NoName057(16) has been identified as a pro-Russian hacktivist group conducting distributed denial-of-service (DDoS) attacks against websites tied to governments, news agencies, military organizations, suppliers, telecommunications providers, transportation authorities, and financial institutions. The group’s operations have focused on Ukraine and countries supporting Ukraine, with reported targeting that includes Estonia, Lithuania, Norway, and Poland.
Reporting links the group to the Dosia/DDoSia malware family and describes an operation that has evolved through publicly documented infrastructure, targeting patterns, and campaign activity. The activity reflects a sustained disruptive effort aimed at public- and private-sector online services in European states aligned with Ukraine, reinforcing the group’s role as a persistent politically motivated DDoS threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By 17:00 UTC on 25 January 2023, the Estonian subdomain targeted by NoName057(16) displayed a down-for-maintenance message, indicating observable service disruption during the attack window.
Team Cymru observed an attack against an Estonian Ministry of Finance subdomain begin at 07:00 UTC on 25 January 2023, matching the schedule exposed in the group's target list.
The report says it confirmed NoName057(16) attacks since the beginning of 2023 against entities with infrastructure in Czechia, Denmark, Estonia, Germany, Slovakia, and Slovenia.
According to Team Cymru, NoName057(16)'s current campaign coordination server at 31.13.195.87 became operational on 19 December 2022, with Dynamic DNS domains resolving to it for target retrieval.
Team Cymru states that the group's previous command-and-control server, 77.91.122.69, remained active until 16 December 2022 before later infrastructure changes.
Team Cymru reports that NoName057(16) has claimed repeated DDoS attacks against Ukraine, NATO countries, and organizations in government, finance, freight, and media since March 2022.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourceorkl.eu
Open sourceteam-cymru.com
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.