A US court filing names nine people behind the hacker group NoName057(16), including the director and deputy director of a youth-monitoring centre set up by Kremlin decree. Read alongside sanctions files and new prosecutions across Europe, it shows how Russia's 'volunteer' hackers are organised, paid and aimed at NATO countries, and what they are likely to try next.
THE SHORT VERSION
- A US federal indictment filed in Los Angeles in August 2025, and available in a public court archive, names nine alleged members of NoName057(16). NoName is the pro-Russian group behind years of attacks that knock websites offline across NATO countries.
- It says the group's leaders were the chief executive and deputy director of CISM. CISM is a Moscow organisation created by presidential order in 2018, and Russia's 2026 budget allocates it just over 1 billion roubles.
- The deputy director, Mikhail Burlakov, is accused of paying for the group's servers in cryptocurrency. He denies involvement.
- A separate group, Cyber Army of Russia Reborn, was steered by a handler known as "Cyber_1ce_Killer", whom the US and UK link to Russian military intelligence. In 2024 he told the group to stop knocking websites offline and start breaking systems instead. No government has published his real name.
- That shift is now visible on the ground: interference with water plants, a dam and heating plants in Denmark, Norway, Sweden and Poland.
- What's next: almost certainly more website attacks timed to elections and aid decisions. Probably more break-ins at small water, heating and other control systems this winter. Less likely, but most serious: a state-run destructive attack on energy or on the supply lines that carry aid to Ukraine.
- What the evidence does not show: that any of this is preparation for a Russian invasion of a NATO member.
How the pieces connect, according to court filings, sanctions designations and official advisories. Every link is an allegation or an official attribution, not a court finding. Graphic: Valdrans.
Three payments, one state-created centre
In short: the money that kept NoName's servers running was small. The organisation the court filing says sent it is not.
On 28 December 2022, according to US prosecutors, Mikhail Evgenievich Burlakov sent 1.13762 Litecoin to a cryptocurrency wallet that NoName057(16) used to pay a hosting company. That company was hosting one of the group's command servers. He sent 1.485451 Litecoin in February 2023 to pay for proxy servers, and 3.99737 Litecoin that August.[^1]
That comes to 6.62 Litecoin, well under $1,000 at the prices of the time. It is hardly a war chest. But the indictment says Burlakov was not a freelance enthusiast. It describes him as deputy director of the Center for the Study and Network Monitoring of the Youth Environment (CISM), and says he reported to its chief executive, Maksim Nikolaevich Lupin.[^1]
CISM, the indictment states, "was an information technology organization established by order of the President of Russia in October 2018". Publicly, it monitored online risks to Russian children. Covertly, prosecutors allege, it ran projects that included "administrating and coordinating NoName057(16)'s cybercampaign".[^1]
Burlakov has denied the accusations. Responding to the Russian-language outlet Vot Tak in April 2026, he said European authorities had "dragged random people into completely unclear criminal cases". A Telegram account linked to Lupin's phone number called the accusations "some kind of mistake".[^2]
The nine names
In short: the public US announcement named one defendant. The court filing names nine and gives each a role.
