Menu
Browse

NoName057(16)

Primary URL Location Industry
Undetermined
Country Russia
Technology Icon
Technology
Profile

NoName057(16) is a pro‑Russian hacker group that operates from a headquarters located in Russia and is known primarily for conducting distributed denial‑of‑service attacks. The group identifies itself with the alias NoName057(16) and communicates its claims and motivations through its Telegram channel, where it often cites geopolitical grievances such as perceived anti‑Russian sentiments or support for Ukraine. Its attacks are carried out using the DDOSIA toolkit, which enables both volumetric traffic floods and application‑layer techniques such as Slow HTTP to overwhelm target servers. The group’s stated purpose is to disrupt online services of organisations in countries that oppose Russian interests, framing the actions as punitive or retaliatory measures. NoName057(16) does not appear to seek data theft or permanent infrastructure damage, focusing instead on temporary service interruptions that are typically restored after mitigation efforts.

On 4 May 2025 the group claimed responsibility for a DDoS campaign that disrupted several Romanian government and election‑related websites, including those of the interior and justice ministries and a presidential candidate’s site, rendering the pages inaccessible until authorities restored service. On 28 December 2024 it announced a DDoS attack against Italy’s Foreign Ministry and Milan’s airports, stating the action was retaliation for perceived anti‑Russian sentiment and noting that airport mobile applications remained functional while flight operations were unaffected. On 31 July 2023 NoName057(16) targeted Italian entities such as major banks, a water supply company, a business newspaper and public transport services, using the DDoSia toolkit and justifying the operation by criticising Italy’s support for Ukraine. On 28 May 2023 the group employed Slow HTTP techniques against the website of Banca di Credito Cooperativo di Roma, maintaining incomplete connections for approximately four hours and causing temporary service disruption without permanent damage. On 20 February 2023 it launched a DDoS attack against multiple Italian public and private entities, including government ministries, banks and energy companies, linking the operation to Italy’s provision of military aid to Ukraine. On 15 December 2022 the group struck the Italian Ministry of Defense’s e‑learning platforms, rendering eight of nine websites temporarily inaccessible while one was later restored without system compromise. On 1 November 2022 a separate incident involved a sophisticated vishing and smishing campaign against a major Italian bank that resulted in fraudulent transfers exceeding €1 million, although this event is distinct from the group’s typical DDoS focus. On 22 March 2022 NoName057(16) conducted DDoS attacks against the Italian Ministry of Transport, a transport regulatory authority and Rome’s public mobility company, citing Italy’s military support for Ukraine as motivation and causing temporary service disruptions that were subsequently restored. Across these incidents the group consistently uses Telegram to claim responsibility, emphasizes geopolitical motivations, and relies on the DDOSIA toolkit to produce short‑lived outages that are mitigated by affected organisations without lasting data compromise.

Incidents
Linked incidents available to members
8 incidents