Following NoName057(16) DDoSia Project’s Targets
ID: a379d05c-2edf-5426-b321-2180e35b4b05
STIX ID: report--a379d05c-2edf-5426-b321-2180e35b4b05
Feed Name: Sekoia.com
This report analyzes DDoSia, a cross‑platform DDoS toolkit distributed via Telegram by the NoName057(16) hacktivist group: it documents registration and distribution channels, the C2 HTTP protocol, an AES‑GCM mechanism used to conceal target lists (with key/IV/tag derivation found via dynamic analysis), reverse engineering of the Windows Go binary, victimology covering 486 domains (primarily Ukrainian and NATO countries) from May–June 2023, and provides IoCs (executable SHA256s and a C2 IP).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
