Infrastructure Destruction Squad
Infrastructure Destruction Squad is a threat actor also identified in the provided content as Dark Engine. The content describes it as a Russian-aligned actor that has evolved beyond low-impact DDoS activity into OT/IoT reconnaissance and claimed disruptive targeting of industrial systems. Reported tradecraft includes exploiting internet-facing VNC connections and HMI devices with default or weak credentials to access OT control systems. The actor was cited in reporting on a claimed compromise of Venice’s San Marco flood defense and hydraulic pump system, where it said it had obtained administrative or root-level access, published screenshots of control interfaces, claimed it could disable defenses and flood coastal areas, and offered access for sale via Telegram. Authorities reportedly stated that systems directly protecting the Basilica di San Marco were unaffected. The content also states that Infrastructure Destruction Squad announced BLACKNET-00 on Telegram, described as a GUI-driven ransomware builder sold for $500 and marketed as requiring no programming knowledge. No additional verified sub-groups are identified in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Capital Goods
- Food, Beverage & Tobacco
- Military
Where they target
Geographies tied to known operations.
- 🇩🇪 Germany
- 🇮🇹 Italy
- 🇵🇱 Poland
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-aligned hacktivist group conducting OT/IoT reconnaissance and claimed disruptive attacks against industrial targets; also claimed access to industrial networks in Germany, Italy, and Poland.
Claimed breach of Venice's San Marco flood defense OT system, alleging control of hydraulic pumps and the ability to disable defenses and flood coastal areas; also offered root access for sale to expose infrastructure weaknesses and apply political pressure.
Claimed compromise of Venice’s San Marco flood defense hydraulic pump system, asserting administrative/root access, ability to disable flood defenses, release OT control screenshots, and sell access to the control system.
Advertised and promoted the BLACKNET-00 ransomware builder/RaaS platform via Telegram, lowering the barrier to entry for ransomware deployment through a GUI-driven builder with encryption, evasion, C2, exfiltration, and propagation features.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.