheck Point Research: NoName057(16) and DDoSIA, The Pro-Russia Cyber Hacktivism (multiple years)
reportMandiant: NoName057(16) Russia Hacktivism Continued Tracking
reportRecorded Future Insikt Group: NoName057(16) Russian Hacktivism Tracking
reportFlashpoint: NoName057(16) DDoSIA Operational Tracking
reportCloudflare: NoName057(16) DDoS Tracking
reportAkamai: NoName057(16) DDoSIA Russian Hacktivism Tracking
reportSearchlight Cyber: NoName057(16) Pro-Russian Hacktivism Tracking
reportCzech NUKIB: Multiple Public Alerts on NoName057(16) Operations Against Czech Targets
reportItalian ACN: NoName057(16) Operations Against Italian Critical Infrastructure
reportSpanish CCN: NoName057(16) Operations Against Spanish Critical Infrastructure
reportLithuanian NKSC: NoName057(16) Operations Against Lithuanian Government
reportRadware: NoName057(16) DDoS Tracking
reportIntel 471: NoName057(16) Hacktivism Tracking
reportGroup-IB: NoName057(16) Continued Tracking
reportMalpedia Actor Profile: NoName057(16)

Operational

State sponsor

NoName057(16) is a Russia-aligned pro-Kremlin hacktivism cluster , not a state-aligned APT cluster and not a formally state-tasked cluster, but a self-identified patriotic Russian hacktivism operation that emerged in March 2022 following Russia's February 24, 2022 invasion of Ukraine. The cluster operates the DDoSIA platform, a crowdsourced distributed-denial-of-service operational platform with substantial volunteer-operator recruitment model that distinguishes NoName057(16) from peer Russia-aligned hacktivism operations. Volunteer operators ("DDoSIA Project Volunteers") install DDoSIA software clients on their own computers and contribute their bandwidth to coordinated DDoS attacks against cluster-selected targets in exchange for cryptocurrency payments graduated by attack contribution volume.

The DDoSIA crowdsourced model represents operationally innovative volunteer-recruitment-and-payment tradecraft and is operationally distinctive among Russia-aligned hacktivism operations. Western analytical consensus treats NoName057(16) as freelance hacktivism with apparent Russian state tolerance rather than direct state-tasking, consistent with the broader analytical framing applied to Killnet (already covered as killnet.yaml). The cluster operates with operationally more focused targeting than Killnet, sustained DDoS operations against NATO-country government infrastructure (particularly active against Lithuanian, Polish, German, Italian, French, and Spanish government targets), selective operations during Western political events (EU parliament sessions, NATO summits, Ukraine- Russia war policy decisions), and less brand-marketing / information-operations activity than Killnet.

The cluster is operationally distinct from Killnet despite similar Russia- aligned hacktivism positioning, modern vendor consensus tracks NoName057(16) as separate cluster identity with distinct operational structure (DDoSIA volunteer recruitment model vs Killnet multi-subgroup collective structure). The cluster has received the most operationally significant European-government formal public attribution among Russia-aligned hacktivism operations through coordinated Operation Endgame July 16, 2024 Europol-led action disrupting DDoSIA infrastructure with two arrests (one in Switzerland, one in Italy) and identification of approximately 30 additional alleged DDoSIA Project Volunteers across 15 countries. No formal individual-operator attribution at the named-Russian-national tier has been publicly issued for NoName057(16) core administrators.

Motivations
hacktivism, russian_patriotic_hacktivism, politically_motivated_disruption, distributed_denial_of_service_operations, crowdsourced_ddos_volunteer_operations, retaliatory_disruption_against_western_sanctions_and_ukraine_support, cryptocurrency_volunteer_compensation_recruitment
Sectors
Regions

Detection Blind Spots

42 techniques
Across this actor’s 42 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)15/42 · 35%
Analytics (MITRE CAR)0/42 · 0%
Runtime / container (Falco)0/42 · 0%
File / malware (YARA)0/42 · 0%
Network (Suricata/Snort)6/42 · 14%
Vuln scan (Nuclei)0/42 · 0%

Atomic Test Plan

3 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin