Investigating the Infrastructure Behind DDoSia's Attacks
Dec. 21, 2025, 7:32 p.m.
Description
DDoSia, a participatory DDoS tool created by Russian hacktivists in 2022, is operated by the pro-Russian group NoName057(16). It relies on volunteers to contribute network resources for attacks, primarily targeting Ukraine, European allies, and NATO states. Censys has monitored DDoSia since mid-2025, observing an average of 6 control servers with short lifespans. The tool uses a multi-layered control infrastructure, with systems typically hosted on VPS providers. Despite law enforcement disruption in July 2025, DDoSia quickly reconstituted and resumed operations. The infrastructure is characterized by rapid changes, with most servers active for less than 24 hours. Attacks focus on government, military, transportation, public utilities, financial, and tourism sectors.
Tags
Date
- Created: Dec. 16, 2025, 9:50 a.m.
- Published: Dec. 16, 2025, 9:50 a.m.
- Modified: Dec. 21, 2025, 7:32 p.m.
Indicators
- 7ee3574b0693e78060d863a5794437960aec0614af6c1909dd075daec0bcaf92
- 87cd40fbf9f363c212a8402cc8350f624fd6760799c013a0cdd301707a5bd083
- 8ba11c9e3d3f38a2473620579f61119be9ada9bc0e4dc37fc045017f56248473
- 307e3ea1cb140f375443ef3c9b62028dd5c6449c1bf242b83d6db5d730bd2121
- e3f229dc71ce65c1f2de05e2cfbd7ae848d330661d9b9b3fa00d594bf84f4d93
- 48e9d5b0f8a2d56d31b4e845597789a81e3733c03751139a22f55ceebd15b75a
- 532edcad0f1637b4cb6fe2638c84c9cee2a52786b89f8d155c910bf60f43da9c
- b81734717f36d3cea59e5690b984333c5a6908a15883a0463d77cb20dadcec0c
- 0eae66824c65efe6b69937bf8427b7f28df591f2788b8088fbe9a05e8c26e077
- 2aaf3c08da86d5d0f6f9c00d4011991fd2cd50fa0777d51d5552b98365b15774
- 95375dac86bf8daf101cb8120d78f0340e6b1cdbea16b859d96d7aef946be983
- 0e19deac3d64a33495d237ed4cdb3581813b88b6ed2afe84b8c2908201feaf91
- 89.185.84.159
- 194.180.158.48
- 185.39.204.86
- 5.44.42.29
- 83.217.9.109
- 178.248.75.62
- 188.116.20.254
- 185.196.9.151
- 104.194.145.88
- 109.120.150.76
- 94.140.114.239
- 45.128.232.253
- 193.56.135.252
- 193.149.189.208
- 185.196.11.216
- 185.212.47.40
- 77.239.101.153
- 185.232.205.52
- 83.217.9.48
- 109.120.176.4
- 154.18.239.180
- 181.214.58.92
- 65.38.121.22
- 194.87.79.223
- 45.85.93.177
- 5.181.156.90
- 176.98.40.6
- 185.208.158.30
- 45.89.55.4
- 94.140.115.89
- 45.82.13.121
- 77.91.74.55
- 185.178.231.30
- 46.8.228.233
- 213.165.63.179
- 94.131.96.82
- 104.194.150.61
- 104.194.149.9
- 45.84.0.235
- 145.249.109.202
- 78.153.130.43
- 94.232.249.17
- 62.60.234.87
- 94.183.189.68
- 91.239.148.54
- 23.177.184.108
- 103.80.86.26
- 87.121.52.9
- 80.85.241.183
- 193.124.44.66
- 147.45.125.58
- 141.98.233.53
- 62.133.62.99
- 185.232.205.198
- 147.45.60.149
- 91.239.148.151
- 94.140.112.17
- 185.225.17.32
- 195.133.88.73
- 31.57.29.202
- 95.163.152.28
- 46.29.238.44
- 46.29.238.184
- 145.223.68.34
- 193.17.183.18
- 79.132.135.171
- 195.133.88.72
- 185.121.15.235
- 85.192.27.166
- 62.60.159.248
- 185.219.7.231
- 185.161.251.123
- 181.214.58.65
- 185.196.8.140
- 209.200.246.58
- 94.183.187.222
- 193.233.193.65
- 81.19.140.125
- 85.192.26.92
- 185.143.238.166
- 194.180.158.26
- 31.15.16.216
- 38.180.116.107
- 156.227.6.32
- 193.233.193.90
- 195.133.88.48
- 104.194.143.96
- 185.234.66.126
- 86.54.42.84
- 185.250.180.171
- 45.143.200.29
- 5.182.86.132
- 185.234.66.239
- 168.100.11.21
- 5.252.178.167
- 195.133.88.10
- 185.219.7.53
- 45.85.93.246
- 178.22.31.6
- 91.92.43.242
- 104.194.149.73
- 31.56.117.251
- 103.80.86.66
- 193.56.135.81
- 195.133.88.59
- 31.13.195.87
- 194.87.97.75
- 5.252.23.100
- 216.185.57.42
- 64.190.113.62
- 23.177.185.118
- 194.87.186.215
- 5.252.178.168
- 81.19.141.191
- 185.232.205.16
- 103.136.69.227
- 31.192.236.13
- 185.39.207.45
- 193.17.183.123
- 77.75.230.221
- 213.218.212.59
- 80.77.25.194
- 103.231.75.120
- 185.208.158.23
- 88.218.248.182
- 147.45.124.28
Additional Informations
- Energy
- Finance
- Transport
- Hospitality
- Government and administrations
- Defense
- Ukraine