Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors NoName057(16)

Also known as: NoName057, NoName05716, 05716nnm, Nnm05716

Description

NoName057(16) is performing DDoS attacks on websites belonging to governments, news agencies, armies, suppliers, telecommunications companies, transportation authorities, financial institutions, and more in Ukraine and neighboring countries supporting Ukraine, like Ukraine itself, Estonia, Lithuania, Norway, and Poland.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Telecommunications
Transportation

AI Analysis

· 2 weeks ago

Executive Summary

NoName057(16) is a suspected threat actor targeting critical infrastructure in Ukraine and its allies through DDoS attacks. Their activities primarily focus on disrupting government, financial, telecommunications, and transportation sectors. The actor's operational pattern suggests a strategic approach to targeting entities perceived as supportive to Ukraine, aligning with broader geopolitical tensions.

Goals & Targeting

NoName057(16) appears to target sectors and countries that align with its geopolitical interests, likely seeking to disrupt operations in regions supporting Ukraine. The actor's choice of victims—governments, financial institutions, telecommunications, and transportation—suggests an intention to cause widespread disruption and possibly influence public perception or political dynamics. Typical victims include critical infrastructure entities, which are essential for both economic stability and national security.

Enhanced Description

NoName057(16), also known as NoName05716 or Nnm05716, is an active threat actor that has gained attention for its DDoS attack campaigns targeting high-profile entities. The actor's primary targets include government websites, financial institutions, military suppliers, telecommunications companies, and transportation authorities. These attacks have primarily been observed in Ukraine and neighboring countries that support Ukraine, such as Estonia, Lithuania, Norway, and Poland. The actor's activities demonstrate a clear geopolitical angle, with targeting patterns likely linked to the ongoing conflicts in Eastern Europe. Despite being active, NoName057(16)'s exact motivation and operational affiliations remain unclear. The actor’s use of DDoS attacks suggests basic to intermediate technical capabilities, though its persistence and focus on critical infrastructure indicate a potential desire to cause disruption or political impact.

Key Capabilities

  • DDoS attack capabilities
  • Botnet management

MITRE ATT&CK Tactics

Network Disruption
Defense Evasion

ATT&CK Techniques

T1485
T1076
T1486

Software / Tooling

Custom DDoS Tools
Botnet Command and Control

Campaigns & Victims

NoName057(16) has demonstrated a consistent focus on critical infrastructure sectors, particularly in Ukraine and its allies. The actor's campaigns appear to be timed around significant geopolitical events or conflicts. Notable operations include multiple DDoS attacks targeting government websites and financial institutions, causing temporary outages. The actor's operational tempo suggests an ability to adapt targets based on regional conflict dynamics.

IOC Patterns

  • DDoS attack traffic patterns
  • Large-scale HTTP flood attacks
  • Unusual spikes in network traffic

Recommended Actions

  • Implement DDoS protection solutions
  • Monitor for anomalies in network traffic
  • Enhance botnet detection capabilities
  • Harden public-facing infrastructure
  • Engage with threat intelligence feeds

Suggested Tags

DDoS
Geopolitical
Critical Infrastructure

Confidence Assessment

The information on NoName057(16) is limited, with most data derived from observed attack patterns rather than concrete details about the group's origins or exact motivations. Confidence in the actor's capabilities and targeting patterns is moderate, but gaps exist regarding its primary motivation and long-term objectives.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
DDoS
Government Targeting
Geopolitical
Critical Infrastructure

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.