Back to blog

Blog Post

International Operation Disrupts Pro-Russian Cybercriminal Gang NoName057(16)

Share on social

Jul 25, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
International Operation Disrupts Pro-Russian Cybercriminal Gang NoName057(16)

[NoName Gang Disruption]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

Between July 14 - 17, a co-ordinated international law enforcement operation effort led by Europol and Eurojust, targeted and disrupted the pro-Russian cybercrime network NoName057(16). Authorities from 12 core countries, including the US, Germany, France, and the Netherlands, conducted actions against the group’s infrastructure and members, with support from seven additional countries and agencies such as ENISA, ShadowServer, and abuse.ch.

Key results:

  • 100+ servers dismantled worldwide.
  • Major part of NoName057(16)’s infrastructure taken offline.
  • Seven arrest warrants issues (Six by Germany, one by Spain).
  • Two arrests in France and Spain.
  • 24 property searches across Europe.
  • 13 individuals questioned.
  • 1000+ supporters notified, including 15 administrators.

Germany named six Russian nationals as wanted suspects, two of whom are considered ringleaders. Five profiles were added to the EU Most Wanted List.

NoName057(16) who was an ideologically motivated group supporting Russia’s war on Ukraine, has orchestrated waves of DDoS attacks across NATO countries. Victims have included Swedish authorities, Swiss government events, the recent NATO summit in the Netherlands. The group used platforms like DDoSia to simplify attacks, recruited via chat apps and forums, and incentivized involvement with cryptocurrency rewards, badges, and leaderboards.

Europol led the operation and technical support, including cryptocurrency tracing and digital forensics. Eurojust enabled cross-boarder judicial co-operation, taking out multiple European Investigation Orders. Over 30 co-ordination meetings and two operational sprints ensured alignment between the jurisdictions.

For more information on hacktivist groups (including a mention of NoName057(16)!) listen to this episode of The Dark Dive Podcast.

Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient