Alpha Cyber

Tracking NoName057(16): DDoS & Bobik Stealer Infrastructure

The pro-Russian advanced persistent threat (APT) group NoName057(16) continues to escalate its cyber operations, targeting entities that support Ukraine.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Noname057(16)

Pro-Russian Cyber Operations: Infrastructure Behind NoName057(16)

The pro-Russian advanced persistent threat (APT) group NoName057(16) continues to escalate its cyber operations, targeting entities that support Ukraine. Their toolkit includes DDoS attacks paired with the Bobik Stealer, a malware variant designed to harvest credentials and facilitate further exploitation.

This post presents a clear overview of the attacker’s infrastructure using mapping techniques and provides actionable Indicators of Compromise (IOCs) that defenders should immediately block. Our goal is to help organizations better understand the scope of these threats and implement rapid mitigation strategies.

NoName057(16) Infrastructure Map

NoName(057)16 Bobik Stealer Graph

The campaign structure reveals a layered infrastructure designed to persist, pivot, and disrupt. Below is a breakdown of how the infrastructure operates:

1. Initial Delivery

Methods: Malspam, phishing, or malvertising.

Payload: Bobik Stealer, dropped onto victim systems.

2. Bobik Stealer on Endpoint

Harvests credentials, tokens, cookies.

Beacons to hardcoded C2 URLs.

Retrieves updates from dynamic C2 domains.

3. Command & Control (C2) Layer

IP-based C2 servers.

Dynamic DNS-based C2 domains (e.g., .sytes.net, .servehttp.com).

Uses GUID-style URLs for endpoint identification and tasking.

4. Botnet / Aggregation Layer

Infected systems used for:

Credential exfiltration.

DDoS operations against Ukrainian support targets.

5. Operational Infrastructure

Backup C2 servers using dynamic DNS.

Obfuscation through redirectors and load balancing.

Potential monetization or admin panels concealed via additional layers.

6. Targets

Government and private sector supporters of Ukraine.

News media, financial services, and advocacy platforms.

Indicators of Compromise (IOCs)

Organizations should immediately block the following IPs, domains, URLs, and file hashes to prevent infection and reduce attack surface.

VariantHash
Variant 100fead2e42b663522bfd8de53973b52dce737862b4ed6b965edb547364c64572
Variant 101f0c34c6dccbd321a0a91146e8627a8408dd26cb7e7c5164a1d0f2bfeb16316
Variant 12a450e29979be9fffec1459861a40c3b61445a47cd544665e86a44ed4fe719c9
Variant 159f9e06b0bb5ca296df0b224f8c46982d78f47a1d2d8e536a7792d1b0e8242c4
Variant 17256c9d385cbcf130e023380c77feb89e50d206d82ac4f653d2448b88e0499a6
Variant 23d1817e36ad70a58b809e0eb1bd49533397d58bede47cf98fb4bf306c39109df
Variant 255875b324f86f112adfaad5b5f4b5c3a8028e02a9dd6f6372cedd96a26afb81c

Defensive Recommendations

Network Perimeter

  • Block all listed IPs and domains at firewall and DNS levels.
  • Monitor for outbound traffic matching the URLs listed above.
  • Alert on GUID-style URLs (e.g., /[UUID]/update) in HTTP requests.

Endpoint Defense

  • Add all SHA-256 hashes to antivirus and EDR blocklists.
  • Quarantine any devices showing matches to listed IOCs.
  • Reset credentials for affected systems and enforce MFA.

Detection Engineering

Deploy detection rules in SIEM and IDS/IPS for:

Outbound traffic to known C2 IPs/domains.

Processes exhibiting credential dumping or browser scraping behavior.

Need Help?

Our threat intelligence and incident response teams specialize in:

  • Infrastructure threat mapping
  • IOC ingestion and blocking automation
  • Custom detection engineering and playbook development
  • Tabletop exercises simulating real-world attacks like NoName057(16)

If your organization supports Ukrainian causes or may be considered a target, contact us for a tailored threat assessment.

Stay Ahead of the Threat

This campaign shows how state-aligned threat actors are blending data theft and service disruption in increasingly sophisticated ways. Blocking infrastructure and identifying threats early is the key to defense.

We’ll continue monitoring this threat and will publish new IOCs as they become available.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]