NoName057(16) are targeting the UK today, so I shall start monitoring them and naming their targets and attack types.

Their targeting: https://raw.githubusercontent.com/GossiTheDog/Monitoring/main/NoName/targets_2023_12_07_11am.txt

Currently:
pa.eastcambs.gov.uk
politics.leics.gov.uk
www.liverpool.gov.uk
www.mil.be
www.bollington-tc.gov.uk
www.cranbrooktowncouncil.gov.uk
cert.be
my.swiftcard.org.uk
www.monarchie.be
www.premier.be
www.david-clarinval.be
www.dekamer.be
www.senaat.be

#threatintel #noname

Note this list includes targets they haven't announced yet on Telegram.
Keep up, NoName. Edit: to be clear I mean catch up as I already named these.

quick question - would publishing the NoName DDoS targets in a format like this each day be valuable?

I just had a quick workflow play, I think I can do it.

#threatintel

This is how NoName[16] are DDoSing West Yorkshire Metro.. apparently it's enough to cause Azure App Gateway to fall over.

Later today #NoName will announce they are attacking:

cts21.czechtrade.cz
www.mzv.cz
klient.czechtrade.cz
www.czechtrade.cz
exporters.czechtrade.cz
www.dpp.cz
www.pse.cz
www.moneta.cz
api.moneta.cz
www.rzp.cz
www.senat.cz
pspen.psp.cz
www.vlada.cz
www.mvcr.cz
www.financnisprava.cz
www.policie.cz
www.prg.aero
gate.prg.aero
newfids.prg.aero
ftp.prg.aero
fids.prg.aero
idc-portal-tas.prg.aero

Target list: https://github.com/GossiTheDog/Monitoring/blob/main/NoName/targets_2023_12_08_10am.txt

#precrime #threatintel

Monitoring/NoName/targets_2023_12_08_10am.txt at main · GossiTheDog/Monitoring

Contribute to GossiTheDog/Monitoring development by creating an account on GitHub.

GitHub
@GossiTheDog I suspect nobody in #Czech government agencies is paying attention to your posts. Wonder if anyone in my circles can forward to someone...
@drizzy @GossiTheDog
It doesn't really matter, once a website is on the targetlist it is already being attacked.
It might buy them a couple of minutes but in practice that won't do much.
NN only mentions successful attacks on their Telegram.
Not to burst any bubble but Kevin isn't predicting anything, he extracts the active targetlist from their DDoS client and publishes it in full, whereas NN only publishes sites that went down.