← Back

NoName057(16): from DDoSia to a political pressure infrastructure

Based on an exclusive interview with iQBlack, this Threat Research analyzes NoName057(16) beyond its role as a DDoSia operator. We read it as a pressure infrastructure that combines an ideologized community, intelligence tasks, propaganda, manipulation of the information cycle, functional alliances, and induced political costs.

Leer en Español
Print Share

Executive summary

NoName057(16) does not ask to be measured only by the duration of an outage. In the exclusive interview held with iQBlack, the actor shifts the center of gravity from technical unavailability toward a broader zone. A zone in which it appears equally comfortable shaping public opinion, sustaining volunteers, forcing state reactions, exploiting institutional fear, and turning each Western response into narrative fuel.

DDoS remains a central tool, and DDoSia is one of its most visible surfaces. But the interview suggests that NoName057(16) positions itself as a political-cyber machine in which technical disruption is only one part of the intended effect. The group wants to operate against systems, but also against interpretations.

If NoName057(16) is analyzed only as a DDoS actor, the result is a sequence of downed targets, windows of unavailability, and campaigns against countries that support Ukraine. If it is analyzed as a political pressure infrastructure, other layers appear: mobilized community, intelligence tasks, target selection based on the sociopolitical agenda, exploitation of news, accumulated reputation, modular alliances, and manipulation of state responses.

Europol described NoName057(16) as a pro-Russian cybercriminal network affected by Operation Eastwood in July 2025, linked to attacks against Ukraine and countries that support it. In the same context, Europol noted that platforms such as DDoSia simplified technical processes and allowed new participants to become operational quickly. Gen Digital, for its part, analyzed DDoSia as a volunteer project associated with NoName057(16) and highlighted that a volunteer model could be more efficient and manageable than a traditional botnet under certain political conditions.

The interview with iQBlack adds a different layer. NoName057(16) speaks of analysts, intelligence specialists, content creators, developers, volunteers, allies, access levels, and a role-based structure. It even compares its organization to a private intelligence company, while claiming that its range of capabilities would be broader. That self-description suggests that the actor wants to be interpreted as a distributed system with differentiated functions.

The actor’s own explanation reinforces that reading. NoName057(16) describes target selection as conditioned by the sociopolitical agenda of the moment, differentiates intelligence tasks, technical execution, and information dissemination, and rejects the label of “Kremlin hackers” as an external simplification of its activity.

The central axis of this analysis is that NoName057(16) appears to turn DDoSia into an entry point. The tool provides scale; the community, persistence; propaganda, duration beyond the disruption; intelligence, selection and timing; alliances, capability modules; and the group turns events into narrative. A scheme that multiplies reach and narrative capacity.

DDoSia is visible, but it does not exhaust the system

DDoSia organizes an important part of NoName057(16)’s public visibility. It helps explain volunteer participation, repeated campaigns, operational simplification, and task distribution. It also offers a comfortable reading for defenders and analysts: tool, volunteers, targets, traffic, mitigation.

While that reading is necessary, it is incomplete. In the interview, NoName057(16) avoids being boxed into the tool. It states that it is not simply a hacker collective, but something “broader and more versatile”, capable of doing things not usually associated with hackers in the traditional sense. The key phrase does not refer to bandwidth or infrastructure. It refers to shaping public opinion.

That changes the perspective compared with a traditional analysis. DDoSia can explain how part of the action is channeled, but it does not explain how topics are selected, how volunteer morale is sustained, how campaigns are articulated with political developments, how official responses are exploited, or how a brief disruption is turned into prolonged narrative pressure.

NoName057(16) appears to understand that a tool can be blocked, cloned, replaced, or degraded. An ideologized community, by contrast, can be rebuilt around other channels, other symbols, and other targets. DDoSia provides volume; narrative gives it continuity.

Operational community and people as infrastructure

One of the best phrases in the interview, probably, is not in a technical description, as might be expected. It is in the way NoName057(16) contrasts infrastructure with people. According to the actor, infrastructure can be defended and cyberattacks can be countered, but resisting people driven by deep convictions would be much more difficult.

That formulation reveals a doctrine of resilience in which volunteers can fulfill several functions at once. For NoName057(16), the community is not just an audience, an auxiliary mass, or a Telegram public. It is part of the infrastructure.

A volunteer can consume propaganda, produce belonging, sustain morale, or turn a technical campaign into a political cause. Participation does not need to be homogeneous. A technical member and a sympathizer who redistributes content do not perform the same task, but both can strengthen the system.

