The US Department of Justice announced indictments against Ukrainian national Victoria Eduardovna Dubranova for her involvement in cyberattacks supporting Russian state interests, specifically through the groups CyberArmyofRussia_Reborn (CARR) and NoName057(16). The indictments allege that these groups received financial and logistical support from the Russian government, enabling them to conduct disruptive operations, including the use of proprietary distributed denial-of-service (DDoS) tools. Dubranova, extradited to the US, faces trial for her roles in both groups, which are accused of targeting critical infrastructure worldwide.
During the same period, threat intelligence sources reported a significant DDoS campaign attributed to NoName057(16) and their DDoSia project, with a particular focus on German infrastructure. Between December 29, 2025, and January 4, 2026, over 2,600 attacks were recorded, primarily targeting German domains and IP addresses, marking a strategic escalation against one of Ukraine's key European allies. This campaign demonstrates the operational impact of the indicted groups and highlights the ongoing threat posed by Russian state-backed cyber actors to European critical infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-07, reporting described how NoName057(16) uses the custom DDoSia tool to coordinate volunteer-driven, politically motivated DDoS attacks through controlled command-and-control infrastructure, propaganda, and cryptocurrency incentives. The report also noted the tool's evolution into a modular, multi-platform capability with encrypted C2, traffic randomization, and realistic client signatures.
By the time of the Justice Department announcement, Victoria Eduardovna Dubranova had been extradited to the United States and had entered a not-guilty plea in connection with the two cases. She was reported to be facing trials scheduled for 2026.
On 2026-01-05, the U.S. Justice Department announced indictments against Ukrainian national Victoria Eduardovna Dubranova for alleged involvement in cyberattacks supporting CyberArmyofRussia_Reborn and NoName057(16). The announcement said both groups were backed by the Russian government and GRU and had conducted hundreds of attacks against critical infrastructure, including U.S. utilities, election systems, and financial institutions.
Between 2025-12-29 and 2026-01-04, the pro-Russian threat actor NoName057(16) and its DDoSia project carried out a large DDoS campaign primarily targeting German infrastructure. SOCRadar recorded 2,637 attack entries affecting 115 unique domains and 97 unique IP addresses, with nearly 88% of attacks directed at Germany.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourceflashpoint.io
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.