Anatomy of a NoName057(16)

NoName Attack Pattern

Anatomy of a NoName057(16) Campaign: Inside Russia's Rotating DDoS War on Europe

A weekly (occasionally fortnightly), single-country blitz has become the signature rhythm of Europe’s most persistent pro-Russian hacktivist collective. Here’s how one of these campaigns actually runs – and why Germany keeps ending up on top of the target list.

The Gang

NoName057(16) surfaced within days of Russia’s full-scale invasion of Ukraine in March 2022, and has been the most consistently active pro-Russian hacktivist outfit ever since. Unlike the loose, meme-driven KillNet „universe“ it eclipsed in 2023, NoName is a single, disciplined operation: it develops and maintains its own DDoS tool, DDoSia, and distributes it free of charge to volunteers recruited through Telegram. Participants run the Go-based client on their own machines, register through the @DDosiabot, and are rewarded in cryptocurrency according to a leaderboard tied to how many targets they help take down.

The group is not financially motivated. Its Telegram channel frames every wave of attacks as retaliation – for arms shipments to Ukraine, for sanctions, for a politician’s remarks, for a law-enforcement operation against its own infrastructure. That framing is the key to understanding how a „campaign“ is built.

In July 2025, an international law-enforcement effort coordinated by Europol and Eurojust – Operation Eastwood – disrupted more than 100 servers tied to the group and produced seven arrest warrants (six issued by Germany, one by Spain) plus two arrests and 24 house searches across Czechia, France, Germany, Italy, Poland and Spain. NoName’s Telegram channel dismissed the operation within days and announced „**Operation Time of Retribution**,“ publishing fresh target lists for the twelve countries involved in the takedown – Germany chief among them. The group has operated more or less continuously since.

The Weekly Campaign Model

he operating rhythm that has emerged since late 2023 is remarkably consistent:

Cadence: a new primary target country is selected roughly every seven days. Single-week campaigns have been logged with volumes ranging from ~2,600 to over 8,100 recorded attack entries, spread across 100–170 unique domains and 90–190 unique IP addresses.

Concentration: one country typically absorbs 40–90% of that week’s attack volume, with the remainder spread across Ukraine (a near-permanent secondary target), international commercial (.com) domains, and one or two supporting countries.

Update tempo: target lists are refreshed multiple times a day via Telegram – 27 separate list updates (an average of 3.9 a day) were counted during the first week of March 2026 alone, with bursts of three or four updates inside a 35-minute window.

Daily rhythm: a year-long analysis of activity (July 2024–July 2025) found that operators add new targets in two distinct daily waves, peaking between 05:00–07:00 UTC and around 11:00 UTC on weekdays – a pattern consistent with operators working a standard Russian business day.

Infrastructure churn: the same analysis found that command-and-control servers rotate fast, with an average Tier-1 lifespan of about nine days, which roughly tracks the length of a campaign itself.

Duration: most single-country pushes last about a week before the group pivots elsewhere. A second full week on the same country is unusual – but it happens when a country stays in the news (an arms-supply vote, an anniversary of a law-enforcement action, a diplomatic dispute) or when NoName is explicitly retaliating, as it did against Germany in the weeks after Operation Eastwood in July–August 2025.

The Target-Sector Playbook

The industries NoName hits are strikingly stable – a legacy, in part, of KillNet’s own 2022 playbook, which was concentrated on public administration and government services, logistics and transportation (rail, subway, harbours, airports), banks and payment providers, and energy. NoName inherited and refined that list. Pulling together public activity from 2023 through mid-2026, the recurring target categories break down as:

The consistent core, present in almost every campaign:

Public administration & government, at every level – federal ministries, state/regional governments, municipal portals, tax and revenue offices. One year-long dataset put government/public-sector targets at 41.09% of all recorded attacks, by far the largest single category.

Public transport & logistics – airports, railways, transit and ticketing systems, ports and port authorities. This was NoName’s breakout specialty in June 2023, when it pivoted hard onto ports and logistics companies across at least a dozen countries (Bulgaria, Lithuania, Latvia, Canada, Poland, Spain, the Netherlands, Sweden, Germany, Greece, Finland and Italy) in a single week. The same year-long dataset puts transportation/logistics at 12.44% of all attacks.

– Banks & financial services – retail banks, central banks, stock exchanges, payment processors. Denmark’s banks, Polish payment provider Dotpay, and Deutsche Börse have all been claimed targets at different points.

Frequently recurring, campaign to campaign:

Energy & utilities – grid operators, water companies, oil and gas firms (a category KillNet pioneered against Poland’s PGNiG and ORLEN in 2022, and one Israel’s IEC and Mekorot fell into in March 2026).

Telecommunications – national carriers and ISPs; telecom is repeatedly flagged as a heavily targeted sector, and the same year-long dataset puts technology/media/communications at 10.19%.

Media outlets, including minority-language and regional press – a symbolic, high-visibility target.

