NoName057(16) Targets NATO Exposing DDosia / Bobik Infrastructure
Overview NoName057(16) is a pro‑Russian hacktivist group that has publicly targeted NATO‑aligned entities using the DDosia DDoS toolkit and related tooling (and overlaps observed with Bobik infrastructure).

Overview
NoName057(16) is a pro‑Russian hacktivist group that has publicly targeted NATO‑aligned entities using the DDosia DDoS toolkit and related tooling (and overlaps observed with Bobik infrastructure). This post presents a clean, service‑oriented infrastructure map you can visualize on your site and a concise table of high‑confidence Indicators of Compromise (IOCs) to block and monitor.
This content is defensive in nature, intended to help organizations detect, block, and respond to threats.
Infrastructure map
Use the components below as labeled nodes in a defensive visualization. Each node represents a service role and suggested defensive controls.
1. Delivery & Outreach
Public posting and coordination via Telegram channels and GitHub pages.
Public download pages (GitHub Pages) hosting DDosia artifacts and tooling.
Contact and operator addresses used for coordination.
2. Build / Hosting
Public GitHub repositories hosting DDosia releases and contributors.
FTP subdomains and public hosting used as C2 seed points and file distribution.
3. Command & Control (C2)
Static IPs and domain-based C2 servers used for tasking and data collection.
Overlap with other toolsets (Bobik) suggests reuse or shared hosting.
4. Tooling & Exploitation
DDosia toolkit (DDoS/automation) and PyInstaller‑packed launchers for multiple platforms.
Variants exist for Windows, macOS, and Linux, with multiple versioned builds.
5. Operation & Coordination
Telegram channels and ProtonMail used to coordinate campaigns and announce tooling.
Contributors and forks on GitHub amplify distribution and updates.
6. Targets & Impact
NATO and NATO‑aligned entities, infrastructure providers, and supporting organizations.
Operations include DDoS disruption and potential supporting reconnaissance.
High‑priority IOCs to block
Block these IOCs at DNS, proxy, perimeter firewall and ingest hashes into EDR/AV systems for quarantine and monitoring.
File hashes / binaries
| SHA‑256 | Description |
|---|---|
94d7653ff2f4348ff38ff80098682242ece6c407 | DDosia.py encoded installer |
e786c3a60e591dec8f4c15571dbb536a44f861c5 | DDosia.py encoded installer |
c86ae9efcd838d7e0e6d5845908f7d09aa2c09f5 | December 2022 DDosia PyInstaller |
e78ac830ddc7105290af4c1610482a41771d753f | December 2022 DDosia PyInstaller |
09a3b689a5077bd89331acd157ebe621c8714a89 | July 2022 DDosia PyInstaller |
8f0b4a8c8829a9a944b8417e1609812b2a0ebbbd | dosia_v2_macOSx64 – May 2022 |
717a034becc125e88dbc85de13e8d650bee907ea | dosia_v2_macOSarm64 – May 2022 |
ef7b0c626f55e0b13fb1dcf8f6601068b75dc205 | dosia_v2_linux_x64 – May 2022 |
b63ce73842e7662f3d48c5b6f60a47e7e2437a11 | dosia_v2.0.1.exe – May 2022 |
5880d25a8fbe14fe7e20d2751c2b963c85c7d8aa | dosia_v2.0.1 – May 2022 |
78248539792bfad732c57c4eec814531642e72a0 | dosia_v2.exe – May 2022 |
1dfc6f6c35e76239a35bfaf0b5a9ec65f8f50522 | dosia_win_x64.exe – January 2023 |
IPs (C2 / infrastructure)
| IP | Notes |
|---|---|
2.57.122[.]82 | C2 server, overlaps with Bobik findings |
2.57.122[.]243 | C2 server, overlaps with Bobik findings |
109.107.181[.]130 | C2 server, Oct 2022 and earlier; overlaps Bobik findings |
77.91.122[.]69 | C2 server, Dec 2022 |
31.13.195[.]87 | C2 server, mid Dec to present |
Domains, accounts & channels
| Indicator | Description |
|---|---|
tom56gaz6poh13f28[.]myftp.org | C2 / file hosting domain |
zig35m48zur14nel40[.]myftp.org | C2 / file hosting domain |
05716nnm@proton[.]me | Operator email address |
hxxps://t[.]me/noname05716 | Primary Telegram channel (open) |
hxxps://t[.]me/nn05716chat | Secondary Telegram channel (closed) |
hxxps://github[.]com/dddosia | GitHub account hosting DDOSIA projects |
dddosia[.]github.io | DDOSIA GitHub Pages download site |
hxxps://github[.]com/kintechi341 | Contributor account to DDOSIA toolkit |
Recommended immediate actions
Network & Perimeter
- Block listed IPs and domains at firewall, DNS, and proxy layers.
- Monitor outbound attempts to
myftp.orgsubdomains and GitHub Pages download URLs. - Rate‑limit and alert on unusual traffic patterns from internal hosts to the listed C2s.
Endpoint & Files
- Ingest all listed SHA‑256 hashes into EDR/AV allow/blocklists and quarantine any matches.
- Hunt for DDosia artifacts on endpoints and servers; look for PyInstaller executable artifacts and encoded Python installers.
- Enforce application allow‑listing and block execution from common download locations.
Detection & Hunting
Create SIEM detections for:
- Network connections to the listed IPs and
myftp.orgsubdomains. - Processes spawning networking activity where parent processes are user applications.
- Downloads from
dddosia.github.ioor unexpected GitHub Pages resources. - Correlate telemetry from EDR, DNS and proxy logs to identify early beaconing.
Operational
- Monitor the named Telegram channels and GitHub accounts for new tooling announcements and indicators.
- Share confirmed IOCs with peer organizations and relevant CERTs to assist takedown and broader blocking.
Forensics checklist
If you suspect an incident, collect:
- Full memory dumps of affected hosts (for in‑memory Python modules and decoded strings).
- Disk images and copies of PyInstaller executables and any downloaded installers.
- Network logs, PCAPs, DNS logs and proxy logs showing connections to listed C2s and GitHub Pages.
- Timeline of process creations, scheduled tasks, and autorun registry entries.
Preserve chain of custody if escalation to law enforcement is expected.
Final notes
The provided IOCs reflect confirmed samples and infrastructure; treat them as high priority for blocking and monitoring.
Overlap with Bobik findings suggests shared infrastructure or opportunistic reuse, monitoring for cross‑tool overlaps can speed detection.
If you’d like, we can format these IOCs as CSV/JSON for ingestion, produce platform‑specific detection rules for your SIEM/EDR, or generate an illustrative infrastructure diagram for publication.
Contact our threat intelligence team to request the full IOC package or a tailored defensive playbook.