When the US Justice Department announced charges against NoName in December 2025, the only person it named was Victoria Dubranova, a Ukrainian national extradited to the United States.1 The first superseding indictment in the same case (United States v. Dubranova et al., Central District of California, case 2:25-cr-00578, document 33, filed 21 August 2025) goes much further. A copy is in CourtListener's public RECAP archive.2
| Defendant (as named in the indictment) | Handles listed | Alleged role |
|---|
| Maksim Nikolaevich Lupin | s3rmax, Ya0ff, dobriydobr | CISM chief executive; monitored members who scouted targets; logged into the target-probing server |
| Mikhail Evgenievich Burlakov | Ddosator3000, mdklogo, darkklogo | CISM deputy director; paid hosting firms in cryptocurrency; logged into a server used to probe EU and Polish critical-infrastructure sites "at least 1,772 times" |
| Roman Omelchenko | kintechi341, timnik84, lokki149, kostya | CISM employee; edited code for DDoSia, the group's attack tool; recruited Evstratova to CISM using an official CISM email address |
| Olga Denisovna Evstratova | olechochek, smallwhitedoses | Joined CISM as a programme developer in 2023; edited DDoSia code from a GitHub account registered to a CISM email address; tracked the group's Telegram reach |
| Nikita Aleksandrovich Petukhov | huskyray, kaptiin-tuckhov | Added a "targets dropdown" and a domain-checker function to DDoSia |
| Valeriy Valeriyovich Zaborovsky | NN05716, NoNM05716, K1X_K1X_K1X | Administered NoName's Telegram channels, picked targets and recruited members |
| Vitaly Anatolyevich Zubets | vetal2020 | Moderated the public channels and taught recruits how to run DDoSia |
| Andrei Stanislavovich Abrosimov | tuxarch, ponyashka, gentux79 | Rented servers that generated the heaviest attack traffic against German websites in May 2024 |
| Victoria Eduardovna Dubranova | Vika, Tory, Sovasonya | Made promotional and recruitment videos |
All are allegations by US prosecutors. None has been proven in court. Everyone except Dubranova is described as a resident of Russia and is beyond the reach of US courts.
Four of the nine (Lupin, Burlakov, Evstratova and Abrosimov) also appear on Germany's wanted list from Operation Eastwood, the July 2025 action in which police in 12 countries took more than 100 of NoName's systems offline, executed 24 searches and issued seven arrest warrants.3 The German listing gives several names in different spellings, for example "Mihail" Burlakov and "Avrosimow".
The indictment also shows how the attacks were timed. On 27 September 2024, it says, Zaborovsky sent members six Austrian websites, including a bank and railway sites, explaining that "elections [w]ere coming in Austria" and "We want to rip them off". A week before Belgium's local elections in October 2024, the group posted a list of Belgian municipalities and port websites to attack. During the NATO summit in The Hague in June 2025, it claimed attacks on Dutch transport organisations.2
A patent, a budget line and a sanctions list
In short: three public Russian and EU records support the indictment's picture of CISM. None of them proves a crime.
The patent. Russian patent RU2829699C1, filed in December 2023 and published in November 2024, belongs to CISM. Its five listed inventors include Mikhail Evgenievich Burlakov and Roman Nikolaevich Omelchenko. It covers a method for checking whether web resources and their content can be reached.4 The US indictment names a "Roman Omelchenko" as a CISM employee who edited DDoSia's code. The indictment gives no middle name, so Valdrans cannot rule out two different men with the same name. But the shared employer and the shared co-inventor make it a strong match. Valdrans has found no evidence that the patented system was used in attacks.
The budget. Appendix 23 of Russia's federal budget law of 28 November 2025 allocates CISM a subsidy of 1,019,017,500 roubles for 2026, and slightly more for 2027 and 2028, for monitoring online content that threatens children.5 That is an allocation, not a record of spending. Nothing Valdrans has seen connects that money to NoName's payments. Russian reporting puts CISM's state funding since 2019 at "at least 2 billion roubles".6
The sanctions list. On 28 September 2026 the European Union added CISM to its sanctions list. The grounds were not hacking: the EU cited the deportation and forced assimilation of Ukrainian children.7 The designation does not test the US allegations, but it means CISM is now under EU sanctions.
What the records don't say. The official records say almost nothing about where these men come from. Germany's wanted notice for Lupin lists his place of birth as unknown. The Russian outlet Agentstvo has reported that Burlakov held academic posts at Samara University and previously at MEPhI, a Moscow engineering university.6 Valdrans has not independently confirmed this. We have left out home addresses and family details, which add nothing to the public-interest case.
Three ways the money moves
In short: the attackers are paid in one stream, the infrastructure in another and the GRU's own groups in a third. Each is documented separately. No public record yet ties them together end to end.
