Hackers launch large-scale DDoS attacks to disrupt and make online services inaccessible, driven by motives like revenge or protest, flooding targets with massive amounts of traffic to disable websites.
Recently the cybersecurity researchers at Sekoia identified that the Russian hacker group “NoName057(16)” has been actively planning to conduct massive DDoS attacks.
Since the Ukraine conflict began the nationalist hacktivist groups notably the “NoName057(16),” have risen and are found to be launching Project DDoSia.
They target pro-Ukraine entities, mostly NATO members. Sekoia actively tracks its C2 infrastructure, automated for target collection and real-time monitoring.
Technical Analysis
The Project DDoSia’s Telegram channel recently on 11 November 2023, dropped a surprise update by expanding processor support to 32-bit and adding FreeBSD compatibility.
While the prior versions had AMD64, ARM, and ARM64 covered. Main ZIP has two folders (d_eu, d_ru) for location-based execution. Executing shows a warning, suggesting VPN for users in Russia.
Warning message (Source – Sekoia)
No VPN mandate in Russia hints at the NoName057(16) group’s possible ties with the state, despite no public acknowledgment.
The latest version alters encryption for user-C2 server data exchange. The operating diagram for DDoSia project initiation is provided as a reminder.
Attack Chain (Source – Sekoia)
The latest update adds encryption for data in HTTP POST requests which is a new feature absent in previous versions. C value, a GUID identifying the user’s machine, is encrypted and extracted from \HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid on Windows.
The U value is from the client_id.txt file via DDoSia’s Telegram Bot. While besides this the JSON table “inf” tracks seven elements under Windows, likely for statistical analysis, enhancing transmission sophistication.
The latest software version improved data transmission, but DDoSia admins changed the C2 servers frequently in 2024, facing stability challenges.
NoName057(16) updated the Telegram channel with each server config change which requires users to download and install for continued attacks.
Besides this, DDoSia lacks automated IP address change despite frequent C2 changes. Infrastructure interruptions didn’t hamper NoName057(16) group’s daily attacks. DDoSia likely uses its servers for active participation in attacks.
Top Countries Targeted
Here below we have mentioned all the top targeted countries:-
- Ukraine
- Finland
- Italy
- Spain
- Germany
- Lithuania
- France
- Poland
- Switzerland
- Romania
- Netherlands
- Estonia
- Sweden
- Latvia
- Greece
- United Kingdom
- Czech Republic
- Belgium
Top Sectors Targeted
Here below we have mentioned all the sectors that are targeted most:-
- Government
- Banking
- Transportation
- Technology
- Energy
- Defence
The DDoSia’s Telegram project nears 20,000 users, while NoName057(16) channels surpass 60,000, doubling since 2023.
The growth represents a politically and economically motivated community. NoName057(16) collaborates with hacktivist groups, forming alliances against Italian infrastructures.
Despite DDoSia’s ever-changing infrastructure it consistently claims attacks. Not only that even it also provides daily software updates and a 2024 version with enhanced encryption.