A major international police operation led by Europol has taken down key parts of the infrastructure used by a pro-Russian hacker group called NoName057(16). The group has carried out multiple DDoS cyberattacks against Ukraine and its allied nations. Authorities shut down over 100 systems worldwide and arrested two people in France and Spain. They also searched homes in six countries and issued arrest warrants for six Russian citizens. The group has been active since March 2022, using a tool called DDoSia to carry out attacks and reward participants with cryptocurrency. The operation, named Operation Eastwood, took place from July 14 to 17 and involved law enforcement from over 20 countries, including the U.S., France, Germany, Poland, and Ukraine. Burlakov is believed to be a key member of the hacker group NoName057(16), suspected of helping lead cyberattacks on institutions in Germany and other countries. He allegedly used the nickname "darkklogo" and helped develop attack software, choose targets, and manage payments for illegal server rentals.Evstratova, identified as a key member, is accused of enhancing the group’s cyberattack tool known as DDoSia. Avrosimow is linked to 83 cases of computer sabotage. Europol said they contacted over 1,000 people who supported the group, warning them they could face legal consequences for using automated tools in cyberattacks. The group is said to have amassed over 4,000 supporters and created a botnet comprising hundreds of servers to amplify their cyberattacks. They used game-like features, such as leaderboards and badges, to motivate volunteers, especially younger ones, by framing the attacks as a way to defend Russia or respond to political events. Russian-linked hacker groups have increasingly targeted critical infrastructure across Europe and NATO countries with coordinated cyberattacks, moving beyond website disruptions to more serious threats, as seen in recent arrests and attacks on hundreds of institutions.
Researchers H0j3n and Aniq Fakhrul disclosed a proof-of-concept exploit named Certighost for CVE-2026-54121, an Active Directory Certificate Services (AD CS) vulnerability patched ...
At the core of an advanced malvertising attack scheme known as FakeAgent, SectopRAT was utilized by the cybercriminals in exploiting Anthropic’s Claude platform for the distribut...
Researchers at Group-IB have uncovered a previously undocumented cyber espionage campaign, tracked as JadeProx, targeting government, healthcare, and education organizations across...