The Times Australia
Small Business News

.

Pro-Russian Hacker Group Targeting Sites in Ukraine and Supporting Countries with DDoS Attacks


The group performs politically motivated attacks on websites belonging to governments, utilities, telecommunications, and transportation companies

Avast, a global leader in digital security and privacy, has been tracking the activity of a pro-Russian hacker group called NoName057(16) since June 1, 2022. The group reacts to evolving political situations, targeting pro-Ukrainian companies and institutions in Ukraine and neighbouring countries, like Estonia, Lithuania, Norway, and Poland. According to Avast’s research, the group has a 40% success rate, and companies with well-protected infrastructure can withstand attack attempts. The research also found that 20% of the successes claimed by the group may not be their doing. 

NoName057(16)’s targets

NoName057(16) exclusively carry out DDoS attacks. At the beginning of June, the group targeted Ukrainian news servers. Then, they focused on websites within Ukraine belonging to cities, local governments, utility companies, armament manufacturers, transportation companies, and postal offices. 

By mid-June, the attacks became more politically motivated. Baltic states (Lithuania, Latvia, and Estonia) are significantly targeted. Following a ban on the transit of goods subject to EU sanctions through their territory to Kaliningrad, the group targeted Lithuanian transportation companies, local railway, and bus transportation companies. On July 1, 2022, the transportation of goods destined to reach miners employed by the Russian government-owned coal mining company, Arktikugol, was stopped by Norwegian authorities. In response, the group retaliated by attacking Norwegian transportation companies (Kystverket, Helitrans, Boreal), the Norwegian postal service (Posten), and Norwegian financial institutions (Sbanken, Gjensidige). In early August, after Finland announced their intention of joining NATO, NoName057(16) went after Finnish government institutions, like the Parliament of Finland (Eduskunta), State Council, and Finish police. 

40% success rate

NoName057(16) actively boast about their successful DDoS attacks to their more than 14K followers on Telegram. Their channel was created on March 11, 2022. The group only reports successful DDoS attacks.  

“Although the group’s reported number of successful attacks seems large, statistical information indicates the contrary,” explains Martin Chlumecky, malware researcher at Avast.

“The group’s success rate is 40%. We compared the list of targets the C&C server sends to the Bobik bots to what the group posts to their Telegram channel. Websites hosted on well-secured servers can withstand the attacks. Around 20% of the attacks the group claims to be responsible for did not match the targets listed in their configuration files.” 

Bobik bots act as soldiers

The group controls unprotected PCs around the world infected with malware called Bobik, which act as bots. Bobik first emerged in 2020 and was used as a remote access tool in the past. The malware is distributed by a dropper called Redline Stealer, which botnet-as-a-service cybercriminals pay for to spread their malware of choice. Avast has protected a few hundred PCs from Bobik. Avast researcher Martin Chlumecky, however, estimates there are several thousand Bobik bots in the wild, considering the effectiveness and frequency of attacks. 

The group sends commands to its bots via a C&C server located in Romania. Formerly, the group had two additional servers in Romania and Russia, but these are no longer active. The bots receive lists of targets to DDoS, in the form of XML configuration files, which are updated three times a day. They attempt to overload login pages, password recovery sites, and site searches. The attacks last a few hours to a few days. 

Impact of the attacks

The group's most successful attacks leave sites down for several hours to a few days. To handle the attacks, smaller and local site operators often resort to blocking queries from outside their country. In extreme cases, some site owners targeted by the group unregistered their domains. 

“The power of the DDoS attacks performed by NoName057(16) is debatable, to say the least. At one time, they can effectively strike about thirteen URL addresses at once, judging by configuration history, including subdomains,” continues Martin Chlumecky. “Furthermore, one XML configuration often includes a defined domain as a set of subdomains, so Bobik effectively attacks five different domains within one configuration. Consequently, they cannot focus on more domains for capacity and efficiency reasons.” 

The DDoS attacks carried out were more difficult to handle for some site operators of prominent and significant domains, such as banks, governments, and international companies. After a successful attack, Avast researchers noticed larger companies implementing enterprise solutions, such as Cloudflare or BitNinja, which can filter incoming traffic and detect DDoS attacks in most cases. On the other hand, most large, international companies expect heavier traffic and run their web servers in the Cloud with anti-DDoS solutions, making them more resilient to attacks. For example, the group was unsuccessful in taking down sites belonging to Danish bank, Danske Bank (attacked June 19 - 21, 2022), and Lithuanian bank, SEB (attacked July 12 - 13, 2022 and July 20 - 21, 2022). 

NoName057(16)’s more successful attacks affected companies with simple, informational sites, including just an about, mission, and a contact page, for example. The servers of sites like these are not typically designed to be heavily loaded and often do not implement anti-DDoS techniques, making them an easy target. 

How businesses and consumers can protect themselves

Businesses can protect their sites from DDoS attacks with specialized software and cloud protection.  

