Team Cymru published an infrastructure analysis on Team Cymru mapping the full backend architecture behind NoName057(16)'s DDoSia operation — revealing a professionally designed management stack with Telegram bot integration, MongoDB data storage, RabbitMQ messaging, Redis caching, and Prometheus Node Exporter monitoring, hosted almost entirely within Russian-affiliated IP space. The analysis further confirmed that DDoS attack timestamps are calibrated to Moscow Standard Time (UTC+3), and that 84% of all attack traffic originates from just two interlinked hosting providers.
Backend Architecture: C2 Mirrors, MongoDB, RabbitMQ, Redis, and Prometheus Monitoring
The primary C2 server (31.13.195.87, NETERRA/BG, operational from December 19, 2022) forwards all bot requests over TCP/5001 to a backend primary server at 87.121.52.9 — confirmed as the true target configuration source by returning identical data when queried directly. The primary server makes regular connections to api.telegram[.]org (likely Telegram bot updates for the DDoSia channels), and communicates with two CLOUDASSETS/RU (AS212441) hosts: 109.107.184.11 on TCP/27017 (MongoDB — attack data storage) and 185.173.37.220 on TCP/5672 and TCP/6379 (RabbitMQ and Redis — event queuing and command caching). A monitoring host at 91.142.79.201 (also CLOUDASSETS/RU) polls both the C2 server and primary server on TCP/9100 (Prometheus Node Exporter), collecting campaign metrics and active bot counts. The sophistication of this stack — queuing, caching, database, metrics — indicates operators with legitimate professional systems administration experience.
Moscow Standard Time Attack Scheduling and Estonian Ministry of Finance Case Study
Examination of a target entry for the Estonian Ministry of Finance revealed an attack scheduled for 10:00 — initially assumed UTC. Threat telemetry confirmed the attack commenced at 07:00 UTC, establishing that DDoSia target timestamps are in UTC+3 (Moscow Standard Time). The Estonian attack peaked between 08:00–09:00 UTC before defensive mitigations reduced effectiveness. A second Estonian target from the same period showed a 24-hour attack window also commencing at 07:00 UTC. The targeted subdomain displayed a "down for maintenance" message by 17:00 UTC, confirming partial attack success. Confirmed attack targets since early 2023 include entities in Czechia, Denmark, Estonia, Germany, Slovakia, and Slovenia.
Attack Infrastructure: Static Stark Industries Dominance Raises Volunteer Model Questions
Analysis of all inbound connections to 31.13.195.87:80 since its December 19, 2022 activation identified IPs across 83 distinct ASNs — but 84% of all traffic originated from IPs assigned to either MIRhosting or Stark Industries Solutions (GB). Two /24 netblocks alone accounted for over 65% of attack traffic in the Estonian targets: 5.182.39.0/24 (38 IPs) and 94.131.106.0/24 (21 IPs), with the top 10 netblocks collectively generating 68% of total traffic. Many IPs had been continuously communicating with the C2 since its December 2022 launch — indicating a broadly static rather than dynamically recruited infrastructure. The concentration of traffic in a single provider raises questions about whether NoName057(16) is propping up its ostensibly volunteer-driven model with self-procured infrastructure, or whether a single large "volunteer" contributes the majority of attack capacity.