Hacktivist group

SoubearArmy

SoubearArmy appears in public reporting primarily as one of several hacktivist “ally” brands publicly aligned with the pro‑Russian DDoS ecosystem centered on NoName057(16) and its crowdsourced DDoS tooling (“DDoSia”). Public reporting describes an “alliance” including SoubearArmy and other groups, notably connected to attacks against Italian infrastructure, but provides limited independent, actor‑unique technical artifacts directly attributable to SoubearArmy.

Given the available OSINT, the most defensible analytic stance is to treat SoubearArmy as a label within a broader pro‑Russian hacktivist coalition rather than as a fully distinct intrusion set with unique tooling. Where activity is observed, it is most plausibly expressed through commodity DDoS operations (HTTP floods and related volumetric methods) and/or participation in shared “call‑to‑action” targeting cycles published via Telegram channels affiliated with the wider ecosystem.

Confidence in the coalition linkage is medium (reported “alliance” announcements in multiple sources). Confidence in any specific, independent SoubearArmy infrastructure or bespoke tooling is low due to a lack of uniquely attributable indicators in open reporting. Analysts should therefore model SoubearArmy as a campaign tag for coalition activity and track it as part of NoName057(16)/DDoSia‑style operations, with conservative attribution.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-25