NoName057(16) DDoSia 2024: FreeBSD and 32-bit Architecture Expansion, Machine GUID Fingerprinting, and Daily C2 Rotation Amid 20,000-Member Telegram Network

Sekoia TDR analysts published a 2024 update on Sekoia TDR on Project DDoSia — the crowdsourced DDoS platform operated by pro-Russian hacktivist group NoName057(16) — covering software updates, C2 infrastructure instability, and victimology from January to mid-February 2024. The project's Telegram participant count approached 20,000 active members, with the broader NoName057(16) channel audience exceeding 60,000 followers, nearly doubling since early 2023.

Software Update: FreeBSD Support, 32-bit Architecture, and Machine GUID Fingerprinting

On November 11, 2023, DDoSia administrators silently released a new version adding FreeBSD OS support and 32-bit processor compatibility (previously only AMD64, ARM, ARM64 were supported). The distribution ZIP now contains 11 binaries spanning FreeBSD/Linux/macOS/Windows across x32/x64/ARM/ARM64 architectures, organized into d_eu and d_ru geographic folders. Users in Russia are advised to use a VPN when running from the d_eu binary, though the FAQ explicitly states that operating within Russia "it is extremely unlikely that there will be any problems with the law" — an absence of mandated VPN usage that Sekoia assesses as a possible indicator of implicit Russian state collaboration, though no official attribution exists. The most significant technical change is a new encrypted POST to [C2_IP]:[port]/client/login transmitting system metadata: OS, kernel version and architecture, platform family, CPU core count, registration timestamp, timezone, username, and a machine-unique GUID extracted from HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid — enabling precise operator-side tracking of participant machines and statistical mapping of the botnet's technical composition.

C2 Instability: Daily Rotations, Global Hosting Diversification, and Four Versions in One Day

In 2024, NoName057(16) made several dozen C2 server changes within weeks — a sharp increase from 2023 patterns. Hosting geolocation diversified from predominantly European to global, including Asia, Africa, and South America, likely driven by operational urgency to restore service quickly following takedowns. Some C2 addresses were reused across both years (e.g., 77.75.230[.]221). On February 8, 2024, four different C2 versions were deployed in a single day. Despite these disruptions — including multi-hour service outages — NoName057(16) continued claiming daily attacks, reinforcing Sekoia's assessment that the group maintains its own dedicated attack servers independent of volunteer participant machines.

2024 Victimology: Ukraine Primary, Finland and Italy Geopolitically Targeted, Japan Retaliation

Analysis of 700+ targeted URLs and domains from January 1 to February 18, 2024 shows Ukraine remaining the primary target (approximately 25% of all DDoSia attacks), consistent with 2023 patterns. More than half of all targets were government-related entities (public administrations, ministries, official websites). Transportation and banking each accounted for roughly 12.5% of targets. Finland and Italy received elevated targeting: Finland due to its February 11 presidential election (where Russian aggression was a central campaign issue) and its NATO accession; Italy due to Prime Minister Meloni's role persuading Hungary's Orban to support Ukraine funding. On February 19–21, 2024, Japan-related entities were targeted — assessed with high confidence as retaliation for Japan's Ukraine reconstruction conference announcing a ¥15.8 billion (€98M) aid package. Since December 2023 the group also announced cooperation alliances with SoubearArmy, 22C, CyberDragon, Horus Team, UserSec, and PHOENIX, coordinating attacks particularly against Italian infrastructure.

Read the full analysis on IntelFusions