Alpha Cyber

NoName057(16) Targets NATO Exposing DDosia / Bobik Infrastructure

Overview NoName057(16) is a pro‑Russian hacktivist group that has publicly targeted NATO‑aligned entities using the DDosia DDoS toolkit and related tooling (and overlaps observed with Bobik infrastructure).

Alpha Cyber Research3 min readupdated 1 Apr 2026
NoName05716-The-Pro-Russian-Hacktivist-Group-Targeting-NATO-2

Overview

NoName057(16) is a pro‑Russian hacktivist group that has publicly targeted NATO‑aligned entities using the DDosia DDoS toolkit and related tooling (and overlaps observed with Bobik infrastructure). This post presents a clean, service‑oriented infrastructure map you can visualize on your site and a concise table of high‑confidence Indicators of Compromise (IOCs) to block and monitor.

This content is defensive in nature, intended to help organizations detect, block, and respond to threats.

Infrastructure map

Use the components below as labeled nodes in a defensive visualization. Each node represents a service role and suggested defensive controls.

1. Delivery & Outreach

Public posting and coordination via Telegram channels and GitHub pages.

Public download pages (GitHub Pages) hosting DDosia artifacts and tooling.

Contact and operator addresses used for coordination.

2. Build / Hosting

Public GitHub repositories hosting DDosia releases and contributors.

FTP subdomains and public hosting used as C2 seed points and file distribution.

3. Command & Control (C2)

Static IPs and domain-based C2 servers used for tasking and data collection.

Overlap with other toolsets (Bobik) suggests reuse or shared hosting.

4. Tooling & Exploitation

DDosia toolkit (DDoS/automation) and PyInstaller‑packed launchers for multiple platforms.

Variants exist for Windows, macOS, and Linux, with multiple versioned builds.

5. Operation & Coordination

Telegram channels and ProtonMail used to coordinate campaigns and announce tooling.

Contributors and forks on GitHub amplify distribution and updates.

6. Targets & Impact

NATO and NATO‑aligned entities, infrastructure providers, and supporting organizations.

Operations include DDoS disruption and potential supporting reconnaissance.

High‑priority IOCs to block

Block these IOCs at DNS, proxy, perimeter firewall and ingest hashes into EDR/AV systems for quarantine and monitoring.

File hashes / binaries

SHA‑256Description
94d7653ff2f4348ff38ff80098682242ece6c407DDosia.py encoded installer
e786c3a60e591dec8f4c15571dbb536a44f861c5DDosia.py encoded installer
c86ae9efcd838d7e0e6d5845908f7d09aa2c09f5December 2022 DDosia PyInstaller
e78ac830ddc7105290af4c1610482a41771d753fDecember 2022 DDosia PyInstaller
09a3b689a5077bd89331acd157ebe621c8714a89July 2022 DDosia PyInstaller
8f0b4a8c8829a9a944b8417e1609812b2a0ebbbddosia_v2_macOSx64 – May 2022
717a034becc125e88dbc85de13e8d650bee907eadosia_v2_macOSarm64 – May 2022
ef7b0c626f55e0b13fb1dcf8f6601068b75dc205dosia_v2_linux_x64 – May 2022
b63ce73842e7662f3d48c5b6f60a47e7e2437a11dosia_v2.0.1.exe – May 2022
5880d25a8fbe14fe7e20d2751c2b963c85c7d8aadosia_v2.0.1 – May 2022
78248539792bfad732c57c4eec814531642e72a0dosia_v2.exe – May 2022
1dfc6f6c35e76239a35bfaf0b5a9ec65f8f50522dosia_win_x64.exe – January 2023

IPs (C2 / infrastructure)

IPNotes
2.57.122[.]82C2 server, overlaps with Bobik findings
2.57.122[.]243C2 server, overlaps with Bobik findings
109.107.181[.]130C2 server, Oct 2022 and earlier; overlaps Bobik findings
77.91.122[.]69C2 server, Dec 2022
31.13.195[.]87C2 server, mid Dec to present

Domains, accounts & channels

IndicatorDescription
tom56gaz6poh13f28[.]myftp.orgC2 / file hosting domain
zig35m48zur14nel40[.]myftp.orgC2 / file hosting domain
05716nnm@proton[.]meOperator email address
hxxps://t[.]me/noname05716Primary Telegram channel (open)
hxxps://t[.]me/nn05716chatSecondary Telegram channel (closed)
hxxps://github[.]com/dddosiaGitHub account hosting DDOSIA projects
dddosia[.]github.ioDDOSIA GitHub Pages download site
hxxps://github[.]com/kintechi341Contributor account to DDOSIA toolkit

Network & Perimeter

  • Block listed IPs and domains at firewall, DNS, and proxy layers.
  • Monitor outbound attempts to myftp.org subdomains and GitHub Pages download URLs.
  • Rate‑limit and alert on unusual traffic patterns from internal hosts to the listed C2s.

Endpoint & Files

  • Ingest all listed SHA‑256 hashes into EDR/AV allow/blocklists and quarantine any matches.
  • Hunt for DDosia artifacts on endpoints and servers; look for PyInstaller executable artifacts and encoded Python installers.
  • Enforce application allow‑listing and block execution from common download locations.

Detection & Hunting

Create SIEM detections for:

  • Network connections to the listed IPs and myftp.org subdomains.
  • Processes spawning networking activity where parent processes are user applications.
  • Downloads from dddosia.github.io or unexpected GitHub Pages resources.
  • Correlate telemetry from EDR, DNS and proxy logs to identify early beaconing.

Operational

  • Monitor the named Telegram channels and GitHub accounts for new tooling announcements and indicators.
  • Share confirmed IOCs with peer organizations and relevant CERTs to assist takedown and broader blocking.

Forensics checklist

If you suspect an incident, collect:

  • Full memory dumps of affected hosts (for in‑memory Python modules and decoded strings).
  • Disk images and copies of PyInstaller executables and any downloaded installers.
  • Network logs, PCAPs, DNS logs and proxy logs showing connections to listed C2s and GitHub Pages.
  • Timeline of process creations, scheduled tasks, and autorun registry entries.

Preserve chain of custody if escalation to law enforcement is expected.

Final notes

The provided IOCs reflect confirmed samples and infrastructure; treat them as high priority for blocking and monitoring.
Overlap with Bobik findings suggests shared infrastructure or opportunistic reuse, monitoring for cross‑tool overlaps can speed detection.
If you’d like, we can format these IOCs as CSV/JSON for ingestion, produce platform‑specific detection rules for your SIEM/EDR, or generate an illustrative infrastructure diagram for publication.

Contact our threat intelligence team to request the full IOC package or a tailored defensive playbook.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]