Infrastructure Destruction Squad targets ICS/SCADA in metallurgy and food processing sectors.
Analyst brief
Infrastructure Destruction Squad (Dark Engine) is a threat actor actively targeting industrial control systems (ICS/SCADA) in metallurgy and food processing sectors, with a notable operational surge in June 2025. The group also conducts credential harvesting campaigns by embedding fraudulent CAPTCHA prompts into legitimate WordPress websites, leveraging SEO poisoning techniques. Their key TTPs include ICS-targeted intrusions, web-based social engineering for credential theft, and data leak operations, as evidenced by exposed U.S. phone data. Defenders should monitor SCADA networks for anomalous connections, train users against CAPTCHA-based credential harvesting, and ensure web security patches are up-to-date.
Infrastructure Destruction Squad
Dark Engine
unknown
Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing. The group has conducted multiple ICS-targeted incidents, with a pronounced operational surge in June 2025. Additionally, Dark Engine is involved in a campaign that embeds fraudulent CAPTCHA prompts into legitimate WordPress sites, utilizing SEO poisoning to harvest login credentials. Reports also indicate a data leak from Dark Engine that exposed sensitive phone data in the U.S.
Which industrial sectors does Infrastructure Destruction Squad target?+
Infrastructure Destruction Squad (Dark Engine) actively targets ICS/SCADA systems, primarily in the metallurgy and food processing sectors.
What technique does Dark Engine use to steal user login credentials?+
Dark Engine uses SEO poisoning to embed fraudulent CAPTCHA prompts into legitimate WordPress sites, harvesting user login credentials through this method.