The interview reinforces this reading when the actor states that there are roles for everyone depending on skills and experience. NoName057(16) does not describe its base as an undifferentiated crowd. It speaks of teams, analysts, specialists, developers, content creators, volunteers, and allies. It also recognizes access levels and a role-based structure, introducing a need-to-know logic inside the community.

The result is a form of organization more resilient than a classic botnet because it does not depend only on technical nodes. It depends on identity, reward, recognition, narrative, and emotional continuity.

Functional division: intelligence, technical execution, and information

The interview makes it possible to observe a more precise functional division. NoName057(16) distinguishes an intelligence direction oriented toward collecting, analyzing, and systematizing information; a technical direction responsible for executing assigned tasks; and an information direction responsible for publications and the dissemination of results.

The most relevant detail is not the existence of “intelligence” as a word, but what type of information the actor considers valuable. NoName057(16) prioritizes information that helps understand the relevance of an event, its public and political resonance, and the countries or sectors occupying the center of attention at a given moment.

In other words, intelligence does not appear subordinated only to finding exposed infrastructure. It also operates as a mechanism of political prioritization. It is not only about identifying what can be attacked, but deciding where an action can produce greater public impact.

The agenda as a targeting system

NoName057(16) does not present target selection as a merely opportunistic activity. In the interview, the actor states that it constantly analyzes the information agenda, international events, official statements, and decisions made by different states. According to that explanation, the agenda of the day or the week can determine which country becomes the center of attention.

The example offered by the actor itself is direct: if a country decides to provide financial aid or supply weapons to Ukraine, that country may become the focus of activity. Selection, therefore, is not described as a random search for vulnerable surfaces, but as a decision conditioned by the sociopolitical resonance of the moment.

That point matters because it shifts the question from “which system can go down” to “which disruption can produce a useful reading for its narrative”. In NoName057(16)’s declared logic, and as mentioned above, the value of a target is not only in its technical exposure, but in its ability to connect disruption, political context, media coverage, and symbolic pressure.

In this context, “intelligence” does not necessarily have to mean access to state secrets. It can mean something broader and operational: agenda monitoring, conflict reading, country prioritization, media sensitivity, sector identification, political timing, expected institutional response, and the ability to turn a technical target into a political message.

The tool disrupts. The agenda decides where that disruption can mean something.

Success as secondary cost

NoName057(16) does not describe success as a simple availability metric. It speaks of short- and long-term impact, effect on the target country, the international environment, economic damage, reputational damage, and social consequences. It also claims that, for years, when something stops working in Europe, the automatic assumption often points to NoName057(16), and presents that as recognition of its achievements.

For an actor of this type, the attack does not end when a website comes back online. It can continue in the public explanation, in the emergency meeting, in defensive spending, in the anxiety of authorities, in media coverage, in later regulation, or in the perception that a country was exposed.

The interview shows that NoName057(16) interprets cybersecurity budgets, new state structures, institutional fear, and general economic losses as part of the effect induced by its activity. That causal relationship may be exaggerated, self-promotional, or difficult to sustain case by case. But the mental framework is clear: the actor does not only seek to take services down; it seeks to force reaction.

NoName057(16)’s economy is not only an economy of technical damage. It is an economy of reaction.

Operation Eastwood: absorbing the blow, returning the narrative

Operation Eastwood was publicly presented as an international operation against the NoName057(16) network. Europol stated that, between July 14 and 17, 2025, law enforcement and judicial authorities from different countries took action against infrastructure and affiliates linked to the actor. AP also reported that the coordinated action included simultaneous measures against a pro-Russian network associated with denial-of-service attacks.

The interview shows how NoName057(16) rewrites that episode. The actor claims that, after Eastwood, both the number and range of its attacks increased, including attacks involving industrial systems. It also states that some technical processes changed, but that the main point was that Europol had allegedly been made to look ridiculous.

It is not necessary to accept that version to recognize its function. Operation Eastwood becomes, within the actor’s narrative, resilience material. Law enforcement pressure does not appear as definitive degradation, but as an opportunity to demonstrate continuity, ridicule authorities, and reinforce internal cohesion.

That mechanism is central because NoName057(16) does not only respond to law enforcement operations; it digests them and redistributes them as propaganda. Each advisory can become proof of relevance. Each arrest can be read as persecution. Each sanction can become a medal. Each attempted infiltration can be presented as a counterintelligence victory.

Western pressure does not remain outside the campaign. It enters the circuit and feeds the narrative.

Counterintelligence as defensive propaganda

The interview introduces a particularly sensitive episode. NoName057(16) claims that German police attempted to infiltrate the group through a person identified as Angelique Geray, and that the actor kept her deceived for six months before publishing an investigation about the case.

