Ongoing Cyber Operations by Pro-Russian Hacktivist Group NoName057(16) Target UK
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The National Cyber Security Centre (NCSC) has highlighted ongoing cyber operations by pro-Russian hacktivist group NoName057(16), which has been active since March 2022. This group specifically targets government and private sector entities across NATO member states and other European countries perceived as hostile to Russian interests. Notably, UK local government bodies have frequently been victims of NoName057(16), with attacks primarily manifesting as distributed denial-of-service (DDoS) activities.
NoName057(16) coordinates its operations mainly through Telegram channels, where it claims responsibility for its attacks. The group has also utilized GitHub and other code hosting platforms to distribute its proprietary DDoSia tool, sharing tactics and techniques with supporters. In December 2025, the NCSC co-signed an advisory warning about the group’s activities, underscoring the global nature of these cyber operations.
In response to the escalating threat, the NCSC is urging organizations to reassess their defensive strategies and enhance operational resilience, particularly focusing on strengthening protections against denial-of-service attacks. The UK government has announced a new Cyber Action Plan, allocating £210 million (approximately $283 million) to improve the security and resilience of online public services.
Dr. Ric Derbyshire, a Principal Security Researcher at Orange Cyberdefense, expressed concern over the rise of escalatory hacktivism, where groups align with state narratives and contribute to hybrid warfare efforts. He predicts an increase in both the frequency and severity of attacks on critical infrastructure, with potential physical impacts.
Organizations must prepare for a diversification of attacks from hacktivist groups that emphasize overt disruption, as defenders currently face threats from both cybercriminals and state-driven activities. The NCSC’s warning highlights the urgent need for enhanced cybersecurity measures across various sectors.
Key Takeaways
- Review and strengthen your organization’s defenses against DDoS attacks to mitigate risks from groups like NoName057(16).
- Monitor your online services for unusual activity that may indicate a DDoS attack in progress.
- Stay informed about the latest cybersecurity threats and advisories from the NCSC and other relevant authorities.
- Consider investing in cybersecurity training for staff to recognize and respond to potential cyber threats.
- Evaluate your current cybersecurity posture and make necessary adjustments to enhance resilience against hybrid warfare tactics.
Key Terms & Concepts
- NoName057(16): In this article, NoName057(16) refers to a pro-Russian hacktivist group that conducts cyber operations against organizations in the UK and abroad.
- DDoS: DDoS stands for Distributed Denial of Service, a type of cyber attack that overwhelms a target’s online services with traffic to disrupt access.
- NCSC: The NCSC, or National Cyber Security Centre, is a UK government agency responsible for providing guidance and support on cybersecurity issues.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.