Consumers can prevent their devices from being used as part of a botnet by using reliable antivirus software, like Avast One, which detects and blocks malware like Bobik. Further steps consumers can take to protect their devices include avoiding clicking on suspicious links or attachments in emails and updating software on a regular basis to patch vulnerabilities. It is very difficult to recognize if a device is being used to facilitate a DDoS attack, but an indication could be high network traffic going to an unknown destination. 

More information about the group, Bobik malware, and the DDoS attacks can be found on the Avast Decoded blog: https://decoded.avast.io/martinchlumecky/bobik/

Property Times

Choosing the Wrong Agent Is the #1 Regret Among Aussie Property Sellers

Selling your home is often one of the largest financial transactions you’ll make, and for many Australians, it’s also one of the most emotional. A new survey of Australian home sellers has revealed that their number one regret is having not selected...

Vietnam's "Gold Coast" Emerges as Extraordinary Investment Frontier and Australian Inspired Way of Life

$2 Billion super-city in Vung Tau set to replicate Australia's Gold Coast success story A culturally metamorphic development aptly named "Gold Coast" is set to reshape Vietnam's southern coast below Ho Chi Minh City, becoming a major investment...

First Home Buyers in Melbourne: 3 Key Statistics Proving Why Home & Land Packages Are Your Best Bet in 2025

Stepping into the Melbourne property market for the first time can feel like navigating a maze without a map. Prices, deposits, and decisions stack up fast. But here’s the good news: home and land packages are helping first home buyers get ahead in...

Off-the-Plan Sales Launched for $22 Million Ultra-Luxury Project ‘Vellora’ Set to Redefine Luxury Living in Brisbane’s St Lucia

A new standard of architectural distinction and elevated living is taking shape in one of Brisbane’s most coveted riverside suburbs, with off-the-plan sales officially launching for Vellora last night at an exclusive buyers’ event at The Powerh...

Food & Dining

Cult Favourite, TokyoTaco, Opens Beachfront at Mooloolaba this June

FREE Tokyo Tacos to Celebrate!  Cult favourite Japanese-Mexican restaurant TokyoTaco is opening a beachfront venue at the Mooloolaba Esplanade on Queensland’s Sunshine Coast this June.  The doors of the new venue will open on 18 June and to cel...

International lager claims crown as Australia’s most preferred beer

Launching its inaugural ‘Brand Map of Australia’, Tracksuit reveals Corona as the nation’s most preferred beer  Sydney, Thursday, 29 May 2025 - From iconic mass-produced lagers to innovative craft brews, beer is woven into the fabric of Australi...

Hundreds line up in Sydney to try viral crispy chicken

Pappa Flock’s crispy crunch causes a frenzy in Bondi JunctionBondi Junction officially has chicken fever. Sydneysiders turned out in flocks over the weekend, with queues forming from 5AM - a full seven hours before doors opened - to be among the firs...

Unique Types of Food You'll Get to Try in Australia

The Australian food experience is a combination of Aboriginal traditions, recipes from British colonies, and the tastes of global food trends today. Besides traditional food, Australia offers visitors the chance to try unique food experiences that ...

Business Times

Samsara Eco and lululemon announce 10 year partnership

lululemon and Samsara Eco Announce 10-Year Plan to Advance Recycled Material Portfolio Plan will see lululemon source a...

Barelli Bathrooms announces celebrity interior designer Kellie Ri…

Barelli Bathrooms, a leading name in contemporary bathroom accessories and design, is proud to announce its new national ...

Launchd Acquires Huume, Strengthening Creative Firepower Across T…

Launchd, a leader in talent, technology and brand partnerships, has announced its acquisition of influencer talent manage...

The Times Features

Cult Favourite, TokyoTaco, Opens Beachfront at Mooloolaba this June

FREE Tokyo Tacos to Celebrate!  Cult favourite Japanese-Mexican restaurant TokyoTaco is opening a beachfront venue at the Mooloolaba Esplanade on Queensland’s Sunshine Coast t...

Samsara Eco and lululemon announce 10 year partnership

lululemon and Samsara Eco Announce 10-Year Plan to Advance Recycled Material Portfolio Plan will see lululemon source a significant portion of its future nylon 6,6 and polyes...

The viral diet that could boost your immunity during winter

As we settle into the winter months, immune health becomes top of mind, and the latest food trend gaining traction may be worth taking seriously, especially when it comes to st...

Running Across Australia: What Really Holds the Body Together?

How William Goodge’s 3,800km run reveals the connection between movement, mindset, and mental resilience As a business owner, I’ve come to realise that the biggest wins rarely com...

Telehealth is Transforming Healthcare Services in Australia

It has traditionally not been easy to access timely healthcare in Australia, particularly for people who live in remote areas. Many of them spend hours on the road just to see...

Launchd Acquires Huume, Strengthening Creative Firepower Across Talent-Led Marketing

Launchd, a leader in talent, technology and brand partnerships, has announced its acquisition of influencer talent management agency Huume from IZEA. The move comes as the medi...