SYMBOLCOMMON_NAMEaka. SYNONYMS

Infrastructure Destruction Squad  (Back to overview)

aka: Dark Engine

Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing. The group has conducted multiple ICS-targeted incidents, with a pronounced operational surge in June 2025. Additionally, Dark Engine is involved in a campaign that embeds fraudulent CAPTCHA prompts into legitimate WordPress sites, utilizing SEO poisoning to harvest login credentials. Reports also indicate a data leak from Dark Engine that exposed sensitive phone data in the U.S.


Associated Families

There are currently no families associated with this actor.


References

There are currently no references.


Credits: MISP Project