NoName is a pro-Russian hacktivist threat actor primarily associated with disruptive cyber operations, especially distributed denial-of-service activity against governments, critical infrastructure, and telecommunications organizations. The group has been notably active against Ukraine, where it has been identified as one of the most active actors in recent attack waves and has targeted government entities, critical sectors, and multiple telecom service providers. NoName has also been linked to activity against Swiss government websites ahead of a virtual address by Ukraine’s president to the Swiss parliament, illustrating politically motivated targeting aligned with Russian interests. The actor has been named alongside other pro-Russian hacktivist groups in government warnings about ongoing targeting of critical infrastructure organizations worldwide. Reported activity includes unauthorized access to a municipal water treatment facility in Quebec in October 2025, indicating that the group’s operations are not limited to website disruption and may extend to intrusion affecting operationally sensitive environments. Across observed campaigns, NoName’s behavior is consistent with hacktivist and influence-driven disruption: targeting public-sector and critical-service organizations, conducting coordinated campaigns with ideologically aligned groups, and focusing on visibility and operational impact rather than covert long-term persistence. Known reporting identifies the actor under the name NoName. High-confidence characterization supports describing it as a pro-Russian hacktivist group rather than a formally attributed state unit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist activity involving unauthorized access to a municipal water treatment facility in Quebec.
NoName is a pro-Russia hacktivist group known for targeting European critical infrastructure with disruptive cyberattacks, including ransomware operations.
NoName is a pro-Russia hacktivist group targeting critical infrastructure organizations worldwide.
Pro-Russia hacktivist group actively targeting critical infrastructure organizations worldwide.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.