Cyber Threat Actor: NoName057(16)
| Actor Type | Location | Known Incidents |
Activist
|
Russia
|
203 incidents |
|---|
Profile
NoName057(16) is a hacktivist group that operates under several aliases including NoName, NoName057(16), SenzaNome and DEV‑0586 and has been identified by open‑source sources as being based in Russia. The group describes itself as pro‑Russian and has stated that its actions are taken in support of the Russian Federation following the start of the war between Ukraine and Russia. Multiple sources refer to the collective as a Russian‑linked hacktivist group that has been active since early 2022 and that focuses its activities on NATO‑aligned countries and entities that support Ukraine.
The group’s observed targeting spans government institutions, financial institutions, critical infrastructure and health‑care providers across Europe, North America and Ukraine. Public statements and claimed responsibility messages indicate that the attacks are intended as retaliation for political and military support provided to Ukraine, including responses to military aid packages, sanctions and public statements of solidarity. Victims have included the French national postal service and its banking portal, a Danish water utility, the Sachsen‑Anhalt state portal, Dutch provincial and municipal websites, Romanian government and election‑related sites, Belgian federal and regional portals, Ukrainian banks, NATO earthquake‑relief operations, the Eurocontrol air‑traffic agency, the French Senate and National Assembly, and Canadian government sites. The group has also claimed attacks on Ukrainian financial sector entities such as First Ukrainian International Bank, Oshchadbank, Credit Agricole Bank and Universal Bank, as well as on Czech ministries and companies.
Observed tactics, techniques and procedures consist primarily of distributed denial‑of‑service (DDoS) campaigns, with the group frequently citing the use of its own DDoSIA tool and employing Slow HTTP (Slowloris) techniques to exhaust server connections. Claims of responsibility are routinely posted to the group’s Telegram channel, where it announces targets and motivations. Victims have reported implementing mitigations such as geo‑blocking, traffic scrubbing services and application‑layer firewalls in response to the attacks. The group’s activity is characterized by repeated waves of traffic that overwhelm targeted services, leading to temporary unavailability of websites and online services without reported data exfiltration or persistent damage to underlying systems.
Notable campaigns highlighted in open‑source reporting include a December 2025 DDoS that disrupted France’s postal service and associated banking platforms, a November 2025 attack that manipulated water pressure controls at a Danish utility causing pipe bursts, a July 2025 DDoS against the Sachsen‑Anhalt state portal, a June 2025 campaign against Dutch provincial sites, a May 2025 series of attacks on Romanian government and election sites, a March 2025 barrage on Belgian federal and regional portals, a June 2023 wave targeting Ukrainian banks, a February 2023 disruption of NATO earthquake‑relief operations, an April 2023 assault on Eurocontrol, and a May 2023 DDoS that took down the French Senate website. While some sources have noted suspicions of possible state involvement, the publicly available material does not provide a definitive attribution to a specific Russian state organ, and the group is consistently described as a pro‑Russian hacktivist collective rather than a formally acknowledged state entity.
