🔴 [LATEST] IRAN DEPLOYS 2 CYBER FRONTS: HANDALA TARGETS ISRAEL, CYBERAV3NGERS TARGETS US    ◆    🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS

~/Threat Intelligencearticle

Threat Intelligence

NoName057(16) Resumes #OpRomania: DDoS Attacks Target Shipping and Logistics Sector

> By Haider | Aug 04, 2026 | 4 min read

The notorious pro-Russian hacktivist syndicate NoName057(16) has launched a fresh wave of Distributed Denial of Service (DDoS) attacks against Romania, reviving their ongoing #OpRomania campaign. This latest offensive specifically targets the critical shipping and logistics sectors of the Eastern European nation. The aggressive cyber operations serve as direct retaliation against recent geopolitical and defense-industrial developments between Romania and Ukraine, highlighting how civilian infrastructure continues to bear the brunt of digital proxy conflicts.

NoName057(16)

> TABLE_OF_CONTENTS [toggle]

The Catalyst: Drone Production in Cluj-Napoca

According to the official manifesto posted on their primary Telegram channel, NoName057(16) explicitly cited a newly announced defense agreement as the trigger for this attack. Romanian technology firm OVES Enterprise and Ukrainian defense contractor EDRONE recently finalized an agreement to jointly produce military drones in the Romanian city of Cluj-Napoca. The partnership is slated to manufacture a variety of unmanned aerial vehicles (UAVs) based on the Baton series, including FPV (First-Person View) combat drones, interceptor drones, and specialized reconnaissance units.

The hacktivist group viewed this industrial cooperation as a direct provocation and an escalation of Romania’s support for the Ukrainian war effort. In a menacing statement directed at Bucharest, the group wrote: “Romania is in no hurry to learn the lessons of our past attacks. Well, let’s repeat it again.” This rhetoric aligns perfectly with the group’s established modus operandi: punishing European Union and NATO member states that offer military, financial, or logistical aid to Ukraine.

Targeting the Shipping and Logistics Arteries

To execute their warning, the threat actors directed their formidable botnet against the digital infrastructure of key Romanian maritime and transport companies. The confirmed victims of this specific campaign include Midmar Star Agency, a prominent Romanian shipping resource, and Lion Shipping & Chartering SRL, a major transport and logistics enterprise.

The attackers successfully overwhelmed multiple endpoints associated with these companies. The evidence provided by the group includes “check-host” validation links proving that the main web resources, authorization portals, and critical subdomains of both Midmar Star Agency and Lion Shipping & Chartering SRL were rendered inaccessible. By disrupting authorization portals, the attackers not only take down public-facing websites but also severely impact the internal administrative capabilities of these logistics firms, potentially causing delays in cargo processing and supply chain management.

Claim / Threat Activity Source Status
DDoS attack targeting Midmar Star Agency web resources Telegram Post Verified
Disruption of Lion Shipping & Chartering SRL authorization portals Check-Host Reports Verified

The Mechanics of DDoSia and Hacktivist Tactics

The technical backbone of these disruptions is the “DDoSia” project, a custom-built, crowdsourced DDoS toolkit developed and maintained by the group. Unlike traditional botnets that rely on compromised IoT devices or malware-infected computers, DDoSia operates on a volunteer model. Sympathizers voluntarily install the software on their own machines, essentially renting out their bandwidth to participate in coordinated layer 7 (application layer) attacks.

This decentralized approach allows the group to generate massive volumes of junk HTTP/HTTPS traffic, easily overwhelming the server resources of unprepared targets. Because the attack originates from thousands of legitimate, globally distributed IP addresses, mitigating the flood using simple geo-blocking or IP blacklisting is highly ineffective. The group’s persistent ability to take down authentication portals suggests they meticulously map out their targets’ infrastructure to identify the most resource-intensive bottlenecks.

Mitigating Geopolitically Motivated DDoS Threats

For organizations operating in critical sectors like shipping, logistics, and manufacturing within NATO-aligned countries, robust DDoS protection is no longer optional. Traditional firewalls are insufficient against modern, high-volume application-layer floods. Companies must implement enterprise-grade Web Application Firewalls (WAF) and utilize Content Delivery Networks (CDNs) capable of absorbing and scrubbing malicious traffic before it reaches the origin servers.

According to advisory guidelines published by the Cybersecurity and Infrastructure Security Agency (CISA), organizations should also ensure that critical administrative and authorization portals are heavily segmented and hidden behind secure VPNs, rather than being exposed directly to the public internet. This prevents hacktivists from easily targeting login endpoints to maximize backend database strain. As we have seen in previous attacks against Romanian infrastructure, the speed at which these politically motivated actors pivot between targets requires defenders to maintain a state of constant readiness and proactive threat intelligence monitoring.

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

> INTELLIGENCE_NOTICE

The report above detailing NoName057(16) Resumes #OpRomania: DDoS Attacks Target Shipping and Logistics Sector is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Haider

Lead Security Researcher & Malware Reverse Engineer specializing in deconstructing APT toolkits and validating underground breach claims.

> related_intel --suggest