Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
cybersecurity

European cyber cops target NoName057(16) DDoS network in Operation Eastwood

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Operation Eastwood, coordinated by Europol and Eurojust in July 2025, disrupted major parts of the pro-Russian NoName057(16) DDoS infrastructure and led to arrests, warrants and formal warnings. Official accounts describe a significant disruption and continuing investigation—not proof that the network has been permanently eliminated.

What happened in Operation Eastwood?

Law-enforcement agencies coordinated activity from 14 to 17 July 2025, with the main action on 15 July. Authorities in Germany, Latvia, Spain, Italy, Czechia, Poland and France carried out searches and took parts of the network’s central server infrastructure offline.

Europol and Eurojust presented the operation as an international action against NoName057(16), a hacktivist network that uses distributed-denial-of-service (DDoS) attacks. Eurojust defines a DDoS attack as flooding a website or online service with traffic until its capacity is overloaded and the service becomes unavailable.

How large was the disruption?

Measure What authorities reported Attribution and qualification
Attack infrastructure More than 100 computer systems worldwide disrupted Eurojust and Europol operational accounts, July 2025
Botnet Hundreds of computer systems shut down Eurojust description of the network’s own botnet
Malware participants About 4,000 users downloaded software that enabled participation in DDoS attacks Eurojust estimate
Supporters notified About 1,100 people warned about potential criminal liability Eurojust account of the operation
Administrators notified 17 administrators warned about criminal-liability consequences Eurojust account of the operation

The figures describe systems and people reached by the operation; they do not establish that every participant was identified, arrested or charged.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Arrests, searches and warrant counts

Two suspects were arrested, one in France and one in Spain. The legal totals differ between official releases because they refer to different jurisdictions and stages of the proceedings.

Authority and date Figure reported How to read it
Eurojust, 16 July 2025 Seven international arrest warrants Eurojust’s consolidated international figure, including warrants for suspected main instigators believed to be living in Russia
Dutch police, July 2025 Eight warrants issued by Germany, Spain and France A national account covering the warrants reported by those issuing countries
Dutch police, July 2025 24 searches Search activity reported in the Dutch account; it should not be treated as a replacement for Eurojust’s international total

These numbers should not be merged into one total. They reflect separate authorities, legal processes and reporting dates, and they are not convictions.

Who is NoName057(16)?

European authorities characterize NoName057(16) as an ideologically motivated hacktivist group that publicly supports the Russian Federation and attacks Ukraine and countries aligned with NATO.

The crowd-sourced DDoSia model

The group recruited supporters through messaging services and distributed malware that allowed participants to contribute their computers to attacks. It also maintained a botnet made up of hundreds of servers. This combination gave the network a large pool of volunteer-controlled devices alongside infrastructure managed by the group itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The model is often described as crowd-sourced DDoS activity: the operators coordinate targets and tooling, while many participants supply computing resources. Downloading the software or joining a campaign does not by itself establish that a person was prosecuted, which is why authorities’ warnings about possible liability matter.

Which countries and services were targeted?

Location or period Reported targets and incidents
Germany Eurojust recorded 14 attacks affecting about 230 organisations, including arms factories, power suppliers and government organisations.
Sweden Authorities and bank websites were targeted.
Switzerland Attacks coincided with a Ukrainian president’s parliamentary video message and the 2024 Ukraine Peace Summit.
Netherlands Targets were reported around the June 2025 NATO Summit.
Broader European pattern ENISA identified public-administration sites, ministries, parliamentary websites, municipalities, banks, payment providers, air and rail services, telecoms and hosting as recurring target types.

The targets were generally public-facing services whose disruption could attract attention or inconvenience users, rather than evidence of long-term control over industrial systems.

What ENISA says about the campaign’s scale and impact

ENISA’s Threat Landscape 2025, published in October 2025, found that NoName057(16) sustained the highest operational tempo among five leading hacktivist groups. ENISA linked that pace in part to the group’s crowd-sourced DDoSia model.

Share of EU hacktivist activity by sector

Sector Share reported by ENISA
Public administration 63.1%
Transport 12%
Finance 11.7%
Digital infrastructure 5.4%
Manufacturing 4%
Media and entertainment 4%

Share of DDoS attacks against EU digital-infrastructure services

Group or category Share reported by ENISA
All hacktivist-led DDoS activity 57.5% of attacks against EU digital-infrastructure services
NoName057(16) 33.8% of those incidents
Keymous+ 21.4%
Mr Hamza 6.5%

High activity volume did not translate into widespread confirmed downtime. ENISA wrote that NoName057(16)’s activity led to almost no confirmed outages and that “the overall impact of DDoS activities remained marginal.” That gap between the number of attacks and measurable disruption supports ENISA’s assessment that the campaigns also served an information-operation purpose: demonstrating activity, generating publicity and creating pressure even when services recovered quickly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was the network taken down permanently?

No permanent end has been established. Operation Eastwood removed more than 100 systems and major central infrastructure from operation, but the official statements describe disruption, arrests, warrants and ongoing investigative work. They do not establish that every server, administrator or participant was identified, nor do they report final convictions.

DDoS networks can regenerate when operators replace servers, recruit new participants or redistribute tooling. A takedown can therefore reduce capacity and expose organizers without guaranteeing that attacks stop indefinitely.

What service operators should take from the operation

The incidents show why public-facing organisations need plans for short, politically motivated traffic floods as well as conventional criminal attacks.

  • Mitigation capacity: confirm that upstream providers can absorb attack volumes beyond the organisation’s normal bandwidth.
  • Filtering speed: define who can activate rate limits, traffic challenges, scrubbing or emergency routing and how quickly they can do so.
  • Geographic coverage: check whether protection extends to every region where users and services are hosted.
  • Public-facing infrastructure: map government portals, payment pages, transport systems, DNS, APIs and other internet-dependent services that may be targeted together.
  • Logging and forensics: retain traffic, firewall, DNS and application logs so an incident can be distinguished from a brief service fault and evidence can be shared with investigators.
  • Regulatory and public-sector coordination: establish contacts and notification procedures before an incident, particularly for essential or publicly funded services.

Those measures improve resilience regardless of whether an attack is linked to NoName057(16) or another group.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The bottom line

European authorities achieved a substantial, multinational disruption of NoName057(16)’s DDoS infrastructure in July 2025, including server seizures, arrests, warrants and warnings to thousands of alleged supporters and administrators. The operation reduced the network’s operating base, but ENISA’s later assessment shows why attack counts should not be confused with lasting outages—and why Eastwood should be treated as a major intervention, not a guaranteed final takedown.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.