1. Paying the volunteers. NoName recruits volunteers to run DDoSia from their own computers. The indictment says the group published a daily leaderboard and paid "top-ranking members in cryptocurrency through a wallet server within the DDoSia infrastructure".2 In 2022, researchers saw prizes of 80,000, 50,000 and 20,000 roubles for the top three.8 Radware researchers who joined undercover reported that from March 2023 payouts moved to the TON cryptocurrency through Telegram's CryptoBot, worth roughly $2 to $30 a day to top participants.9 By 2026, according to an investigation by Vot Tak and RKS.Global, volunteers earned an in-house token, the "dCoin", worth about 2.4 US cents and convertible to TON. Fifty dCoins were paid for 500,000 successful requests a day. The investigation also found that monthly attack commands rose after Operation Eastwood, from about 6,300 to 7,708.10
2. Paying for the servers. In 2023 the threat-intelligence firm Team Cymru traced most of NoName's attack infrastructure to two linked hosting providers, MIRhosting and Stark Industries.11 The EU sanctioned Stark Industries and its owners, Iurie and Ivan Neculiti, in May 2025.12 Recorded Future then documented the business re-emerging under new branding through a Dutch company, WorkTitans B.V.13 On 18 May 2026 the Dutch fiscal investigation service FIOD arrested two men and seized about 800 servers on suspicion of breaching EU sanctions. Media reporting later linked the case to Stark, MIRhosting and WorkTitans. MIRhosting denies any wrongdoing and says it is cooperating with the authorities.14 De Volkskrant reported that WorkTitans and MIRhosting networks were the ones most used in attacks on Danish authorities in November 2025.15
3. Paying for the GRU's groups. The second prosecution concerns Cyber Army of Russia Reborn (CARR). According to the US Justice Department, CARR was "founded, funded, and directed" by Russian military intelligence, the GRU. Its handler's "organization financed CARR's access to various cybercriminal services", including subscriptions to rented attack services.1 The CARR indictment says payments to one such service, Stresser.tech, were arranged and converted from roubles.16 No amounts have been published.
The missing link. No public record yet connects a specific wallet to a specific hosting account to a named operator. The three Litecoin transfers come with no transaction IDs or wallet addresses. Until those court exhibits become public, nobody outside the prosecution can reconstruct the money trail independently.
"If we hit Kyiv with missiles, we won't need DOS"
In short: the person who steered CARR is known only by his online name. What he told the group in 2024 marks the shift from nuisance attacks to sabotage.
In the CARR indictment, the handler appears only as "FNU LNU" (first name unknown, last name unknown), alias "Cyber_1ce_Killer", alias "Commander".16 Two of the overt acts quote him directly:
- 27 March 2024: his organisation "would no longer fund CARR's DDoS efforts". CARR should focus on getting "information for the war, namely, to destroy the information resources and systems of the enemy".
- 28 March 2024: DDoS "was closed" for CARR "because it does not cause any damage", and "[i]f we hit Kyiv with missiles, we won't need DOS".
(DDoS, or DOS, means distributed denial-of-service attacks, which knock websites offline by flooding them with traffic.)
According to the indictment, his co-conspirators believed he was a Russian government agent and called him "Commander". US prosecutors and the UK government both say the online name is associated with "at least one GRU officer".117 The UK says CARR and its offshoot Z-Pentest are linked to GRU Unit 74455, the unit Western governments call Sandworm.17
Valdrans has not identified Cyber_1ce_Killer, and no government, court or credible news outlet has published a real name for him. We have deliberately not tried to match his online name to individuals. In a story about intelligence officers, getting that wrong could put an innocent person at risk.
The people around him are named:
- Yuliya Vladimirovna Pankratova, described as CARR's leader, and Denis Olegovich Degtyarenko, described as its main hacker, were sanctioned by the US in July 2024.18 The UK and the EU sanctioned them on 13 July 2026. The same EU package listed Z-Pentest itself, citing its December 2024 attack on a Danish water utility.19
- Victoria Dubranova is charged in both US cases. The Justice Department's announcement says she pleaded not guilty.1 CyberScoop and the Kyiv Independent have since reported that she pleaded guilty in both cases.20 Valdrans has not confirmed her plea status on the court docket.
