Tracking NoName057(16): DDoS & Bobik Stealer Infrastructure
The pro-Russian advanced persistent threat (APT) group NoName057(16) continues to escalate its cyber operations, targeting entities that support Ukraine.

Pro-Russian Cyber Operations: Infrastructure Behind NoName057(16)
The pro-Russian advanced persistent threat (APT) group NoName057(16) continues to escalate its cyber operations, targeting entities that support Ukraine. Their toolkit includes DDoS attacks paired with the Bobik Stealer, a malware variant designed to harvest credentials and facilitate further exploitation.
This post presents a clear overview of the attacker’s infrastructure using mapping techniques and provides actionable Indicators of Compromise (IOCs) that defenders should immediately block. Our goal is to help organizations better understand the scope of these threats and implement rapid mitigation strategies.
NoName057(16) Infrastructure Map

The campaign structure reveals a layered infrastructure designed to persist, pivot, and disrupt. Below is a breakdown of how the infrastructure operates:
1. Initial Delivery
Methods: Malspam, phishing, or malvertising.
Payload: Bobik Stealer, dropped onto victim systems.
2. Bobik Stealer on Endpoint
Harvests credentials, tokens, cookies.
Beacons to hardcoded C2 URLs.
Retrieves updates from dynamic C2 domains.
3. Command & Control (C2) Layer
IP-based C2 servers.
Dynamic DNS-based C2 domains (e.g., .sytes.net, .servehttp.com).
Uses GUID-style URLs for endpoint identification and tasking.
4. Botnet / Aggregation Layer
Infected systems used for:
Credential exfiltration.
DDoS operations against Ukrainian support targets.
5. Operational Infrastructure
Backup C2 servers using dynamic DNS.
Obfuscation through redirectors and load balancing.
Potential monetization or admin panels concealed via additional layers.
6. Targets
Government and private sector supporters of Ukraine.
News media, financial services, and advocacy platforms.
Indicators of Compromise (IOCs)
Organizations should immediately block the following IPs, domains, URLs, and file hashes to prevent infection and reduce attack surface.
| Variant | Hash |
|---|---|
| Variant 1 | 00fead2e42b663522bfd8de53973b52dce737862b4ed6b965edb547364c64572 |
| Variant 1 | 01f0c34c6dccbd321a0a91146e8627a8408dd26cb7e7c5164a1d0f2bfeb16316 |
| Variant 1 | 2a450e29979be9fffec1459861a40c3b61445a47cd544665e86a44ed4fe719c9 |
| Variant 1 | 59f9e06b0bb5ca296df0b224f8c46982d78f47a1d2d8e536a7792d1b0e8242c4 |
| Variant 1 | 7256c9d385cbcf130e023380c77feb89e50d206d82ac4f653d2448b88e0499a6 |
| Variant 2 | 3d1817e36ad70a58b809e0eb1bd49533397d58bede47cf98fb4bf306c39109df |
| Variant 2 | 55875b324f86f112adfaad5b5f4b5c3a8028e02a9dd6f6372cedd96a26afb81c |
Defensive Recommendations
Network Perimeter
- Block all listed IPs and domains at firewall and DNS levels.
- Monitor for outbound traffic matching the URLs listed above.
- Alert on GUID-style URLs (e.g., /[UUID]/update) in HTTP requests.
Endpoint Defense
- Add all SHA-256 hashes to antivirus and EDR blocklists.
- Quarantine any devices showing matches to listed IOCs.
- Reset credentials for affected systems and enforce MFA.
Detection Engineering
Deploy detection rules in SIEM and IDS/IPS for:
Outbound traffic to known C2 IPs/domains.
Processes exhibiting credential dumping or browser scraping behavior.
Need Help?
Our threat intelligence and incident response teams specialize in:
- Infrastructure threat mapping
- IOC ingestion and blocking automation
- Custom detection engineering and playbook development
- Tabletop exercises simulating real-world attacks like NoName057(16)
If your organization supports Ukrainian causes or may be considered a target, contact us for a tailored threat assessment.
Stay Ahead of the Threat
This campaign shows how state-aligned threat actors are blending data theft and service disruption in increasingly sophisticated ways. Blocking infrastructure and identifying threats early is the key to defense.
We’ll continue monitoring this threat and will publish new IOCs as they become available.



