Cyprus and Israel Under DDoS Siege: Weekly DDoS Threat Intelligence Analysis
ID: 8b0767ad-c085-5f21-8ef3-df488f0e76cd
STIX ID: report--8b0767ad-c085-5f21-8ef3-df488f0e76cd
Feed Name: SOCRadar Blog
**Executive Summary:** Between March 9–16, 2026, pro‑Russian hacktivist NoName057(16) executed a coordinated DDoS campaign via the DDoSia framework producing 5,828 recorded attack instances across 143 domains and 131 IPs, with Cyprus (52.5%), Israel (12.7%), and Romania (8.9%) as primary targets; the campaign was application‑layer dominant (82.4% HTTP), overwhelmingly targeted HTTPS (97.5% on port 443), affected government, transportation, financial, media, and defense entities (including Elbit and IAI), showed evidence of automated sustained C2 (28 JSON target‑list updates), and the report issues urgent Layer‑7 mitigation and HTTPS inspection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
