NoName057(16)
Also known as NoName
Reports
11
First seen
Dec 2, 2025
Last seen
Jul 8, 2026
Motivation
Hacktivism, Sabotage, Geopolitical
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
Netherlands ×1
Top ATT&CK techniques
T1566 Phishing ×6T1486 Data Encrypted for Impact ×5T1498 Network Denial of Service ×5T1190 Exploit Public-Facing Application ×4T1110 Brute Force ×3T1561 Disk Wipe ×3T1041 Exfiltration Over C2 Channel ×2T1598 Phishing for Information ×2T1021 Remote Services ×2T1003 OS Credential Dumping ×2T1219 Remote Access Software ×2T1195 Supply Chain Compromise ×2
Indicators
domain ×80cve ×17filename ×5
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2020-12812 (exploited)CVE-2024-20353 (exploited)CVE-2024-20359 (exploited)CVE-2024-40766CVE-2025-14174 (exploited)CVE-2025-20333 (exploited)CVE-2025-20362 (exploited)CVE-2025-43529 (exploited)CVE-2025-53690 (exploited)CVE-2025-55182 (exploited)CVE-2025-59718 (exploited)CVE-2025-59719 (exploited)CVE-2025-64155CVE-2025-8088 (exploited)CVE-2026-1281 (exploited)CVE-2026-20045 (exploited)CVE-2026-21509 (exploited)CVE-2026-8398 (exploited)
Recent reports
Medium