Political organisations – party websites, individual politicians‘ pages, parliaments, and election-related infrastructure. During the run-up to the June 2024 European Parliament elections, NoName and allied groups hit political parties and voter portals in the Netherlands, Slovenia, Denmark and Sweden in a single coordinated week.

Situational but recurring depending on the target country’s profile:

Defence & aerospace when the target has a defence-export profile, as Israel does. In the March 2026 campaign, Elbit Systems, Rafael, and Israel Aerospace Industries were all hit as a cluster.

Public procurement & tender platforms – an escalation first documented at scale in March 2026, when NoName hit at least 17 separate German procurement portals (DTVP, eVergabe-Online, eVergabe-MV/NRW, Vergabemarktplatz Brandenburg, and others) for a combined 974 attack entries, or 13% of that week’s total traffic – an unprecedented concentration on a single functional category of government infrastructure.

Cultural & heritage institutions – museums, cathedrals, foundations. Symbolic rather than disruptive; Naumburg Cathedral (a UNESCO World Heritage site) and the Moritzburg Foundation have both appeared on German target lists.

Weapon manufacturers – flagged specifically in the pre-EU-election 2024 wave.

Civil society, NGOs and religious/political organisations – the March 2026 Israel component pulled in a wide mix of religious-political and agricultural-cooperative sites alongside the defence and banking targets.

Tax authorities – a Bavarian district tax-office cluster plus Germany’s national ELSTER e-filing portal absorbed 447 attack entries in the March 2026 wave, timed to the German tax-filing period.

Case study: Germany, the recurring favourite

No single NATO country appears on NoName’s target lists as often as Germany. German authorities have logged 14 separate waves of NoName attacks since November 2023, affecting more than 250 companies and institutions. Three recent weekly campaigns illustrate why, and how the pattern repeats with variations:

29 December 2025 – 4 January 2026 („New Year“ campaign). Germany absorbed 88% of that week’s 2,637 attack entries across 115 domains – one of the most concentrated single-country weeks on record. Unusually, over 80% of the targets were private-sector rather than government: cultural institutions (Naumburg Cathedral), political-party regional chapters (SPD Saxony-Anhalt), a regional airport (Baden-Airpark), a Sorbian-language newspaper, and a procurement platform (Tender24), alongside the more conventional municipal government targets. Analysts read the New Year timing as a deliberate choice to exploit reduced holiday-period defensive staffing.

2–8 February 2026 (shared with Italy). Germany took 29.5% of an 8,101-entry week, with Italy as the larger share (42.9%) – a reminder that not every „German week“ is Germany-only; the group frequently runs two national fronts in parallel.

2–8 March 2026 (shared with Israel). Germany was again dominant, at 65.6% of 7,512 entries, with Israel a substantial secondary front at 19.7%. This is the week that produced the procurement-portal blitz described above, plus a geographically dispersed hit-list concentrated in Saxony-Anhalt – including the personal site of the state’s Minister-President, Reiner Haseloff, and the city portal of Magdeburg, the site of the December 2024 Christmas-market attack, whose inclusion was read by analysts as a deliberate attempt to compound an already-traumatised city’s difficulties. On the technical side, that week’s traffic split almost evenly between GET floods (23.3%) and SYN floods (22.2%), with a 9.6% slice of nginx_loris slow-connection attacks aimed at exhausting server connection pools rather than bandwidth – and 72.9% of all traffic aimed squarely at port 443 (HTTPS), i.e. services that can’t simply be switched off as a mitigation measure.

Outside the weekly-tracker data, Germany also produced the clearest real-world casualty of the group’s 2026 activity: on 17 February 2026, a multi-wave DDoS attack knocked out Deutsche Bahn’s website, its DB Navigator app, and station departure boards for several hours. Train control and signalling were unaffected – the attack hit customer-facing systems only – but it ran in parallel with attacks on other NATO countries and was quickly attributed to NoName057(16)’s DDoSia tooling, prompting public comment from BSI President Claudia Plattner on the growing strategic weight of DDoS as a tool of geopolitical pressure.

And the group’s own framing leaves little doubt about motive: German officials and researchers alike have tied the post-Eastwood surge directly to the arrest warrants Germany issued against alleged NoName leadership, and separately to German political decisions on Ukraine support – including, in an earlier 2025 wave, backlash against Chancellor Friedrich Merz’s plans to supply Taurus cruise missiles.

The rotation ledger

Pulling together weekly public activity tracking for the winter/spring 2026 season shows the rotation in full:

Two of ten tracked weeks put Germany on top – more than any other single country in this window, though not as a single unbroken fortnight. The closest thing to a genuine multi-week German campaign in the public record is the post-Eastwood „revenge“ wave: Cybervandals tracked German local-administration and police sites going down within five days of the July 2025 takedown, and NoName’s own Telegram announcement of „Operation Time of Retribution“ named 16 German targets on the same day it declared the crackdown a failure – a wave that was still „hitting hard and succeeding“ more than a month later.

