DDoSia is a cross-platform distributed denial-of-service tool developed and operated by the pro-Russian hacktivist group NoName057(16). Its broader ecosystem, known as the DDoSia Project, coordinates crowdsourced attacks through centrally managed infrastructure and volunteer participation. Active since 2022, it primarily targets Ukraine and countries supporting Ukraine, including NATO members. Targets include government and diplomatic services, financial institutions, transportation and logistics providers, defense organizations, telecommunications companies, and media outlets. Campaigns frequently coincide with politically significant events.
Early implementations used Python, while subsequent clients are written in Go and support Windows, Linux, and macOS, including multiple processor architectures. Clients authenticate using participant-specific identifiers, retrieve centrally assigned target lists and attack parameters, and generate application-layer and transport-layer attack traffic. Supported techniques include HTTP and HTTPS request floods, HTTP/2 floods, TCP floods including SYN flooding, and slowloris-style resource exhaustion. Later versions retrieve encrypted target data and decrypt it in memory before attack execution. Clients report operational statistics to measure participant contributions.
DDoSia is distributed primarily through Telegram, with GitHub also used historically to host tooling and supporting resources. Participants deliberately install and run the client on their own devices rather than joining solely through malware infection. Telegram bots support registration, while public leaderboards and performance-based cryptocurrency rewards incentivize participation. DDoSia followed NoName057(16)'s earlier use of the separate Bobik botnet. Its principal purpose is disruption of service availability; DDoSia activity does not itself establish intrusion or data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Giving a look to the list of targets shared on DDosia today I can confirm that administrators planned attacks against the Farnesina, five Italian embassy sites, several Interior and Defence Ministry services, and other Italian organizations.
“Noname057(16) developed a project—malicious software called Ddosia”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than operating a traditional botnet, the group leverages a volunteer-based system, mobilizing supporters - referred to as “heroes” - via Telegram. These individuals install the DDoSia client on their personal devices to participate in coordinated DDoS attacks. | To gain greater support for their activities and effectively mobilize their community, NoName strategically leverages DDoSia... These individuals install the DDoSia client on their personal devices to participate in coordinated DDoS attacks.
The DDoS tool (DDOSIA) receives targeting information from the /client/get_targets URL path on either of these domains (over HTTP on TCP/80).
http | L7 | Classical HTTP GET/POST request generation, but with advanced customization and request randomization support... http2 | L7 | Similar to the HTTP module but utilizes the modern HTTP/2 protocol for enhanced capabilities.
investigation into Stark Industries reveals it is being used as a global proxy network that conceals the true source of cyberattacks and disinformation campaigns against enemies of Russia
The content identifies distributed denial-of-service (DDoS) attacks and describes NoName057's "DDoSia Project," in which participants overload websites of government institutions, banks, and infrastructure.
NoName recruited volunteers from around the world to download DDoSia and used their computers to launch DDoS attacks on the victims that NoName leaders selected.
DDoS attacks at this layer are often designed to overwhelm application logic rather than saturate network bandwidth, as they can more easily bypass traditional firewalls because the requests look like normal user behavior.
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crowdsourced distributed denial-of-service tooling and operation linked to NoName057(16), described as targeting governments supporting Ukraine. The author reports that its October 8 target list included Italy’s Foreign Ministry, diplomatic websites, and other Italian organizations. This establishes planned targeting, not confirmed responsibility for the ministry’s reported attack.
Crowdsourced DDoS project associated with NoName057(16), described as attacking governments that support Ukraine. Its October 8 target list included Italy’s Foreign Ministry, diplomatic websites and other Italian organizations. The planned targets do not establish that DDoSia caused the ministry’s reported attack, which remained officially unattributed.
A DDoS toolchain used to coordinate and conduct distributed denial-of-service attacks against NATO and European targets.
A DDoS platform associated with NoName057(16) that was identified as a key tool used in the attack campaigns targeting Italian infrastructure during the Milano Cortina 2026 Winter Games period.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.