Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU Infrastructure

Hacktivism as Hybrid Warfare (TL-2026-2154), also tracked as DDoSia Project, is a high-severity tracked intrusion set, first published 2026-08-26. It is attributed to NoName057(16) (Russia, Iran) with high confidence, affects California Water Service (Cal Water) Customer billing database and, maps to 15 MITRE ATT&CK techniques (T1008, T1027, T1059.010), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-2154

Threat ID
TL-2026-2154
Also known as
DDoSia Project, Handala Popular Resistance Front (HPRF)
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-08-26
Last reviewed
2026-08-26
Attribution
NoName057(16)
Attribution confidence
HIGH
Nation-state nexus
Russia, Iran
Motivation
HACKTIVISM
Target sectors
government administration, energy, water, transport, health, finance, manufacturing, administrative, defense
Target regions
Europe, North America, Middle East
Detection rules
9
Indicators of compromise
21

Malware and tooling in Hacktivism as Hybrid Warfare

Malware and tooling: nginx_loris, DDoSia, F5UPDATER.EXE

Pro-Russian hacktivist collectives NoName057(16) and Killnet, alongside the pro-Iranian Handala Hack Team (a Void Manticore/MOIS persona), have shifted from opportunistic defacement/DDoS to disciplined, gamified, state-aligned campaigns. NoName057(16)'s DDoSia Project uses military-style ranks and cryptocurrency (dCoin) rewards to crowdsource DDoS attacks that have disrupted energy, water, transportation, and administrative infrastructure across 30+ NATO/EU nations, while Handala has escalated from hack-and-leak into destructive wiper attacks and physical-threat coordination.

