Also known as: NoName057, NoName05716, 05716nnm, Nnm05716
NoName057(16) is performing DDoS attacks on websites belonging to governments, news agencies, armies, suppliers, telecommunications companies, transportation authorities, financial institutions, and more in Ukraine and neighboring countries supporting Ukraine, like Ukraine itself, Estonia, Lithuania, Norway, and Poland.
Targeted Sectors
Executive Summary
NoName057(16) is a suspected threat actor targeting critical infrastructure in Ukraine and its allies through DDoS attacks. Their activities primarily focus on disrupting government, financial, telecommunications, and transportation sectors. The actor's operational pattern suggests a strategic approach to targeting entities perceived as supportive to Ukraine, aligning with broader geopolitical tensions.
Goals & Targeting
NoName057(16) appears to target sectors and countries that align with its geopolitical interests, likely seeking to disrupt operations in regions supporting Ukraine. The actor's choice of victims—governments, financial institutions, telecommunications, and transportation—suggests an intention to cause widespread disruption and possibly influence public perception or political dynamics. Typical victims include critical infrastructure entities, which are essential for both economic stability and national security.
Enhanced Description
NoName057(16), also known as NoName05716 or Nnm05716, is an active threat actor that has gained attention for its DDoS attack campaigns targeting high-profile entities. The actor's primary targets include government websites, financial institutions, military suppliers, telecommunications companies, and transportation authorities. These attacks have primarily been observed in Ukraine and neighboring countries that support Ukraine, such as Estonia, Lithuania, Norway, and Poland. The actor's activities demonstrate a clear geopolitical angle, with targeting patterns likely linked to the ongoing conflicts in Eastern Europe. Despite being active, NoName057(16)'s exact motivation and operational affiliations remain unclear. The actor’s use of DDoS attacks suggests basic to intermediate technical capabilities, though its persistence and focus on critical infrastructure indicate a potential desire to cause disruption or political impact.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
NoName057(16) has demonstrated a consistent focus on critical infrastructure sectors, particularly in Ukraine and its allies. The actor's campaigns appear to be timed around significant geopolitical events or conflicts. Notable operations include multiple DDoS attacks targeting government websites and financial institutions, causing temporary outages. The actor's operational tempo suggests an ability to adapt targets based on regional conflict dynamics.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information on NoName057(16) is limited, with most data derived from observed attack patterns rather than concrete details about the group's origins or exact motivations. Confidence in the actor's capabilities and targeting patterns is moderate, but gaps exist regarding its primary motivation and long-term objectives.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics