Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU Infrastructure — Threadlinqs Intelligence
As of 2026-08-26, Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU Infrastructure is a high-severity threat intel threat attributed to NoName057(16) (Russia, Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-2154 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: NoName057(16) · Russia, Iran · HACKTIVISM
Pro-Russian hacktivist collectives NoName057(16) and Killnet, alongside the pro-Iranian Handala Hack Team (a Void Manticore/MOIS persona), have shifted from opportunistic defacement/DDoS to
Between July 2025 and August 2026, three hacktivist collectives with assessed nation-state alignment intensified operations that Flashpoint and CISA characterize as a component of hybrid warfare rather than opportunistic activism. NoName057(16), assessed to have originated as a covert project of Russia's Centre for the Study and Network Monitoring of the Youth Environment (CISM) operating on behalf of the Kremlin, runs the DDoSia Project: a Go-based, volunteer-operated DDoS client distributed via a Telegram bot (t.me/DDosiabot) that assigns each participant a User Hash and UUID4 Client ID, retrieves AES-GCM-encrypted target lists from a two-tier, rapidly rotated C2 infrastructure (Tier-1 nodes averaging a 9-day lifespan; Tier-2 nodes ACL-restricted to Tier-1 only), and rewards volunteers with an internal currency (dCoin, convertible via TON cryptocurrency to cash) scaled to attack-traffic leaderboards and military-style ranks. Observed DDoSia traffic in 2025-2026 was dominated by nginx_loris application-layer floods (31.5%), SYN floods (17.6%), ACK floods (16.1%), and HTTP GET floods (15.4%), averaging roughly 50 unique daily targets across government, financial, transportation, energy, telecommunications, and NATO-affiliated organizations in 30+ countries. NoName057(16) and allied group ServerKillers ran sustained campaigns against Spain (January-February 2026, ~6,000 entries across 143 domains; a further Spain-focused wave February 16-23, 2026, logged 8,044 attacks across 167 domains and 180 IPs, with Spain absorbing 49.4% of activity) and against Italy during the Milano Cortina Winter Olympics (February 2026). NoName057(16)-affiliated actor PalachPro breached Ukrainian General Staff and territorial recruitment center (TCC) databases, exposing military casualty figures, personal data of soldiers, and next-of-kin contact information. On July 23, 2026, DDoSia participants claimed access to an Ontario water system; independent analysts classified this as an unverified OT-access claim rather than confirmed disruption. International law enforcement responded with Operation Eastwood (July 14-17, 2025), an Europol/Eurojust-coordinated action across the Czech Republic, Finland, France, Germany, Italy, Lithuania, the Netherlands, Poland, Spain, Sweden, Switzerland, and the US that seized 100+ servers, made two arrests (France, Spain), issued seven arrest warrants (six Germany, one Spain), and conducted 24 house searches; NoName057(16) responded by declaring a coordinated retaliation campaign against Spain (#FuckGuardiaCivil). CISA subsequently published advisory AA25-343A (December 9, 2025) formally mapping pro-Russia hacktivist TTPs to MITRE ATT&CK. Killnet, the pro-Russian collective led by KillMilk that dominated the space 2022-2024 with claimed attacks on NATO Special Operations Headquarters, Strategic Airlift Capability, and NATO's restricted communications network, has since fragmented; its Telegram infrastructure was sold off and its remaining influence persists mainly through successor/splinter entities (e.g., Cyber Army Russia Reborn, associated with the Z-Pentest OT-targeting brand) rather than a unified Killnet operation. In parallel, the pro-Iranian Handala Hack Team - publicly a pro-Palestinian hacktivist persona but attributed by the US DOJ and researchers to Void Manticore (TAG-145 / Red Sandstorm / Banished Kitten), a cluster tied to Iran's Ministry of Intelligence and Security (MOIS) Counterterrorism Division - escalated from hack-and-leak operations into destructive attacks. Handala's intrusion chain uses phishing emails carrying malicious PDF attachments disguised as system-recovery utilities and NSIS-packaged/AutoIT (.a3x) droppers such as F5UPDATER.EXE, escalates privileges via a Bring-Your-Own-Vulnerable-Driver technique (ListOpenedFileDrv_32.sys loaded through OpenFileFinder.dll), performs discovery via native Windows commands, and communicates over hardcoded Telegram bot tokens/channel IDs before executing a d
Target sectors: government administration, energy, water, transport, health, finance, manufacturing, administrative, defense
Target regions: Europe, North America, Middle East
Timeline
- NoName057(16) emerges as a pro-Russia hacktivist collective following the invasion of Ukraine, assessed as originating within Russia's CISM youth-monitoring center.
- Handala Hack Team establishes its Telegram presence, later attributed to the Void Manticore (TAG-145) cluster tied to Iran's MOIS.
- Operation Eastwood begins: Europol/Eurojust-coordinated action across 12 countries against NoName057(16), running through July 17, 2025.
- Operation Eastwood concludes: 100+ servers seized, two arrests (France, Spain), seven arrest warrants, 24 house searches; NoName057(16) declares retaliatory campaign against Spain.
- CISA publishes advisory AA25-343A mapping pro-Russia hacktivist opportunistic-attack TTPs to MITRE ATT&CK for US and global critical-infrastructure defenders.
- NoName057(16) targets Italy and the Milano Cortina Winter Olympics with DDoS attacks.
- NoName057(16) runs a Spain-focused DDoSia wave (through Feb 23): 8,044 logged attacks across 167 domains and 180 IPs, ~49.4% of activity targeting Spain.
- Handala launches the 'RedWanted' website, publicly listing individuals identified as Israel supporters.
- Handala claims theft of 851GB of confidential data from members of the Sanzer Hasidic Jewish community.
- Handala claims a destructive wiper attack against Stryker Corporation, compromising its Intune/MDM console and issuing remote-wipe commands against 80,000-200,000 employee devices across 79 countries.
- Handala claims a breach of then-FBI Director Kash Patel's personal email account and publishes over 300 emails.
- Handala claims a breach of California Water Service (Cal Water), publishing a 5GB proof-of-concept dump from billing and RTKBase NTRIP GPS systems across Bakersfield, Visalia, and Chico; independent analysis finds no OT/ICS compromise.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1583.003, T1583.005, T1583.006, T1071.001, T1095, T1571, T1008, T1498.001, T1499.003, T1491.002