= Noname057(16) =

NoName057(16)
- Size: 180px
- Formation: 2022
- Type: Hacktivist group
- Status: Active
- Purpose: Pro-Russian cyber activities
- Headquarters: Unknown
- Region Served: Global
- Leader Title: Origin
- Leader Name: Russia
- Leader Title2: Platforms
- Leader Name2: Telegram, GitHub
- Leader Title4: Products
- Leader Name4: DDOSIA (DDoS tool)
- Affiliations: Pro-Russian entities

NoName057(16) is a pro-Russian hacker group that first declared itself in March 2022 and claimed responsibility for cyber-attacks on Ukrainian, American and European government agencies, media, and private companies. It is regarded as an unorganized and free pro-Russian activist group seeking to attract attention in Western countries.

The first attacks claimed by the group in March 2022 were DDoS attacks targeting Ukraine news and media websites Zaxid and Fakty UA among others. Overall the motivations of the group appear to center around silencing organisations the group deem to be anti-Russian.

In July 2025 Europol and Eurojust took action against the gang, releasing warrants for 6 people.

== Activity ==
NoName057(16) operates using Telegram channels where they claim responsibility for their attacks, mock targets, make threats, and share educational content. They have used GitHub to host their DDoS tool website and associated repositories. The group has developed a DDoS tool named DDOSIA, which conducts denial-of-service attacks by repeatedly issuing network requests to target sites.

It is noteworthy that the threat actor appears to collaborate with other pro-Russian cyber collectives, such as Killnet and XakNet.

Ukrainian media employees received threatening letters from the NoName057(16) group. This was confirmed by the Ukrainian ex-Ombudsman Lyudmila Denisova. OSINT researcher Cyberknow20 has included NoName057(16) in his summary table of hacker groups, which he periodically updates.

== Motivation ==
On the Telegram channel of the group a "Manifesto" was posted 11/03/2022.

The English translation reads:Greetings, comrades! Hacker group NoName057(16) goes out on the warpath with Ukrainian sub-hackers and their corrupt servants! These admirers of the neo-fascists, who have seized power in Ukraine, are trying to attack the Internet resources of our country and intimidate our compatriots with their attacks orchestrated through the social networks and other communication channels. In response to their pathetic efforts, we are conducting massive attacks on Ukropropaganda resources that brazenly lie to people about Russia's special operation in Ukraine, as well as on the websites of Ukrainian grief-hackers who try to support the neo-Nazi regime of Zelensky and a handful of drug addicts and Nazis from his mob! We have already conducted several successful attacks on Ukrainian resources, which have paralyzed users’ access to them. And this is just the beginning. To our enemies, we want to remind the words of the famous Russian commander Alexander Nevsky: “Whoever comes to us with a sword will perish by the sword!" Here we will talk about our cases and conducted attacks.

== Authoritative action against the group ==
In an internationally coordinated operation, called Operation Eastwood, law enforcement agencies from numerous countries took action against the hacker group from the 14th to the 17th of July, 2025. The operation was coordinated by Europol and Eurojust and executed in Czechia, France, Finland, Germany, Italy, Lithuania, Poland, Spain, Sweden, Switzerland, the Netherlands and the United States simultaneously. A network consisting of several hundred servers distributed worldwide was shut down. Several arrest warrants have been issued, and the suspects are being sought internationally. The six people against whom arrest warrants have been issued are reportedly Russian citizens or people residing in Russia. Two of them are believed to be the main perpetrators. In addition, another arrest warrant was issued by the Spanish authorities.

Since the beginning of Russia's war of aggression against Ukraine, around 4,000 supporters have been recruited via the messaging service Telegram. They were offered the download of special software that allowed them to participate in DDoS attacks using their own resources. The group also built its own botnet consisting of several hundred servers.

== Known DDOS attacks ==

=== Belgium ===
On October 7, several websites of Belgian governmental organisations and ports started getting DDoS attacked by the hacker group. Provinces and local government websites went down for 2 days. These are also the two governments for which elections take place on October the 13th.

On December 15, websites of several Belgian energy suppliers, such as Eneco, and Luminus were attacked by the hacker group.

=== Canada ===
On September 13, 2023, the NoName057(16) group has launched a DDoS attack on many Canadian and Quebec government websites. A total of 8 sites are attacked.

=== Baltic sites ===
==== Estonia ====
On June 7, 2022, NoName057(16) carried out a cyberattack on the website of the Central Bank of Estonia. Bank representatives confirmed the fact of the attack and emphasized that as a result of the incident, “the external website and the statistics module of the Bank of Estonia were not working due to technical reasons”.[27]
==== Latvia ====
The DDOS attack claimed by the NoName057(16) group disrupted the online train ticket sales system on the website and in the mobile application of the Latvian company Passenger Train (Pasažieru vilciens). The company representatives stated in their Twitter account they had to stop selling tickets on the site and in the application because of the incident.
==== Lithuania ====
On June 21, representatives of the hacker group NoName 057(16) announced on their Telegram channel that they were joining the attacks on the websites of the Republic of Lithuania. In their appeal, they called on other communities of pro-Russian hackers, as well as individual hacktivists, to do the same. The hackers called their actions "revenge for Kaliningrad".
As a result, in about a month, the group carried out more than 200 attacks on Lithuanian Internet infrastructure resources.
The Lithuanian Ministry of Defense stated that the participants in the attacks were pro-Russian "volunteer activists".
In particular, the group attacked the website of the Lithuanian company Ingstad, the websites of Lithuanian airports and other Internet resources.
In addition to DDOS attacks on Lithuanian sites, hackers from NoName057(16) managed to perform a so-called deface on one of them. As a result, a message from hackers appeared on the main page of the resource of the logistics company ExpressTrip.