How Hacktivism as Hybrid Warfare works

Between July 2025 and August 2026, three hacktivist collectives with assessed nation-state alignment intensified operations that Flashpoint and CISA characterize as a component of hybrid warfare rather than opportunistic activism. NoName057(16), assessed to have originated as a covert project of Russia's Centre for the Study and Network Monitoring of the Youth Environment (CISM) operating on behalf of the Kremlin, runs the DDoSia Project: a Go-based, volunteer-operated DDoS client distributed via a Telegram bot (t.me/DDosiabot) that assigns each participant a User Hash and UUID4 Client ID, retrieves AES-GCM-encrypted target lists from a two-tier, rapidly rotated C2 infrastructure (Tier-1 nodes averaging a 9-day lifespan; Tier-2 nodes ACL-restricted to Tier-1 only), and rewards volunteers with an internal currency (dCoin, convertible via TON cryptocurrency to cash) scaled to attack-traffic leaderboards and military-style ranks. Observed DDoSia traffic in 2025-2026 was dominated by nginx_loris application-layer floods (31.5%), SYN floods (17.6%), ACK floods (16.1%), and HTTP GET floods (15.4%), averaging roughly 50 unique daily targets across government, financial, transportation, energy, telecommunications, and NATO-affiliated organizations in 30+ countries. NoName057(16) and allied group ServerKillers ran sustained campaigns against Spain (January-February 2026, ~6,000 entries across 143 domains; a further Spain-focused wave February 16-23, 2026, logged 8,044 attacks across 167 domains and 180 IPs, with Spain absorbing 49.4% of activity) and against Italy during the Milano Cortina Winter Olympics (February 2026). NoName057(16)-affiliated actor PalachPro breached Ukrainian General Staff and territorial recruitment center (TCC) databases, exposing military casualty figures, personal data of soldiers, and next-of-kin contact information. On July 23, 2026, DDoSia participants claimed access to an Ontario water system; independent analysts classified this as an unverified OT-access claim rather than confirmed disruption. International law enforcement responded with Operation Eastwood (July 14-17, 2025), an Europol/Eurojust-coordinated action across the Czech Republic, Finland, France, Germany, Italy, Lithuania, the Netherlands, Poland, Spain, Sweden, Switzerland, and the US that seized 100+ servers, made two arrests (France, Spain), issued seven arrest warrants (six Germany, one Spain), and conducted 24 house searches; NoName057(16) responded by declaring a coordinated retaliation campaign against Spain (#FuckGuardiaCivil). CISA subsequently published advisory AA25-343A (December 9, 2025) formally mapping pro-Russia hacktivist TTPs to MITRE ATT&CK. Killnet, the pro-Russian collective led by KillMilk that dominated the space 2022-2024 with claimed attacks on NATO Special Operations Headquarters, Strategic Airlift Capability, and NATO's restricted communications network, has since fragmented; its Telegram infrastructure was sold off and its remaining influence persists mainly through successor/splinter entities (e.g., Cyber Army Russia Reborn, associated with the Z-Pentest OT-targeting brand) rather than a unified Killnet operation. In parallel, the pro-Iranian Handala Hack Team - publicly a pro-Palestinian hacktivist persona but attributed by the US DOJ and researchers to Void Manticore (TAG-145 / Red Sandstorm / Banished Kitten), a cluster tied to Iran's Ministry of Intelligence and Security (MOIS) Counterterrorism Division - escalated from hack-and-leak operations into destructive attacks. Handala's intrusion chain uses phishing emails carrying malicious PDF attachments disguised as system-recovery utilities and NSIS-packaged/AutoIT (.a3x) droppers such as F5UPDATER.EXE, escalates privileges via a Bring-Your-Own-Vulnerable-Driver technique (ListOpenedFileDrv_32.sys loaded through OpenFileFinder.dll), performs discovery via native Windows commands, and communicates over hardcoded Telegram bot tokens/channel IDs before executing a disk-wipe payload (4,096-byte overwrites on Windows; Linux variants using parted/mkfs to reformat drives as XFS). Confirmed/claimed 2026 Handala operations include the March 1 launch of the "RedWanted" doxxing site naming Israel supporters, the March 6 claimed theft of 851GB from the Sanzer Hasidic Jewish community, the March 11-12 wiper attack against medical device manufacturer Stryker Corporation that triggered remote-wipe commands against 80,000-200,000 Intune/MDM-managed devices across 79 countries, the March 27 breach and publication of 300+ emails from then-FBI Director Kash Patel's personal account, and a June 11-12 claimed breach of California Water Service (Cal Water) affecting Bakersfield, Visalia, and Chico customers - independent analysis confirmed exposure of a billing database and an RTKBase NTRIP GPS-correction server (no OT/ICS compromise, no service disruption), with Handala stating it retaliated for US strikes on Iranian water infrastructure and asserting - without demonstrating - the ability to cause disruption. Handala's parent ecosystem also runs Telegram-based proxy-recruitment and psychological-operations infrastructure (VIPEmployment bots soliciting attacks/espionage, MOISIRAN publishing surveillance footage of Israeli personnel, and the Handala Popular Resistance Front (HPRF) claiming vehicle-arson attacks against Israeli law enforcement), extending the campaign beyond cyber into coordinated physical and influence operations. Flashpoint's August 26, 2026 report frames this convergence - gamified crowdsourcing, real-world critical-infrastructure disruption, and physical/psychological operations run by state-aligned hacktivist brands - as a maturing hybrid-warfare capability rather than isolated activist activity.

MITRE ATT&CK techniques used in TL-2026-2154

Command and Control

T1008 Fallback Channels; T1071.001 Application Layer Protocol: Web Protocols; T1095 Non-Application Layer Protocol; T1571 Non-Standard Port

Defense Evasion

T1027 Obfuscated Files or Information

Execution

T1059.010 Command and Scripting Interpreter: AutoHotKey & AutoIT

Discovery

T1082 System Information Discovery

Impact

T1491.002 Defacement: External Defacement; T1498.001 Network Denial of Service: Direct Network Flood; T1499.003 Endpoint Denial of Service: Application Exhaustion Flood; T1561.001 Disk Wipe: Disk Content Wipe

Initial Access

T1566.001 Phishing: Spearphishing Attachment

Resource Development

T1583.003 Acquire Infrastructure: Virtual Private Server; T1583.005 Acquire Infrastructure: Botnet; T1583.006 Acquire Infrastructure: Web Services

Affected products and versions in Hacktivism as Hybrid Warfare

  • California Water Service (Cal Water) — Customer billing database and RTKBase NTRIP GPS-correction caster network (Bakersfield, Visalia, Chico districts)
    Vulnerable versions: IT-adjacent billing and field-GPS systems
  • Stryker Corporation — Microsoft Intune / mobile device management (MDM) console
    Vulnerable versions: MDM-enrolled employee endpoints, 79 countries
  • Ukrainian Ministry of Defence — General Staff and territorial recruitment center (TCC) personnel/casualty databases
    Vulnerable versions: Military personnel and next-of-kin records
  • NATO and EU member-state public sector / critical-infrastructure operators — Public-facing government, energy, water, and transportation web services
    Vulnerable versions: 30+ NATO/EU member-state entities