From NoName057(16)’s perspective, the group does not appear only as a target of Western intelligence. It appears as an actor capable of detecting, manipulating, and exposing that activity. The story, whether real, exaggerated, or partially constructed, serves at least three narrative operations: reinforcing superiority, producing cohesion, and humiliating the adversary.

Counterintelligence, in this case, also functions as theater. It is not limited to protecting the group. It produces a scene for the community, feeds internal confidence, and turns potential vulnerability into a signal of control: “they tried to get in, we saw them, we deceived them, we survived”.

That narrative is useful even if it does not prove everything it claims.

Propaganda, disinformation, and manipulation of the information cycle

NoName057(16) states that it follows the information agenda, global events, official statements, state decisions, and the evolution of the media context. That constant observation does not appear as a secondary activity, but as part of the mechanism that guides focus, timing, and country selection.

The technical operation produces an event. The event produces coverage. The coverage generates reaction. The reaction provides new material. That material returns to the actor’s channels, now transformed into propaganda, mockery, proof of impact, or symbolic recruitment.

Disinformation does not always need to appear as a lie fabricated from scratch. It can operate through selection, exaggeration, causal appropriation, emotional framing, omission of context, or interested attribution of consequences. NoName057(16) appears comfortable in that terrain because its information activity feeds on real news, real state decisions, and real political tensions, even if it later rearranges them within its own narrative.

The technical outage is fleeting. But interpretation… interpretation can last much longer.

Alliances as pressure modules

NoName057(16) states that it has worked with Z-Pentest for a long time, that each party knows its area of responsibility, and that the closeness between both actors is so strong that many perceive them as a single entity.

That response allows alliances to be read as modular architecture. One organization can provide community scale, another technical specialization, another documentary exposure, another propaganda capability, another translation, another audience, another legitimacy inside a sub-ecosystem.

Under iQBlack’s analysis, Z-Pentest reinforces that reading because it acknowledges cooperation with NoName057(16), but protects its narrative autonomy. NoName057(16), by contrast, emphasizes functional closeness and a perception of integration. The combination suggests an ecosystem where cooperation can be real without requiring formal merger.

In this framework, the alliance does not function only as public adherence. It functions as distribution of tasks and capabilities.

State links, tolerance, and functional utility

The relationship between NoName057(16) and Russian state structures requires precision. In the interview, the actor explicitly rejects being part of a state structure and considers the category of “Kremlin hackers” inaccurate. According to its reading, those categories arise from the nature of its activity and the information context around it, but they simplify a more complex reality.

That denial does not close the discussion. An actor’s self-description is not independent proof of autonomy, just as an external categorization does not prove operational direction. The analytical value lies in observing the gray zone between political alignment, tolerance, functional utility, informal coordination, and strategic convergence.

Western official sources have raised possible direct or indirect associations between pro-Russian hacktivist groups and the Russian state. A joint advisory published by NSA, FBI, CISA, and partners mentions NoName057(16), CARR, Z-Pentest, Sector16, and affiliated groups among pro-Russian actors observed in opportunistic operations against critical infrastructure.

iQBlack does not evaluate the interview as proof of state direction. NoName057(16) does not offer such confirmation and, moreover, explicitly denies that reading. However, the interview does show functional compatibility with political pressure objectives aligned with Russian interests: selection of countries according to support for Ukraine, anti-Western narrative, ideological mobilization, attacks on institutional legitimacy, use of news events, and orientation toward economic and social consequences.

In gray zones, the question “who gives the order?” may be too narrow. There are other questions just as important: who benefits? What activity is tolerated? What narratives are reinforced? Which adversaries are worn down? What costs are induced? What official or paraofficial structures find utility in that pressure? Who finances?

Control, informal coordination, tolerance, affinity, and strategic convergence are not synonyms. But they can produce compatible effects. NoName057(16) appears to function as a useful actor for a distributed pressure strategy: it operates below the threshold of conventional military action, mobilizes community, generates noise, consumes defensive resources, and produces narratives that reinforce political positions favorable to Russia.

Conclusion

NoName057(16) is not relevant only because of DDoSia. It is relevant because it turns a participation tool into a political pressure architecture.

The exclusive interview with iQBlack shows an actor that describes itself as community, structure, information apparatus, volunteer network, role-based system, and platform of consequences. And it defines itself as something more durable than a DDoS campaign and more political than a simple disruption tool.

In its logic, the attack does not end when the service returns. It ends, or continues, when the adversary spends, communicates, fears, sanctions, investigates, legislates, or explains itself to its own population.

DDoSia is the interface. Political pressure is the product.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved