Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - DDoS - Pro-Russian Cybercrime Group NoName057(16) Hit Hard in Global Takedown
DDoS Attacks Critical Infrastructure Security Latest News News & Analysis Risk Management Security

Pro-Russian Cybercrime Group NoName057(16) Hit Hard in Global Takedown

Kirsten DoyleBy Kirsten DoyleJuly 18, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cybercrime Group NoName057
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A global police operation has dealt a heavy blow to the pro-Russian cybercrime network dubbed NoName057(16), which has been accused of launching disruptive digital attacks in support of Moscow’s war against Ukraine.

Between 14 and 17 July, law enforcement agencies from across Europe and North America carried out coordinated raids and seizures under Operation Eastwood. The crackdown was led by Europol and Eurojust, and supported by a wide coalition of countries and cybersecurity experts.

It dismantled a major portion of the group’s infrastructure, took servers offline, issued arrest warrants, and warned hundreds of suspected sympathisers.

NoName057(16) is known for orchestrating distributed denial-of-service (DDoS) attacks; cheap, loud, and effective methods for flooding websites with traffic until they crash. Their targets have included Ukrainian institutions, European governments, banks, parliaments, and NATO events. Their motivation? Ideology, influence, and a steady drip of cryptocurrency rewards.

A Criminal Network Without a Leader 

Investigators say the group isn’t tightly organised. There’s no clear hierarchy. No genius in a basement. Just a sprawling network of Russian-speaking volunteers, pulled in through social media, hacker forums, and gamified propaganda.

They call on sympathisers to attack. They share tutorials and tools. They praise top performers and pay them in crypto. It’s part political theatre, part online mob. 

But now, many of those volunteers are learning what that support costs.

More than 1,000 suspected backers (15 of them identified as administrators) received warnings via messaging apps. The messages were blunt: your actions are illegal. You are being watched. Legal consequences are on the table.

Arrests, Seizures, and Disruption 

The operation also led to:

  • Two arrests (in France and Spain) 
  • Seven arrest warrants, including Six targeting Russian nationals 
  • 24 house searches across Czechia, France, Germany, Italy, Spain, and Poland 
  • 13 individuals questioned 
  • Over 100 servers taken down 
  • Major parts of the group’s infrastructure wiped offline

Germany, a key player in the investigation, issued six warrants. Two suspects are believed to be ringleaders. The names of several individuals are now public, with five featured on the EU’s Most Wanted website.

The FBI also participated, alongside police forces from countries including Sweden, Lithuania, the Netherlands, Switzerland, and Finland. Support came from Canada, Belgium, Denmark, Estonia, Latvia, Romania, Ukraine, and ENISA. Private partners ShadowServer and abuse.ch assisted with the technical side.

DDoS in the Name of the Kremlin

While NoName057(16) started out targeting Ukrainian systems, they soon widened their scope. Anyone who showed support for Ukraine became fair game.

In Germany, the group carried out 14 waves of cyberattacks against more than 250 institutions between late 2023 and mid-2024. In Switzerland, they struck in sync with symbolic moments, like a Ukrainian video address to Parliament and the Bürgenstock Peace Summit. The Netherlands also reported attacks during this year’s NATO summit.

Authorities say that although the attacks caused disruption, they were ultimately mitigated. 

The group’s botnet (hundreds of servers strong) was key to their effectiveness. That’s what made this week’s takedown so significant. By knocking out core systems, authorities disrupted the group’s ability to coordinate, communicate, and attack at scale.

Europol and Eurojust at the Helm

Behind the scenes, Europol coordinated more than 30 meetings and operational sprints. It provided forensic expertise, crypto tracing, and ran a prevention campaign targeting suspected members. 

Eurojust helped plan and execute legal actions across borders. Mutual Legal Assistance requests and European Investigation Orders were fast-tracked. On 15 July, as action teams moved in, Eurojust handled real-time judicial support to ensure no time was lost.

Representatives from Germany, France, Spain, the Netherlands and Eurojust were stationed at Europol’s headquarters during the takedown. A virtual command post linked them to counterparts in participating countries. 

Cybercrime Meets Gamification 

What sets NoName057(16) apart is how it recruits. 

They use the language of gamers. Rewards. Leaderboards. Badges. Status. 

You don’t need to know how to code. You just need to believe in the cause, or want some crypto. Their DDoS platform, “DDoSia,” lowers the barrier to entry. Everything else is about emotion. Anger, belonging, and purpose. 

Investigators believe many of the group’s 4,000+ supporters were pulled in this way. Some were teenagers. Others were opportunists. All are now under the microscope.

Multi-Layered Security Needed

According to Rafa López, security engineer at Check Point, “While the recent international crackdown on the NoName057(16) group has disrupted their operations, it is unlikely to mark the end of their activities.” 

He says the Russia-affiliated hacktivist group, which primarily targets countries with anti-Russian stances, continues to operate through encrypted channels like Telegram and Discord. “Although their DDoS capabilities have been reduced, they are shifting toward more sophisticated methods, including system intrusions and data exfiltration. The group remains active and has built a vast network of affiliates, with thousands of volunteers across various platforms, including online gaming and hacktivist forums.

“As experts in cybersecurity, we recommend that organisations strengthen their defences by implementing multi-layered security strategies, including robust DDoS protection, intrusion detection systems, and regular security audits. It is also essential to educate employees about the risks of cyberattacks, as well as to monitor for unusual activities on communication platforms that might indicate potential recruitment efforts. By staying vigilant and proactive, companies can better safeguard themselves against evolving threats from groups like NoName057(16),” López ends.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

How to Protect Your VoIP System from DDoS Attacks

September 9, 20258 Mins Read

Gorilla Botnet Launches Over 300,000 DDoS Attacks

October 8, 20243 Mins Read

New DDoS Attack Vector Discovered in CUPS, Exposing 58,000+ Vulnerable Devices Online

October 7, 20244 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}