- Artem Revenskii, known as "Digit", of the CARR spin-off Sector16, pleaded guilty in Los Angeles on 30 April 2026, according to the Kyiv Independent. Prosecutors say messages show him discussing physical damage, including "deforming pipelines" and overloading gas-extraction equipment. His alleged targets included oil and gas sites in Germany, France and Latvia.21
From websites to valves
In short: the "hacktivists" are now reaching into the control systems that run water, heating and power. So far the damage has been small. The intent is not.
The method is crude. A December 2025 advisory issued by US agencies with Europol and partners in more than a dozen countries sets out how it works.22 The groups scan the internet for exposed remote-access screens on VNC ports 5900–5910 and get in with default, weak or blank passwords. Once on a plant's control screen, they change settings, rename devices, switch off alarms and lock operators out. Then they post a screen recording to Telegram. The advisory says victims are chosen mainly because they are reachable, not because they matter strategically.
The results so far:
| When | Where | What happened | Attribution |
|---|
| Jan 2024 | Muleshoe, Texas, US | Water tank overflowed | Claimed by CARR; cited by US Treasury18 |
| Dec 2024 | Køge area, Denmark | Destructive attack on a water utility | Z-Pentest, "links to the Russian state" (Danish military intelligence; EU)1923 |
| Apr 2025 | Bremanger, Norway | Dam valve opened for about four hours | Pro-Russian actors (Norway's security police, PST)24 |
| Early 2025 | Sweden | Attempted destructive attack on a thermal power plant | Group tied to Russian services (Swedish government, Apr 2026)25 |
| Sep 2025 | Jabłonna Lacka, Poland | 2,500 residents without water for six hours | Two Russians charged, Aug 2026 (suspects in Russia)26 |
| 29 Dec 2025 | Poland | Destructive attacks on more than 30 renewable sites and two combined heat-and-power plants. At the smaller plant a steam turbine and process-water treatment shut down; heat to 50,000 residents was not interrupted | Split (see below)27 |
| Sep 2026 | Latvia | About five intrusions into municipal CCTV and smart-building systems | "Clear link… to Russia" (CERT.LV)28 |
The Polish case shows how hard attribution can be. Poland's national computer emergency team, CERT Polska, found that the attack infrastructure overlapped with a cluster tied to Russia's FSB security service (Static Tundra or Berserk Bear). The Slovak security firm ESET attributed the wiper malware to the GRU's Sandworm with "medium confidence".2729 Both may be partly right. The disagreement deserves a direct answer from both organisations.
In April 2026, Sweden's civil defence minister Carl-Oskar Bohlin summed up the trend: "Pro-Russian groups that once carried out denial-of-service attacks are now attempting destructive cyber attacks."25
Is this a rehearsal for attacking NATO?
In short: official assessments describe escalating sabotage and a small but growing military risk. None describes a planned invasion.
The question behind this investigation was whether Russia might attack a NATO member to test Article 4 or Article 5. Article 4 only provides for consultations, which any ally can request when it feels threatened. Poland invoked it after Russian drones crossed its airspace in September 2025. Article 5 covers collective defence. NATO says a serious cyberattack could trigger it, case by case, but nothing triggers it automatically.30
The most recent official judgement comes from Danish military intelligence, published on 24 September 2026. It expects Russia to "intensify its hybrid war", with more frequent attacks with "greater consequences", including destructive cyberattacks. It sees a "low but growing" risk of limited military strikes on a NATO state bordering Russia. It calls a full-scale invasion "highly unlikely".31 Estonia's foreign intelligence service said in February 2026 that Russia had no intention of attacking a NATO member in the coming year, provided deterrence held.32
Physical sabotage is running in parallel. On 29 September 2026, Estonia's prime minister said the August arson at a warehouse of Milrem Robotics, a Tallinn firm that supplies unmanned ground vehicles to Ukraine, was "commissioned by the special services of the Russian Federation". Three Latvian suspects are in custody. The Kremlin calls the accusation baseless.33 No cyber element has been reported in that case. A pro-Kremlin Telegram post shared with Valdrans, whose original timestamp we have not been able to verify, both disputes Russian involvement in these incidents and openly urges strikes on Western arms factories.
