Infrastructure Destruction Squad (IDS), also using the name Dark Engine, is a pro-Russia threat actor that emerged in 2025 and has been associated with disruptive operational technology and industrial control system activity. The group has been linked to Russian-aligned hacktivist and influence-driven operations that evolved from lower-impact disruptive activity into OT and IoT reconnaissance, attempted industrial disruption, and the commercialization of offensive tooling aimed at critical infrastructure environments. IDS has been reported targeting industrial and critical infrastructure systems, including water, flood-control, smart-building, and broader ICS environments. Reported activity includes claimed administrative access to flood-defense infrastructure in Venice, alleged attacks against an Italian smart building automation company, and reported victimology spanning Italy, Ukraine, Romania, and the United States. The group has also been discussed alongside other Russian-aligned actors exploiting internet-facing remote access and human-machine interface systems, particularly where default or weak credentials expose OT control paths. The actor is notable for monetizing OT-focused capabilities. IDS advertised OT attack tooling including a SCADA scanner naming major industrial vendors, and it has been associated with an ICS-specific malware family called VoltRuptor, described as incorporating persistence and anti-forensics features. IDS also announced BLACKNET-00, a low-cost GUI-driven ransomware builder marketed to lower-skill operators. Reported BLACKNET-00 functionality includes payload generation, encryption, data theft, persistence, anti-analysis, command-and-control resilience, and local-network propagation, indicating an effort to lower the barrier to ransomware and extortion operations. Across reporting, IDS demonstrates interest in reconnaissance of exposed industrial assets, disruptive access to OT environments, persistence, defense evasion, and post-compromise monetization. Its activity aligns most closely with pro-Russian politically motivated operations, while also showing a financial component through the sale of malware, access, and ransomware tooling. Because some publicly reported incidents rely in part on actor claims, attribution for specific intrusions should be treated cautiously unless independently confirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Telegram-based group monetizing OT/SCADA attack tooling, including scanners and claimed PLC/SCADA attack capabilities, in parallel to the water-sector PLC targeting discussed in the article.
Russia-aligned hacktivist group conducting OT/IoT reconnaissance and claimed disruptive attacks against industrial targets; also claimed access to industrial networks in Germany, Italy, and Poland.
Claimed breach of Venice's San Marco flood defense OT system, alleging control of hydraulic pumps and the ability to disable defenses and flood coastal areas; also offered root access for sale to expose infrastructure weaknesses and apply political pressure.
Claimed compromise of Venice’s San Marco flood defense hydraulic pump system, asserting administrative/root access, ability to disable flood defenses, release OT control screenshots, and sell access to the control system.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.