=== Czech Republic ===
During the 2023 presidential elections on January 13, 2023, the website of presidential candidate General Petr Pavel has been under a strong hacker attack since Friday morning. That's why it was not loading for some users, his election team said. It is said that the website faced a similarly strong attack throughout Wednesday. According to the operator, the attack was conducted from various IP addresses across Europe.

On March 24, 2023, there was a DDoS attack on the site of Prague Integrated Transport website about public transportation in Prague. The website was unavailable for several hours. The Noname057(16) claimed responsibility for the attack. Also, the website of Florenc Central Bus Station was also affected by this attack.

On August 30, 2023, a DDoS attack on Czech banks occurred, causing their online banking systems to be unavailable. Noname057(16) claimed responsibility for its attack on its Telegram channel.

=== Denmark ===
The group claimed responsibility for DDoS attacks on the sites of a number of businesses in the financial sector, along with the Ministry of Finance in January 2023, due to the Danish support to Ukraine. And September 2023 tha Danish data commissioners website.
Most recently an attack against Danish municipalities and Ministry of Transportation. Downtime for the majority of the municipalities: less than 30 minutes.

=== Finland ===
A cyber attack on the website of the Finnish Parliament occurred after Finland joined NATO on April 4, 2023. Finnish journalists ranked the group as pro-Russian.

As a result of the incident, the Finnish criminal police launched a preliminary investigation.

=== France ===
In 2025 a DDoS attack against the postal service interrupted operations during the several days before Christmas. The attack interrupted online banking as well as postal services and package delivery. Noname057(16) claimed responsibility.

=== Germany ===
The group claimed responsibility for DDoS attacks on the sites of a number of Government and businesses sites, along with the Federal Foreign Office, Bundestag and the Platform for the Reconstruction in Ukraine which were unsuccessful in February to April 2023.
In February 2026 the group attacked the booking services operated byDeutsche Bahn.

=== Iceland ===
During the Summit of the Heads of State and Government of the Council of Europe in Reykjavik, Iceland, May 16, 2023, the NoName057(16) group claimed responsibility for several attacks on Icelandic governmental websites.

=== Italy ===
Following the visit of Prime Minister Giorgia Meloni to Kyiv, in support of Ukraine's efforts in the ongoing conflict with Russia, a series of Italian companies' and institutions' were attacked in February and March 2023.

=== Netherlands ===
The group carried out DDOS attacks against websites of several Dutch ports in Q1 of 2023. Port authorities state that their internal systems were not compromised or affected. The group hints that the attacks are in response to the Dutch plan to buy Swiss tanks for Ukraine.

In August 2023 Dutch organizations have been targeted by DDoS attacks according to the Netherlands' National Cyber Security Centre NCSC. The pro-Russian or Russia aligned hacker group NoName057(16)claimed responsibility for these attacks, which had limited impact on the targeted organizations. NoName057(16) is known for politically motivated attacks associated with Russia or could be hired by Russian actors as cyber-mercenaries.

On 4 November 2023 A DDoS (Distributed Denial of Service) attack involves bombarding computer systems with a substantial amount of internet traffic, aiming to overwhelm and disrupt them. NoName05716, a pro-Russian "hacktivist" group, is currently conducting such attacks on Dutch organizations in response to Dutch support for Ukraine in its conflict with Russia. Translink, a company affected by the attacks, reported that their website experienced temporary unavailability due to the ongoing DDoS attack. Despite the disruption, the ov-chipkaart, a public transportation smart card, remains operational for travelers, and Translink anticipates resolving the issue by Saturday afternoon.

=== Norway ===
As a kind of protest against the decision of the Norwegian authorities to ban the delivery of goods to Russian citizens in the Svalbard archipelago, the NoName057(16) group organized attacks on a number of sites in Norway. The attacks were noticed by the local media.

=== Poland ===
The group also carried out DDOS attacks against Poland's Internet infrastructure in different periods of time.

=== Taiwan (ROC) ===
On September 12, hackers from NoName057(16) attacked several websites of Taiwan companies and government, including Mega Financial Holding Company Ltd., Chailease Finance Co., Ltd., Chang Hwa Bank, Taiwan Stock Exchange, and Directorate General of Budget, Accounting and Statistics.

=== Ukrainian sites ===
Starting from March 2022, the NoName057(16) group has carried out a number of cyberattacks on Ukrainian media websites and Ukrainian media portals. For example, such as: the portal "Detector Media", the site "Odesa Online", the information agency "Competitor".

=== United Kingdom ===
On October 28, 2024, 13 local authorities were targeted by NoName057(16), with additional local authorities targeted on October 30. The first wave of attacks resulted in service disruption for 6 councils, with the second wave disrupting services for 3 councils.

=== United States ===
Also, hackers from NoName057(16) carried out attacks on the websites of American companies from various fields of activity.
As a result of one of these attacks the website of the ITT company ceased to be available to users for a long time.
