
On July 17, 2026, iQBlack conducted a direct interview with NoName057(16), a pro-Russian hacktivist actor publicly associated with DDoSia, denial-of-service campaigns, volunteer mobilization, information pressure, and operations directed against Ukraine and countries that support Ukraine. Days later, the interview was complemented with new questions aimed at clarifying how the actor describes its information dimension, its intelligence tasks, and its position regarding the categories used by Western governments and analysts.
Based on those responses, iQBlack developed an analytical piece titled NoName057(16): from DDoSia to a political pressure infrastructure. That analysis was not intended to reproduce the interview in a linear way, but to interpret what the responses revealed about how NoName057(16) attempts to project itself beyond technical disruption: as an ideologized community, an information apparatus, a volunteer network, a role-based structure, a political pressure platform, and an actor capable of turning news events, state responses, and law enforcement operations into narrative fuel.
iQBlack publishes intelligence and threat analysis from another perspective. For that reason, this publication serves a different purpose. Here, the full interview is presented as primary material, as a direct source of the actor’s self-description, and in its original version. The objective is to allow researchers, analysts, journalists, security teams, and specialized readers to access the actor’s responses directly and compare them with the analytical reading published by iQBlack or develop their own interpretations.
Editorial note on the literal publication
NoName057(16)’s responses are presented literally, with minimal formatting normalization to improve readability, and do not imply that iQBlack validates every statement made by the actor. In some passages, the actor uses propagandistic, derogatory, or politically hostile language to refer to governments, analysts, media outlets, and state actors. iQBlack decided to preserve those expressions because they are part of the interview’s documentary value and allow readers to observe how NoName057(16) interprets its own activity, its adversaries, and the ecosystem in which it operates.
The actor’s voice as a starting point
What follows is the direct voice of NoName057(16), without an interleaved reading by iQBlack between questions and answers.
- You often define yourselves as an idea sustained by people, not merely as infrastructure, tools, or services. In practical terms, what does that mean for the operational continuity of NoName057(16)?
We believe that we are not merely a hacker collective; we are far broader and more versatile than that. We are capable of doing things that are not typically associated with hackers in the traditional sense—we shape public opinion.
Publications about our activities convey a clear message to all of Russia's enemies: if you support what we describe as the terrorist regime in Ukraine, you will face consequences. Your economy will suffer enormous losses, and your citizens will engage in acts of civil disobedience against your government, as we claim is already happening in many Western countries as a result of our activities.
Infrastructure can be defended, and cyberattacks can be countered. But resisting people is far more difficult - especially when they are driven by deeply held convictions.
- After Operation Eastwood, what actually changed inside the NoName057(16) ecosystem: the organization, internal security, relationship with volunteers, infrastructure, or only the public narrative?
First of all, both the number and the range of our attacks have increased. For example, we have begun targeting industrial systems. In other words, we have inflicted even greater damage on the economies of countries that are unfriendly toward Russia.
Some of our processes have changed from a technical standpoint, but that is not the main point. The main point is that Operation Eastwood was a failure, and Europol ended up making a complete fool of itself - a disgrace it will never be able to erase.
In addition, the German police attempted to infiltrate our group by using a spy named Angelique Geray. Yesterday, we published an investigation detailing how we kept her misled for six months: https://telegra.ph/Angelique-Gerays-Botched-Blitzkrieg-How-NoName05716-Defeated-German-Intelligence-on-the-Anniversary-of-Operation-Eastwood-07-16
- Many analysts describe you primarily as a DDoS-oriented actor. Is that description still sufficient, or do you consider NoName057(16) to operate today as a broader platform for cyber and political pressure?
DDoS is just one of the tools we use to achieve our objectives. We have evolved into an entire cyber empire, with volunteers in many countries who possess a wide range of skills and expertise.
- When selecting targets, what matters most: the symbolic value of the country or institution, the real possibility of generating unavailability, the political timing of the moment, or the ability to mobilize the community?
We devote a great deal of time to intelligence gathering and analysis. Naturally, the choice of which country to target is influenced by current geopolitical developments, the actions of that country's authorities - particularly with regard to supporting what we describe as the terrorist regime in Ukraine - as well as many other factors.
