Quorum Cyber
Threat Actor Profile of NoName057(16)
Pages
13
Time to read
9 mins
Publication
Language
English
Pages
13
Time to read
9 mins
Publication
Language
English
This document is a technical report detailing the threat actor profile of NoName057(16), a hacktivist collective aligned with the Russian Federation. Active since July 2022, NoName057(16) primarily conducts distributed denial-of-service (DDoS) attacks against high-profile organizations within NATO member states, particularly targeting government entities, financial institutions, and transport hubs. The report outlines the group's operational profile using the Diamond Model of Intrusion Analysis, which maps the adversary's capabilities, infrastructure, and victim characteristics. The motivations behind NoName057(16)'s operations are linked to geopolitical events, particularly NATO's support for Ukraine. The report also includes verified indicators of compromise (IoCs) and mitigation strategies to enhance industry awareness of the threat actor's activities. Additionally, it discusses the DDoSia project, which aims to facilitate mass DDoS attacks against entities supporting Ukraine, and provides recommendations for organizations to bolster their defenses against such threats.