CSIDB logo
Threat actor

NoName057(16)

Attribution profile

Type
Activist
Location
Russia
Known incidents
202 incidents
Sources
84 sources
First seen
2015-04-01
Last seen
2025-12-22
Updated
2026-09-04 10:38
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

NoName057(16), also tracked under the aliases NoName and SenzaNome, is a pro-Russian hacktivist collective that emerged shortly after Russia's February 2022 invasion of Ukraine. The group first drew attention by claiming distributed denial-of-service (DDoS) attacks against Ukrainian outlets such as Zaxid and Fakty UA, framing the operations as retaliation against media perceived as anti-Russian, and has since sustained a near-continuous tempo of low-sophistication disruption campaigns against a broad cross-section of Western targets. Danish intelligence services have publicly described both NoName057(16) and the separate pro-Russian group Z-Pentest as instruments used by the Russian state as part of its hybrid warfare against countries supporting Kyiv, stating that the purpose of their operations is to create insecurity in targeted nations and to punish those that back Ukraine. The group operates as a loose network of digital activists who publicly coordinate and boast on Telegram and X (formerly Twitter), where they post target announcements, mock victims, and circulate short propagandistic statements.

The group's operational focus is overwhelmingly disruptive rather than financially or espionage-driven. Their primary technique is DDoS bombardment, frequently executed through a custom toolkit called DDOSIA, which the group distributes via GitHub and recruits volunteers to run in exchange for cryptocurrency payouts. They overwhelmingly target government ministries, parliamentary and election-related portals, municipal and provincial websites, banks, airports, media outlets, and logistics operators in NATO member states and other countries deemed hostile to Moscow, including Ukraine itself. Recent operations have hit government portals in Romania on the day of presidential elections, the state portal of Sachsen-Anhalt in Germany, a service used by Dutch provinces and municipalities, Belgian official sites including MyGov.be and the Walloon Parliament, Italian banks and ministries, Swiss cantonal banks and municipalities, Luxembourg communal sites, the New Zealand Parliament, the Finnish Ministry of Justice, the Canadian Border Services Agency, the UK councils of Portsmouth, Salford and Middlesbrough, Japan's Liberal Democratic Party ahead of a general election campaign, and a wave of Spanish municipalities including Toledo. The French national postal service La Poste was similarly hit in December 2025. A common thread in the messaging accompanying these attacks is the naming of a triggering event, such as Belgian, Italian, Dutch, Swiss, Japanese, Spanish, Danish, or Romanian support for Ukraine, statements by Western officials criticized as Russophobic, or specific arms deliveries to Kyiv.

NoName057(16) shows a consistent pattern of timing strikes around elections, NATO summits, or other high-visibility political moments to maximize embarrassment, and Dutch officials explicitly noted that the operations against Dutch provincial and municipal sites fit a pattern of pro-Russian cyber activity ahead of a NATO summit. Beyond nuisance-level DDoS, the group has occasionally used the same botnet infrastructure to enable contact-form spamming, and Spanish reporting indicates that members have been arrested in Spain on suspicion of conducting attacks with terrorist intent against public institutions, strategic companies, and NATO countries under an operation codenamed "Grizzlie." Attribution to state sponsorship remains publicly nuanced: while researchers such as Brett Callow have noted the group could be state-backed, and Danish intelligence has described links to the Russian state, other reporting, including Romanian coverage of the May 2025 campaign, characterized the group as pro-Russian but lacking direct Kremlin ties, underscoring the ambiguity that surrounds its organizational structure.

Incidents

Attributed incidents are available to members.

202 incidents

Sources

Sources available to members: 84 sources.

CSIDB