The selection of specific targets depends on the overall attack strategy. Perhaps the primary consideration, however, is the extent of the impact we expect to achieve by targeting a particular objective. This includes not only economic damage, but also reputational damage, as well as the broader societal consequences that an attack may trigger.
- How do you internally evaluate whether an operation was successful? Is the duration of unavailability more important, or the victim's reaction, media coverage, institutional response, or the effect on the morale of your supporters?
We assess our success using a variety of criteria. It is always important to evaluate results in both the short term and the long term. We also consider how a particular operation has affected the targeted country as well as the broader international environment.
Overall, however, we believe our activities are most successful over the long term. For several years now, whenever something stops working in Europe, the default assumption has been that the hackers from NoName057(16) are responsible. We see that as a form of recognition of our achievements.
The media often publish false information about us or are not allowed to report on us at all. They believe that covering us would amount to giving us publicity. We do not need publicity - we are the most active pro-Russian hacking group.
For example, we frightened the Danish authorities so much with our attacks that, during the election period, they purchased flashlights, electric generators, and emergency supplies because they feared that the "evil Russian hackers" from NoName057(16) might simply cut off their electricity.
The enormous sums that European governments now allocate to cybersecurity also speak for themselves. They are spending billions of euros and creating entire bureaucratic structures that, in our view, will simply waste those funds, while our successful attacks will continue. Those resources could otherwise have been used to support what we describe as Ukrainian terrorists, but because of us, they no longer can.
Here are several examples that we believe support this assessment:
Spain allocated €1.157 billion to strengthen its cyber defenses and establish a new cybersecurity structure.
Poland introduced personal accountability for organizational leaders regarding cybersecurity.
In Italy, following the large-scale cyberattacks during the 2026 Winter Olympics, the agency created under Bruno Frattasi failed to prevent subsequent attacks, and Frattasi resigned.
Losses to the German economy from cyberattacks in certain years - including 2023 and 2025 - have been estimated at approximately €206–223 billion.
- Your ecosystem includes core operators, volunteers, allies, dissemination channels, and occasional participants. Without mentioning personal identities, what types of roles actually exist inside NoName057(16)?
We have many different teams, including analysts, intelligence specialists, content creators, developers, other subject-matter specialists, our volunteers, and our allies.
- Are there different levels of trust or access within the community? For example: public sympathizers, technical participants, coordinators, infrastructure operators, target validators, or communication managers.
Yes, of course. We have different access levels and a role-based structure. In that respect, we could probably be compared to a private intelligence company - except that our range of capabilities and expertise is far broader.
- What type of participant is most valuable to NoName057(16) today: someone with technical capability, access to infrastructure, knowledge of targets, language skills, media capability, or persistence over time?
Every person is important to us. The more people we have, the stronger we become. We have a role for everyone, based on each volunteer's individual skills and expertise.
- From the outside, people often speak about "volunteers" and "community," but also about incentives and coordination. How would you describe the balance between ideological participation, operational discipline, and reward?
The overwhelming majority of our volunteers are motivated by ideology; for them, their beliefs take precedence over financial rewards. At the same time, we have never been reluctant to recognize and reward the contributions of our people, and we have helped some of them through various personal circumstances when they needed support.
- What criteria must another group meet to be considered a real ally of NoName057(16), rather than simply a friendly channel, amplifier, or temporary participant in an operation?
This group must share the values outlined in the NoName057(16) Manifesto and be pro-Russian, as well as, naturally, anti-Ukrainian and anti-Western.
- In joint operations with groups such as Z-Pentest Alliance, is there a division of functions between availability disruption, intrusion, document exposure, propaganda, and target selection, or does each actor operate independently?
Yes, such cooperation exists. We have been working with Z-pentest for a long time, and each side knows its area of responsibility. We have become so closely connected with them that many people perceive us as a single entity.
- What do Western analysts usually misunderstand about the relationship between NoName057(16), DDoSia, volunteers, and allied groups?
To begin with, many Western analysts are biased. Their objective is not to tell the truth; their objective is to discredit us and claim that our attacks allegedly cause no damage.
