Infrastructure Destruction Squad (IDS) is a pro-Russian, hacktivist-aligned and financially motivated threat cluster active through Telegram and criminal forums. It is also known as BLACKNET, BLACKNET-CORPORATE, BLACKNET-00, and Dark Engine. The group combines promotional ransomware activity, offensive-tool and access sales, and reconnaissance focused on internet-exposed operational-technology (OT), industrial-control-system (ICS), and cloud-service environments. IDS has been linked to Russian interests, although it is not established as a Russian state-directed actor. IDS publicly released the BLACKNET-00 ransomware builder, a GUI-driven tool that generates Windows ransomware payloads. Analysed payloads encrypt targeted files, alter endpoint policies, establish Registry Run and scheduled-task persistence, terminate selected security and analysis processes, perform limited virtual-machine checks, capture screenshots, present ransom messaging, and transmit victim telemetry to Telegram. Although marketed as AES-based ransomware, analysed builds use weak repeating-key XOR encryption and expose the decryption key in the ransom note, substantially weakening the ransomware's effectiveness. The cluster has also distributed Shadow Ghost, which performs reconnaissance for publicly exposed Firebase Storage, Firestore, and Realtime Database resources caused by permissive configuration. Its TRK-25 tooling contains code for OT and ICS exposure discovery, industrial service scanning, product fingerprinting, and Modbus/TCP register and coil interactions. The available TRK-25 sample was incomplete and several advertised capabilities could not be validated. IDS has advertised DDoS services and claimed disruptive compromises of critical infrastructure, but such operational claims are not established. The group has been associated with targeting in Italy and the United States, particularly environments involving industrial and OT systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal cluster operating via Telegram and criminal forums, promoting and offering a ransomware builder, a Firebase-focused scanner, and an ICS scanner; also advertising DDoS-as-a-Service and sharing tools with third-party groups.
A hybrid ransomware author, offensive-tool vendor, access broker, and hacktivist-flavoured extortion cluster. Its BLACKNET-00 ransomware builder produces a functional but cryptographically weak payload; Shadow Ghost performs Firebase misconfiguration reconnaissance; and TRK-25 contains credible ICS/SCADA discovery, industrial fingerprinting, and near-operational Modbus logic. Many wider compromise, ICS-impact, and DDoS claims remain self-reported or unverified.
Telegram-based group monetizing OT/SCADA attack tooling, including scanners and claimed PLC/SCADA attack capabilities, in parallel to the water-sector PLC targeting discussed in the article.
Russia-aligned hacktivist group conducting OT/IoT reconnaissance and claimed disruptive attacks against industrial targets; also claimed access to industrial networks in Germany, Italy, and Poland.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.