logo

Inside DDoSia: NoName057(16)’s Pro-Russian DDoS Campaign Infrastructure

ID: ce4d4f47-5e2c-5ebb-aaae-f5bbd2eed4d4

STIX ID: report--ce4d4f47-5e2c-5ebb-aaae-f5bbd2eed4d4

Feed Name: Recorded Future Blog

Threat Score
70/100

Date Published: 2025-07-22

Date Updated: 2026-04-28

...
...

**Insikt Group tracked NoName057(16) conducting a sustained, volunteer-driven DDoS campaign (DDoSia) from July 2024–July 2025 targeting ~3,776 hosts—primarily government and public-sector targets in Ukraine and allied European countries—using a multi-tier C2 infrastructure with rapidly rotated Tier 1 servers, encrypted AES‑GCM client/C2 communication, and randomized request parameters to evade filtering; defenders are advised to deploy layered DDoS mitigation, CDNs, WAFs, rate limiting, and incident response plans, while noting recent coordinated law enforcement actions (Operation Eastwood).**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.