But if that were actually the case, Europol, the FBI, and hundreds of intelligence agents from Western countries would not be pursuing us. You have to agree.
- When an authority, media outlet, or company attributes an operation to NoName057(16), how do you decide whether to respond, ignore it, ridicule it, or turn that attribution into your own propaganda?
It depends on the specific situation. We use the vast majority of newsworthy events in our information activities. We may ridicule someone when it is genuinely funny or absurd.
- You described NoName057(16) as more than a hacker collective and as a structure capable of shaping public opinion. Without discussing active operations or technical procedures, how is that information dimension organized: audience analysis, narrative selection, political timing, translations, media monitoring, allied channels, or measurement of public reaction?
We constantly analyze the information agenda, follow events taking place around the world, as well as statements and decisions made by different states. To a large extent, it is the agenda of the day or the week that determines where attention will be focused. For example, if a country decides to provide financial aid or supply weapons to Ukraine, that country may become the center of attention. At the same time, the situation can change quickly depending on how events evolve, the emergence of new information, or changes in the media context.
In other words, target selection is not random and is not carried out solely on someone’s whim. It is always conditioned by the current sociopolitical agenda and by those events that have the greatest public resonance at that moment.
- In the interview, you mentioned analysts, intelligence specialists, content creators, developers, volunteers, and allies. Inside NoName057(16), what separates an “intelligence” task from a purely technical or propaganda-related task? What type of information do you consider most valuable before choosing a country, sector, or target category?
The intelligence direction is primarily responsible for collecting, analyzing, and systematizing information. Its main task is to form the most complete possible picture of what is happening, in order to understand which events are most important at any given moment. This involves analyzing open sources, media publications, official statements, political decisions, and the general information agenda.
Unlike the technical direction, which is responsible for executing the assigned tasks, or the information direction, which handles publications and the dissemination of results, analysts focus specifically on searching for and evaluating information. The most valuable information is the kind that makes it possible to understand the relevance of a specific event, its public and political resonance, as well as to determine which countries or sectors are at the center of attention at a given moment. Subsequent decisions are made precisely on the basis of this analysis.
- Western governments and analysts often use different categories to describe pro-Russian hacktivist groups: state-directed actor, state-tolerated actor, proxy, ideological ally, volunteer ecosystem, or independent actor. Without naming people, channels, or sensitive links, which of those categories do you consider inaccurate, and how would you describe the real boundary between political alignment with Russia, informal coordination, institutional tolerance, and operational direction?
There have been numerous attempts to link our group to all kinds of structures. During this entire time, we have been attributed to practically every possible organization, so we are already quite tired of having to explain the same thing over and over again. We are not a state structure, even though statements of this kind regularly appear in the media and in various publications.
The widespread opinion that we are supposedly the “Kremlin hackers” does not correspond to reality. Such conclusions are probably reached because of the nature of our activity and the information context surrounding it. However, these kinds of labels are more of an attempt to simplify the picture of what is happening, rather than a reflection of the real situation.
Editorial closing
This interview is published as a documentary record of a direct interaction with NoName057(16). Its reading allows the actor’s self-description to be contrasted with its public activity, with the editorial analysis developed by iQBlack, and with the evolution of a pro-Russian hacktivist ecosystem where DDoSia, volunteer mobilization, information pressure, functional alliances, and law enforcement operations also form part of the contested terrain.
The value of this publication does not lie in assuming that every statement made by the actor is verified, but in preserving its voice as primary material. Throughout the interview, NoName057(16) describes its own view of DDoSia, Operation Eastwood, its ties with Z-Pentest Alliance, its target selection criteria, the information dimension of its activity, and its rejection of categories such as “Kremlin hackers.”
This publication also reflects part of the work iQBlack develops within [Cyber]Crime Characterization for Intelligence (3C-INT), where actors such as NoName057(16) are observed, characterized, and linked within a broader ecosystem of relationships, public activity, cooperation between actors, operational propaganda, and intelligence signals. The full content of that characterization remains reserved for private and contractual workflows; here, only editorial material suitable for public consultation is published.
Explore 3C-INT
Expand actor, campaign and operational-link tracking through a structured intelligence layer.
Get new publications
Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.