NoName057(16), also known as NoName057, NoName05716, and NNM05716, is a Russian pro-Russian hacktivist group active since March 2022. Its principal activity is distributed denial-of-service (DDoS) against government institutions and commercial organizations, particularly in countries supporting Ukraine. Targets include ministries, diplomatic services, banks, airports, ports, transport authorities, and healthcare organizations. The group coordinates activity and announces targets and attack claims through Telegram, combining service disruption with political messaging and public amplification. NoName057(16) is linked to the DDoSia Project, also called DDosia, a crowdsourced DDoS operation targeting governments that support Ukraine. It has also used the Bobik botnet for DDoS attacks. Campaigns frequently coincide with diplomatic events, defense assistance announcements, or statements critical of Russia. Italian campaigns have targeted government, banking, aviation, and maritime websites, including attacks timed around Ukrainian President Volodymyr Zelensky’s January 2025 visit to Rome and retaliation for remarks by Italian President Sergio Mattarella. The group has claimed attacks against French websites citing pension reform and against Dutch organizations around the NATO summit. It has also announced DDoS targets in protest against Western support for Israel. Beyond DDoS, NoName057(16) compromised exposed IP cameras belonging to Estonian and Canadian targets in August and September 2026. Its infrastructure was disrupted by international law enforcement during Operation Eastwood in July 2025, although subsequent activity demonstrates continued operations. Associated groups include Server Killers, while documented collaborative relationships include Zarya and AzzaSec; these relationships do not establish that those groups are subordinate units or that NoName057(16) itself conducts ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
95 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pro-Russian hacktivist group conducting politically timed DDoS campaigns against governments supporting Ukraine. The article describes repeated targeting of Italian government websites, banks, ports and airports. Its linked DDoSia operation listed Italian ministries and diplomatic websites as planned targets on October 8, 2026. However, the Foreign Ministry did not attribute the current attack, and the target list does not establish responsibility or successful disruption.
Pro-Russian hacktivist group associated with politically timed DDoS campaigns against governments supporting Ukraine. Reported Italian targets include government ministries, banks, airports and ports. The article identifies planned attacks through the linked DDoSia operation, but the ministry has not attributed the October 8 attack, and no group has claimed it. The ministry reports successful mitigation without disruption.
Pro-Russian hacktivist group observed gaining control of exposed IP cameras at targeted organizations.
Gained control of exposed IP cameras in targeted organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.