Hacktivist group

OverFlame

OverFlame is a pro-Russia-aligned hacktivist brand repeatedly referenced in OSINT as an active participant in DDoS campaigns and coalition structures. In 2024, the actor is described as part of hacktivist “coalitions” and as operating alongside NoName057(16) in prominent DDoS waves (e.g., Austria-focused targeting ahead of elections). OSINT also places OverFlame within a broader ecosystem of pro-Russian hacktivist alliances that cross-promote and share operational capacity.

From 2025 onward, reporting increasingly links OverFlame to OT/critical-infrastructure narratives through collaboration/adjacency with Sector16 and Z-Pentest ecosystems, including claims of unauthorized access to industrial control interfaces. These OT-related claims are often framed as intimidation (“proof-of-access” screenshots/videos) and should be treated as variable-impact without victim-side validation.

Confidence is high that OverFlame is a real, active hacktivist brand participating in pro-Russia-aligned DDoS campaigns and coalition messaging. Confidence is medium regarding the actor’s direct OT/ICS intrusion capability, because much of the linkage appears via alliances, shared infrastructure narratives, and claim-driven reporting rather than consistent, independently validated technical artifacts.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-22