What comes next: three scenarios for October 2026 to March 2027
These are Valdrans' relative judgements based on the evidence above. They are not intelligence or probabilities, and the scenarios can overlap.
Tier 1: almost certain. Website attacks timed to politics.
NoName-style campaigns will knock government, transport and banking websites offline around political flashpoints. Likely moments include Latvia's parliamentary election (3 October), Czech Senate and local elections (9–10 October), Bulgaria's presidential election (25 October), the US midterms (3 November), European Council meetings in October and December, the fourth anniversary of Russia's full-scale invasion on 24 February 2027, and Estonia's parliamentary election, with internet voting from 1 to 6 March and election day on 7 March 2027.34
Why: the indictment documents exactly this pattern in Austria, Belgium and the Netherlands.2 The EU cybersecurity agency ENISA counted 4,709 hacktivist claims in its 2026 report, more than 89% of them denial-of-service attacks, clustered around elections.35 Operation Eastwood did not stop the activity.10
Limits: in past cases a website going down has not meant trains stopping or votes being changed. Latvia and Denmark count ballots by hand.
Tier 2: likely. Opportunistic break-ins at small control systems.
Water works, district heating, small dams and building-management systems in Poland, the Baltic states, the Nordic countries and Germany are the probable targets, with heating plants of particular interest in winter. Expect short local outages, followed by exaggerated claims online.
Why: the method is cheap, documented and still working. The latest example is Latvia's municipal CCTV and smart-building systems in September 2026.222628
Limits: operators have so far contained most incidents. No deaths or injuries have been reported.
Tier 3: less likely, highest consequence. A state-run destructive attack.
A GRU or FSB unit could use access it already has to damage energy systems, or companies in the supply chain carrying aid to Ukraine, possibly alongside physical sabotage or a limited military provocation.
Why it is credible: the December 2025 Polish attacks were destructive by design.27 A 2025 advisory from 18 countries documented GRU spying on aid logistics, including more than 10,000 attempts to access internet-connected cameras, most of them in Ukraine and some watching border crossings.36 Danish intelligence expects attacks "with greater consequences".31
Why it ranks lower: coordinating real damage across several organisations takes preparation, risks exposure and escalation, and can be stopped. The Polish wiper was blocked.
What would change this assessment: authenticated orders issued before an attack; independently linked intrusions in several countries; operators confirming physical effects; or court exhibits tracing the money. An alarming Telegram post or a recycled video of a control screen is not enough.
What we know, what's alleged, what's unknown
| Status | Item |
|---|
| Established in public records | CISM was created by presidential order and receives state budget funding; Burlakov and a Roman Nikolaevich Omelchenko are named inventors on a CISM patent; sanctions on Pankratova, Degtyarenko, Z-Pentest and CISM; the Polish, Danish and Latvian incidents |
| Alleged (indictments, not convictions) | That CISM staff ran NoName; Burlakov's Litecoin payments; Cyber_1ce_Killer's instructions; that the GRU funded CARR |
| Official attribution (intelligence-based) | Links between the GRU and CARR/Z-Pentest; Russian state links to Z-Pentest; Russian services behind the Milrem arson |
| Disputed | FSB or GRU behind the Polish grid attack; Dubranova's plea |
| Unknown | Cyber_1ce_Killer's identity; the wallet-to-host money trail; any plan to attack NATO militarily |
Method: this article draws on public court filings (the NoName indictment was read page by page from the archived PDF; SHA-256 hash recorded in the evidence ledger), sanctions designations, government statements, patent and budget records, and published research. Valdrans did not enter private hacker channels, buy criminal services or contact operators. Criminal allegations are not convictions. Requests for comment to CISM, Burlakov, Lupin, MIRhosting, CERT Polska and ESET are pending.