Inside DDoSia: NoName057(16)’s Pro-Russian DDoS Campaign Infrastructure
ID: ce4d4f47-5e2c-5ebb-aaae-f5bbd2eed4d4
STIX ID: report--ce4d4f47-5e2c-5ebb-aaae-f5bbd2eed4d4
Feed Name: Recorded Future Blog
**Insikt Group tracked NoName057(16) conducting a sustained, volunteer-driven DDoS campaign (DDoSia) from July 2024–July 2025 targeting ~3,776 hosts—primarily government and public-sector targets in Ukraine and allied European countries—using a multi-tier C2 infrastructure with rapidly rotated Tier 1 servers, encrypted AES‑GCM client/C2 communication, and randomized request parameters to evade filtering; defenders are advised to deploy layered DDoS mitigation, CDNs, WAFs, rate limiting, and incident response plans, while noting recent coordinated law enforcement actions (Operation Eastwood).**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