The group has also shown it will borrow allies to extend a national campaign: it worked with ServerKillers, another pro-Russian outfit, against Spanish government and EU-linked sites in January–February 2026, and separately joined forces with pro-Iranian groups MuddyWater and CyberAv3ngers for a combined Germany–Israel push that hit roughly 6,000 targets across 143 domains, with heavy telecom-sector focus.

Why the rotation exists

The pattern is best read as an editorial calendar rather than a random walk. NoName’s own Telegram messaging consistently frames a new week’s target country in terms of a specific grievance – sanctions, arms deliveries, a diplomatic statement, a NATO summit, a law-enforcement action – which lets the group claim political relevance for what is, technically, a low-sophistication attack type. Rotating the primary target also has a practical defensive benefit for the attackers: it prevents any single country’s CERTs, CDNs and ISPs from settling into a steady-state mitigation posture, forcing a fresh scramble roughly every seven days. Germany’s outsized share of the rotation reflects its outsized role in the underlying conflict it’s being punished for – NATO’s largest European economy, one of Ukraine’s most consequential military and financial backers, and the country that issued most of the Eastwood arrest warrants.

Selected references

Cybervandals – NoName057 is back https://blog.kybervandals.com/noname057-is-back/

Ports and Logistics are the new Targets of NoName057 https://blog.kybervandals.com/ports-and-logistics-are-the-new-targets-of-noname057/

DDoS-Attacks on EU-Institutions by russian activist https://blog.kybervandals.com/attacks-on-eu-by-russian-activist-summarized/

DDoS as Attackvector for State-Sponsored/Hacktivist-Groups in Times of Crisis https://blog.kybervandals.com/ddos-as-attackvector-for-state-sponsored-hacktivist-groups-in-times-of-crisis/)

Hacktivists in Ukraine-Russia Conflict https://blog.kybervandals.com/swithak/

Tracking DDoS – Botnets https://blog.kybervandals.com/tracking_botnets/

SOCRadar weekly DDoS Threat Intelligence — [Germany, 29 Dec–4 Jan]
https://socradar.io/blog/ddos-threat-intelligence-germany-5-jan26/

Italy & Germany, 2–8 Feb https://socradar.io/blog/italy-germany-under-ddos-9-feb26/)

Czechia, 19–25 Jan https://socradar.io/blog/ddos-threat-intelligence-czechia-26-jan26/

Multi-Country, 26 Jan–1 Feb https://socradar.io/blog/ddos-threat-intelligence-multi-country-3-feb26/)

Spain, 16–23 Feb https://socradar.io/blog/spain-under-ddos-23-feb26/

Germany & Israel, 2–8 Mar https://socradar.io/blog/germany-israel-under-ddos-10-mar26/)

Operation Eastwood coverage https://socradar.io/blog/operation-eastwood-targets-noname05716/)

Dark Web Profile: NoName057(16) https://socradar.io/blog/dark-web-profile-noname05716/

Recorded Future / Insikt Group — Inside DDoSia: NoName057(16)’s Pro-Russian DDoS Campaign Infrastructure https://www.recordedfuture.com/research/anatomy-of-ddosia

Europol / EU Neighbours East — Global operation targets NoName057(16) pro-Russian cybercrime network https://euneighbourseast.eu/news/latest-news/global-operation-targets-noname05716-pro-russian-cybercrime-network/

The Record (Recorded Future News) — International operation disrupts pro-Russian hacker group NoName057(16) https://therecord.media/international-police-takedown-noname-hacker

Computer Weekly — European cyber cops target NoName057(16) DDoS network https://www.computerweekly.com/news/366627802/European-cyber-cops-target-NoName05716-DDoS-network

Security Today (DE) — Q1 2026: The Five Most Dangerous Cyber Incidents in Germany https://www.securitytoday.de/en/2026/03/28/q1-2026-the-five-most-dangerous-cyber-incidents-in-germany-and-what-they-have-in-common/)

Dark Reading — DDoSia Powers Affiliate-Driven Hacktivist Attacks https://www.darkreading.com/cyberattacks-data-breaches/ddosia-powers-volunteer-driven-hacktivist-attacks

Wikipedia — Noname057(16) https://en.wikipedia.org/wiki/Noname057(16)

You are under DDoS-Threat, by NoName or others?

Our DDoS Threat Simulation Platform „Avydos“ is the platform of choice for automated DDoS testing. Built as a self-service cloud platform with 24/7 availability, it gives you full control to run DDoS simulations whenever you need them – quickly, independently, and without external dependencies.

The platform covers all attack vectors, from high-volume Layer 3/4 attacks to sophisticated Layer 7 application attacks, including both single and multi-vector combinations. This broad coverage helps to uncover weaknesses in defenses that simpler tests often miss.

At the same time, Avydos is perfectly designed to support compliance efforts. It helps organizations meet requirements under DORA, NIS2, and similar regulations by providing continuous, documented resilience testing and clear reporting that auditors and regulators expect.

Avydos DDoS Threat Simulation and Automation Platform: https://avydos.com/en/

zeroBS DDoS Testing Services: https://zero.bs/en/

Infos & Contact

en_GBEnglish

Your request

Contact us