Pro-Russia Hacker Group NoName057(16) Launches DDoS Attacks on Italian Entities

Listen to this Post

2025-02-28

A Fresh Wave of Cyberattacks Hits Italy

This morning, the pro-Russia hacker group NoName057(16) launched a series of Distributed Denial-of-Service (DDoS) attacks against several high-profile Italian institutions. Among the affected entities were Linate and Malpensa airports, the Italian Transport Authority, Intesa San Paolo Bank, and the ports of Taranto and Trieste.

Although the cyberattacks caused disruptions, the Italian National Cybersecurity Agency (ACN) quickly intervened to mitigate their impact. The hackers primarily used well-known attack techniques that the Italian government is capable of countering.

The attacks were reportedly in retaliation to comments made by Italian President Sergio Mattarella, who compared Russia’s actions in Ukraine to those of Nazi Germany during World War II. This statement angered Russian officials and triggered a response from NoName057(16), who labeled Mattarella a “Russophobe” and vowed retaliation through cyberattacks.

In a Telegram post, the hacker group criticized Italy’s past alliance with Nazi Germany under Mussolini and accused the country of supporting what they called the “neo-Nazi Kyiv regime” by providing military aid to Ukraine. They also warned that Italy would continue facing DDoS attacks as a consequence of its stance against Russia.

The Russian Foreign Ministry echoed these sentiments, with spokesperson Maria Zakharova warning that Mattarella’s words would not go “without consequences.”

NoName057(16) has been active since March 2022, launching cyberattacks on government institutions and critical infrastructure worldwide. The group is known for using tools like the Bobik botnet and for intensifying its attacks during periods of heightened geopolitical tension.

This latest wave of cyberattacks follows previous assaults on Italian institutions, including a large-scale operation in January that coincided with Ukrainian President Volodymyr Zelensky’s visit to Italy. Italian banks, ministries, and private companies were all targeted in these past campaigns.

What Undercode Says:

1. Political Motivations Behind Cyber Warfare

The attacks by NoName057(16) highlight the growing intersection of cyber warfare and geopolitics. These incidents are not just random acts of hacking but calculated responses to political statements and actions. The fact that these cyberattacks were launched following Mattarella’s remarks shows how digital attacks are increasingly used as tools of state-aligned retaliation.

2. The Pattern of NoName057(16)’s Attacks

Historically, NoName057(16) has escalated its activities in response to geopolitical developments, especially those related to Ukraine. Their attacks tend to increase when European nations express support for Ukraine or when key diplomatic events take place, such as Zelensky’s visit to Italy. This pattern suggests a level of coordination and intent beyond simple hacktivism—it points to a structured and possibly state-backed cyber operation.

3. The Role of the Bobik Botnet

One of the key tools in NoName057(16)’s arsenal is the Bobik botnet. This malware is capable of creating large-scale DDoS attacks by hijacking infected devices and directing their traffic towards target websites. The use of such a tool indicates a level of sophistication that goes beyond amateur hacktivists and suggests professional-level cyber expertise.

4. Italy’s Cybersecurity Response

The Italian National Cybersecurity Agency (ACN) responded swiftly to mitigate the impact of the attacks. However, the repeated targeting of Italian infrastructure raises concerns about whether current defenses are adequate. If NoName057(16) can continually launch attacks with minimal disruption to their operations, it suggests that Italy’s cybersecurity measures may need further strengthening.

5. Future Cyber Threats from NoName057(16)

Given the group’s past behavior, it is likely that future geopolitical developments will trigger new waves of attacks. If Italy continues supporting Ukraine or making statements that anger Russian authorities, NoName057(16) may intensify its cyber warfare efforts.

6. Broader Cybersecurity Implications for Europe

Italy is not the only target of pro-Russian cyberattacks. Many European nations supporting Ukraine have experienced similar digital assaults. This indicates that countries aligned with Ukraine must strengthen their cyber defenses against state-affiliated hacker groups.

7. Digital Warfare as a New Battlefield

The increasing reliance on cyberattacks as a form of political retaliation suggests that the digital realm is now a crucial battlefield in modern warfare. Governments and organizations must recognize this shift and invest in stronger cybersecurity strategies to counteract state-sponsored hacking groups.

8. Strategies for Countering DDoS Attacks

Governments and private entities must adopt robust defense mechanisms, including:
– Advanced Threat Intelligence: Monitoring and analyzing hacker group activities to predict and prevent attacks.
– Cloud-Based DDoS Protection: Using scalable cloud solutions to absorb and mitigate attack traffic.
– Zero Trust Security Models: Restricting access to critical systems based on verification protocols.
– Public-Private Collaboration: Encouraging cooperation between governments, cybersecurity agencies, and private companies to strengthen national defenses.

9. The Need for International Cyber Regulations

As cyberattacks become more common in geopolitical conflicts, there is a growing need for international regulations governing cyber warfare. Establishing norms and potential repercussions for state-sponsored hacking could help deter such activities in the future.

10. Conclusion

The cyberattacks on Italy demonstrate the increasing role of cyber warfare in international conflicts. As tensions between Russia and Western nations persist, such incidents are likely to continue. Governments must stay vigilant, bolster their cybersecurity frameworks, and anticipate further digital retaliation from groups like NoName057(16).

Fact Checker Results:

  1. Confirmed Activity of NoName057(16): NoName057(16) has been active since March 2022, with a documented history of launching cyberattacks against government and critical infrastructure targets.

  2. Bobik Botnet Usage Verified: Security researchers, including those from Avast, have confirmed that NoName057(16) utilizes the Bobik botnet for DDoS attacks.

  3. Retaliation Motive Aligns with Official Statements: The hacker group’s justification for the attacks aligns with statements from the Russian Foreign Ministry, indicating a direct response to Mattarella’s remarks.

References:

Reported By: https://securityaffairs.com/174294/hacktivism/noname05716-launched-ddos-attacks-on-italian-sites.html
Extra Source Hub:
https://www.digitaltrends.com
Wikipedia: https://www.wikipedia.org
Undercode AI

Image Source:

OpenAI: https://craiyon.com
Undercode AI DI v2Featured Image