Since NoName057(16) is no more, I might as well reveal how I tracked them now.
It’s super dumb.
I cosplayed as a Russian supporter (under my real name btw, I have nothing to hide), then actually ran their Ddosia client from a PC which could only access their C2 (so couldn’t actually execute attacks).
I used video game modding tools to automatically extract the AES encrypted config ( ) and automatically dump it into Excel spreadsheets so defending orgs knew what to block.