socradar.io 2/23/2026, 2:01:34 PM · via preferred

Pro Russian NoName057(16) floods Spain with DDoS via DDoSia

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

BETWEEN February 16 and 23, 2026, SOCRadar identified a coordinated DDoS campaign led by the pro-Russian threat actor NoName057(16) using the DDoSia tool, resulting in 8,044 recorded attack entries across 167 unique domains and 180 unique IP addresses.

Spain was the primary target, accounting for 49.4% of attacks (3,975), with a broad national footprint that included six autonomous communities and multiple major cities, while Ukraine attracted 10.1% and Germany 2.5%, Denmark 2.0% and other international entities made up the remainder. The most targeted port was 443 (HTTPS), involved in 69.8% of attacks, with TCP floods and HTTP floods forming the dominant techniques alongside application-layer nginx_loris and UDP floods.

The campaign is described as a significant operational intensification against a NATO member state, demonstrating a deliberate, multi-front strategy designed to disrupt government, transportation, energy and defense sectors across Spain, Ukraine, and other countries. The analysis highlights rapid target list updates—26 in seven days, including five within 20 minutes on February 19—reflecting high real-time operational agility.

View full article

Article by CyberSIXT