Remediation for Hacktivism as Hybrid Warfare

Immediate actions

  • Deploy DDoS scrubbing/CDN protection (rate limiting, WAF challenge-response) in front of public-facing government and critical-infrastructure web services in NATO/EU member states
  • Block or rate-limit traffic patterns matching DDoSia's HTTP/2 GET-flood and nginx_loris application-layer signatures at the edge
  • Restrict and monitor MDM/UEM (e.g., Microsoft Intune) console access with phishing-resistant MFA and just-in-time admin access to prevent mass remote-wipe abuse
  • Block execution of unsigned/unexpected drivers via Microsoft's vulnerable-driver blocklist (WDAC/HVCI) to mitigate ListOpenedFileDrv_32.sys-style BYOVD privilege escalation

Workarounds

  • Geo/ASN-fence or challenge traffic from hosting providers repeatedly observed serving DDoSia Tier-1 C2 nodes
  • Disable or tightly scope remote-wipe capability in MDM consoles pending verified administrator identity for bulk device actions

Longer-term hardening

  • Deploy behavioral EDR with kernel-driver load monitoring and disk-wipe/mass-overwrite detection to catch destructive payloads before completion
  • Segment OT/ICS networks from IT and vendor-management systems (billing, GPS/NTRIP, MDM) so an IT-side breach cannot pivot toward operational disruption
  • Establish takedown/monitoring relationships for regional-branded Telegram channels (e.g., 'NoName057(16) <country>') used for propaganda, recruitment, and target coordination
  • Participate in law-enforcement information sharing following Operation Eastwood-style actions to sustain infrastructure disruption against DDoSia's C2 tiering

Timeline of Hacktivism as Hybrid Warfare

  • NoName057(16) emerges as a pro-Russia hacktivist collective following the invasion of Ukraine, assessed as originating within Russia's CISM youth-monitoring center.
  • Handala Hack Team establishes its Telegram presence, later attributed to the Void Manticore (TAG-145) cluster tied to Iran's MOIS.
  • Operation Eastwood begins: Europol/Eurojust-coordinated action across 12 countries against NoName057(16), running through July 17, 2025.
  • Operation Eastwood concludes: 100+ servers seized, two arrests (France, Spain), seven arrest warrants, 24 house searches; NoName057(16) declares retaliatory campaign against Spain.
  • CISA publishes advisory AA25-343A mapping pro-Russia hacktivist opportunistic-attack TTPs to MITRE ATT&CK for US and global critical-infrastructure defenders.
  • NoName057(16) targets Italy and the Milano Cortina Winter Olympics with DDoS attacks.
  • NoName057(16) runs a Spain-focused DDoSia wave (through Feb 23): 8,044 logged attacks across 167 domains and 180 IPs, ~49.4% of activity targeting Spain.
  • Handala launches the 'RedWanted' website, publicly listing individuals identified as Israel supporters.
  • Handala claims theft of 851GB of confidential data from members of the Sanzer Hasidic Jewish community.
  • Handala claims a destructive wiper attack against Stryker Corporation, compromising its Intune/MDM console and issuing remote-wipe commands against 80,000-200,000 employee devices across 79 countries.
  • Handala claims a breach of then-FBI Director Kash Patel's personal email account and publishes over 300 emails.
  • Handala claims a breach of California Water Service (Cal Water), publishing a 5GB proof-of-concept dump from billing and RTKBase NTRIP GPS systems across Bakersfield, Visalia, and Chico; independent analysis finds no OT/ICS compromise.
  • NoName057(16)/DDoSia participants claim access to a water system in Ontario; assessed as an unverified OT-access claim rather than a confirmed operational compromise.
  • Flashpoint publishes 'The Evolution of Hacktivism,' characterizing the combined NoName057(16)/Killnet/Handala campaigns as a hybrid-warfare capability with real-world impact across 30+ NATO/EU nations.

Sources cited for Hacktivism as Hybrid Warfare

More in threat intel

Detection coverage for TL-2026-2154

As of 2026-08-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2154 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats