DDoSia is a custom distributed denial-of-service platform associated with the pro-Russian hacktivist group NoName057(16) and active since 2022. It was developed to enable large-scale, coordinated denial-of-service operations through a volunteer participation model rather than relying solely on a traditional botnet of compromised hosts. Supporters are recruited primarily through Telegram, where operators distribute instructions, target updates, public claims of responsibility, and gamified incentives including leaderboards and cryptocurrency-based rewards for top contributors.
The platform is designed to lower the barrier to participation for minimally skilled users. Volunteers authenticate through a Telegram-based registration workflow, receive a client identifier, and run the DDoSia client on their own systems. The client contacts command-and-control infrastructure to retrieve target lists and attack parameters, historically over HTTP and in later iterations with encrypted communications. Reported implementations have included Python and Go variants, with Go-based builds improving portability and performance across multiple operating systems.
DDoSia supports multi-vector denial-of-service activity at both the application and transport layers. Documented modes include HTTP and HTTP/2 request flooding, slow-connection attacks resembling Slowloris behavior, and TCP flooding including SYN-based attacks. Campaign reporting consistently shows heavy targeting of web services, especially HTTPS endpoints, though other internet-facing services have also been targeted. The malware reports operational statistics back to its infrastructure, allowing operators to measure participant effectiveness and administer reward schemes.
The platform has been used extensively in politically motivated campaigns against Ukraine, NATO member states, and other countries or organizations perceived as supporting Ukraine. Observed targets have included government agencies, public administrations, financial institutions, transportation and logistics organizations, media, defense-related entities, ports, railways, and other critical infrastructure. Activity often aligns with geopolitical events, elections, diplomatic visits, military aid announcements, and major international gatherings, reflecting its role as both a disruptive and propaganda-amplifying tool.
Multiple public assessments and legal actions have linked DDoSia and the broader NoName057(16) project to Russian state-aligned interests. U.S. and partner government reporting has described NoName057(16) as a covert project tied to CISM, with allegations that personnel developed and customized DDoSia, funded infrastructure, administered communications channels, and selected targets. DDoSia is also widely described as the successor to the earlier Bobik-enabled DDoS ecosystem used by the same collective.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CERT-UA notably highlighted that Global Internet Solutions LLC happens to be one of the three hosting solutions that UAC-0010 (Gamaredon) used the most to host its infrastructure ... NoName057(16) (DDoSia project).
“Noname057(16) developed a project—malicious software called Ddosia”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than operating a traditional botnet, the group leverages a volunteer-based system, mobilizing supporters - referred to as “heroes” - via Telegram. These individuals install the DDoSia client on their personal devices to participate in coordinated DDoS attacks. | To gain greater support for their activities and effectively mobilize their community, NoName strategically leverages DDoSia... These individuals install the DDoSia client on their personal devices to participate in coordinated DDoS attacks.
The DDoS tool (DDOSIA) receives targeting information from the /client/get_targets URL path on either of these domains (over HTTP on TCP/80).
http | L7 | Classical HTTP GET/POST request generation, but with advanced customization and request randomization support... http2 | L7 | Similar to the HTTP module but utilizes the modern HTTP/2 protocol for enhanced capabilities.
investigation into Stark Industries reveals it is being used as a global proxy network that conceals the true source of cyberattacks and disinformation campaigns against enemies of Russia
NoName057(16) is a pro-Russian hacktivist operator / group, which has claimed responsibility for repeated Distributed Denial of Service (DDoS) attacks against entities in perceived anti-Russian countries since March 2022.
NoName recruited volunteers from around the world to download DDoSia and used their computers to launch DDoS attacks on the victims that NoName leaders selected.
DDoS attacks at this layer are often designed to overwhelm application logic rather than saturate network bandwidth, as they can more easily bypass traditional firewalls because the requests look like normal user behavior.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DDoS toolchain used to coordinate and conduct distributed denial-of-service attacks against NATO and European targets.
A DDoS platform associated with NoName057(16) that was identified as a key tool used in the attack campaigns targeting Italian infrastructure during the Milano Cortina 2026 Winter Games period.
A homegrown DDoS platform used to conduct attacks against Italian domains, using HTTP/HTTPS/HTTP2 floods, TCP floods on ports 80, 443, 2222, 8080, and slowloris-style resource exhaustion attacks.
Malware/botnet family referenced as part of the malicious ecosystem hosted by the provider.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.