logo

Investigating the Infrastructure Behind DDoSia's Attacks

ID: be1a6e68-1a79-55d8-9af4-ef4b7449f5e7

STIX ID: report--be1a6e68-1a79-55d8-9af4-ef4b7449f5e7

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2025-12-15

Date Updated: 2026-04-27

Author: Silas Cutler; Principal Security Researcher

...
...

DDoSia is a participatory DDoS tool run by the pro‑Russian hacktivist group NoName057(16) since 2022; volunteers run provided binaries to conduct coordinated DDoS attacks primarily against Ukraine, NATO states, and allied infrastructure. The report details DDoSia’s multi‑layered control infrastructure, short‑lived VPS‑hosted control servers, observed targeting and scale (estimated under 10k bots), identified client binaries with SHA256 hashes, law enforcement disruption in July 2025, and the continued reconstitution and activity observed by Censys through late 2025, emphasizing the need for DDoS mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.