Aalto University’s study finds that NoName057(16) uses technically simple DDoS attacks less for lasting damage than as a stage for propaganda, intimidation and the erosion of trust in governments and essential services. The group’s DDoSia Project lowers the barrier to participation by recruiting volunteers through T...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did the Aalto University study reveal about how the pro-Russian hacking group NoName057(16) has gamified DDoS attacks as a form of hybr. Article summary: The Aalto study characterizes NoName057(16) not as ordinary “hacktivists,” but as a hybrid threat actor: it crowdsources technically simple DDoS disruption to conduct geopolitical and psychological warfare, then exploits. Topic tags: general, general web, government, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, ch
Aalto University research presents NoName057(16) as more than a conventional hacktivist collective. The pro-Russian group combines crowdsourced distributed denial-of-service (DDoS) attacks with propaganda, ideological recruitment and financial incentives—a model the study places at the intersection of hacktivism, geopolitical cyber activity and cybercrime. 1
2
The central lesson is that a short-lived website outage can serve a longer political purpose: making institutions appear vulnerable, amplifying fear and encouraging the public to distrust the organisations responsible for essential services.
NoName057(16) has launched thousands of DDoS attacks against public and private organisations, mainly in NATO member states and other European countries, including Finland. 2 A DDoS attack floods a service with requests or traffic so that legitimate users cannot access it. The immediate consequence may be temporary unavailability, but Aalto’s analysis says the disruption is also used as a platform for propaganda intended to delegitimise opponents.
2
That makes the campaign a hybrid threat. The technical operation creates a visible incident; the surrounding messaging turns that incident into a political narrative. The intended effect is not necessarily permanent technical damage, but anxiety, reputational harm and weaker confidence in governments, institutions and critical services. 1
2
The group’s operating model depends on distributing much of the work across a volunteer network. Participants are recruited through Telegram and given access to DDoSia, the tool used to coordinate attacks against targets selected or promoted by the network. 2
34
43
This lowers the technical barrier to entry. People do not need to develop sophisticated exploits to take part; they can contribute computing resources through a tool and follow the group’s campaign structure. The approach is crowdsourced, but centrally shaped through target selection, communication and performance incentives. 2
34
The result is a community that can be mobilised around political events and perceived support for Russia’s opponents while retaining some features associated with cybercrime-for-hire. Aalto therefore describes the model as blurring the boundaries between ideological hacktivism, geopolitical warfare and financially motivated cybercrime. 2
3
DDoSia is not presented simply as attack software. The project frames participation as a “patriotic online game,” encouraging contributors to see disruptive activity as nationalist or civic action rather than criminal conduct. 3
38
The game-like structure can help with recruitment and retention by giving participants a shared identity, visible goals and a sense of competition. Reporting on the project has also described ranking or performance-based incentives, although the exact mechanics and payment arrangements have changed across accounts and over time. 39
44
This combination is strategically useful: ideology supplies motivation, the game format makes participation feel accessible and social, and financial rewards offer an additional reason to keep contributing.
The project has offered rewards in cryptocurrency to participants who contribute to successful attacks. Earlier reporting cited payments of up to 80,000 Russian rubles—approximately $1,200 at the time—for successful DDoS activity. 46
The reward system matters because it complicates the usual distinction between a politically motivated volunteer and a paid cybercriminal. Participants may be attracted by pro-Russian messaging, by the social experience of the group, by the competitive format or by the prospect of payment. Aalto’s findings indicate that these motives can operate together rather than separately. 2
The available evidence does not establish that every participant is paid or that every attack is motivated by money. The stronger conclusion is that cryptocurrency gives the group another mechanism for recruiting and incentivising contributors alongside its ideological appeal.
According to Aalto University, NoName057(16) launched 23 rounds of attacks against Finnish targets from January 7, 2025, affecting 129 public and private organisations. The targets included Parliament and other government institutions, municipalities, banks and financial institutions, and critical-infrastructure service providers. Aalto also reported an increase in attacks after Finland joined NATO in 2023. 1
Across Europe, the immediate impact of such attacks can be a temporary loss of access to online services. The broader impact is the perception that public bodies, financial organisations or essential-service providers cannot reliably protect their digital front doors. That perception is valuable to an attacker even when systems recover quickly.
Between July 14 and 17, 2025, Europol and Eurojust coordinated Operation Eastwood, a multinational action against NoName057(16)’s people and infrastructure. Authorities from Czechia, France, Finland, Germany, Italy, Lithuania, Poland, Spain, Sweden, Switzerland, the Netherlands and the United States took simultaneous action. 17
The operation disrupted an attack infrastructure comprising more than 100 computer systems worldwide and took a major part of the group’s central server infrastructure offline. 17 Other reporting on the operation described arrests, searches and arrest warrants alongside the infrastructure disruption.
17
23
That was a significant operational setback, but “disrupted” is not the same as permanently eliminated. The available evidence does not show that the underlying recruitment model, political messaging or propaganda effects ceased. A resilient crowdsourced structure can potentially adapt when particular servers or administrators are removed.
Aalto’s analysis points to a response that is wider than ordinary DDoS mitigation. Organisations should account for an attacker’s political objectives, operating model and motivations in threat modelling, risk assessment and incident management—not treat every incident solely as an availability problem. 2
That means pairing technical preparations with communications planning:
The study’s most important implication is therefore strategic. DDoSia turns ordinary internet users into participants in a coordinated influence operation, while making cyber disruption look like a game. Defending against it requires both resilient infrastructure and the ability to contest the story built around an attack.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Aalto University’s study finds that NoName057(16) uses technically simple DDoS attacks less for lasting damage than as a stage for propaganda, intimidation and the erosion of trust in governments and essential services.
Aalto University’s study finds that NoName057(16) uses technically simple DDoS attacks less for lasting damage than as a stage for propaganda, intimidation and the erosion of trust in governments and essential services. The group’s DDoSia Project lowers the barrier to participation by recruiting volunteers through Telegram, presenting attacks as a “patriotic online game” and offering cryptocurrency incentives that have reportedly rea...