Dark Engine is a pro-Russia-aligned hacktivist group identified in the provided reporting as part of a loosely connected ecosystem of Russia-linked hacktivist actors that expanded beyond DDoS into operational technology and industrial control system intrusions. The content places Dark Engine alongside groups such as Z-Pentest, Sector16, and CARR/Cyber Army of Russia Reborn as companion actors moving into attacks affecting industrial HMIs and critical infrastructure in the water, energy, and agriculture sectors. One cited reporting stream links Dark Engine to 26 ICS incidents in Q2 2025. The content does not provide additional confirmed aliases beyond "dark_engine". Based on the provided material, Dark Engine is associated with ICS/OT targeting and intrusion activity rather than only disruptive DDoS operations, but no further high-confidence details on specific tooling, victimology, or organizational structure are directly provided.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist companion group described as expanding from DDoS into operational technology intrusions affecting industrial HMIs in water, energy, and agriculture sectors.
Hacktivist group linked to ICS incidents during the 2025 increase in attacks against critical infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.