SYMBOLCOMMON_NAMEaka. SYNONYMS

Infrastructure Destruction Squad  (Back to overview)

aka: Dark Engine

Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing. The group has conducted multiple ICS-targeted incidents, with a pronounced operational surge in June 2025. Additionally, Dark Engine is involved in a campaign that embeds fraudulent CAPTCHA prompts into legitimate WordPress sites, utilizing SEO poisoning to harvest login credentials. Reports also indicate a data leak from Dark Engine that exposed sensitive phone data in the U.S.


Associated Families

There are currently no families associated with this actor.


References
2026-02-10GoogleGoogle Threat Intelligence Group
Beyond the Battlefield: Threats to the Defense Industrial Base
Infrastructure Destruction Squad
2025-06-03SecurityBrief AustraliaShannon Williams
Fake CAPTCHA scam targets 2,353 WordPress sites, warns CyberCX
Infrastructure Destruction Squad

Credits: MISP Project