Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Infrastructure Destruction Squad

Infrastructure Destruction Squad

TLP:CLEAR
Active

Also known as: Dark Engine, tracked as, the Newscaster Team, primarily exposing HMIs, Sector 16, coordinat, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, JokerDPR, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

Infrastructure Destruction Squad emerged as a significant adversary targeting industrial control systems (ICS) and SCADA networks in sectors such as metallurgy and food processing. Their operations intensified during June 2025, with multiple attacks on water treatment facilities in Italy, production lines at HYBUSUNG TECH, and monitoring interfaces of Jeonnam Technopark. Beyond physical sabotage, the group also engaged in cyber‑crime campaigns that embedded fraudulent CAPTCHA prompts into legitimate WordPress sites to harvest login credentials, leveraging SEO poisoning for credential harvesting. Detailed investigation by Group‑IB in January 2026 confirmed that Infrastructure Destruction Squad exploited a range of vulnerabilities to breach Italian water systems and other OT environments. Their tactics include automated phishing via Telegram, exploitation of known WordPress exploits for C2 staging, and the deployment of custom malware such as InvisiMole, VERMIN, and Anchor. The actor’s operations have shown advanced persistence capabilities, including the use of bulletproof hosting domains (e.g., demo‑cloud.space) to evade detection. The group remains primarily motivated by disruption rather than financial gain. Their campaigns often culminate in operational shutdowns or data exfiltration that can cripple critical services. Recent evidence also highlights a data leak exposing sensitive phone information within the United States, indicating their willingness to use publicly visible channels for broader sabotage objectives.

Goals & Targeting

Targeted Sectors

Defense
Government
Financial services
Manufacturing
Aerospace
Non profit
Energy
Telecommunications
Media
Education
Information technology
Critical infrastructure
Maritime
Healthcare
Think tank
Chemical
Pharmaceutical
Nuclear
Legal services
Mining
Transportation
Hospitality
Entertainment

Targeted Countries / Regions

US
CN
UA
RU
JP
IN
GB
DE
IR
KR
IL
FR
TW
SA
TR
CA
AU
KZ
PK
VN
PL
IT
AE
SG
NL
BR
ES
IQ
BY
SY
MX
RO
KP
EG
AZ

AI Analysis

Grounded in web research
· 2 hours ago

Executive Summary

Infrastructure Destruction Squad, also known as Dark Engine or Newscaster Team, is a pro‑Russian threat actor focused on disrupting industrial control and SCADA systems across a broad spectrum of sectors worldwide. They deploy automated phishing, supply‑chain compromise via compromised WordPress sites, and custom malware such as InvisiMole to infiltrate OT environments, causing potential operational shutdowns. Recent activity in 2025–2026 shows an increasing tempo against critical infrastructure in Europe and Asia.

Goals & Targeting

Infrastructure Destruction Squad targets a wide range of governments and industries—from defense and energy to maritime transport and healthcare—in order to cause systemic disruption and sow operational uncertainty. The actor focuses on countries with significant industrial outputs or geopolitical tensions (US, UK, Germany, China, Russia, Ukraine, Japan). By compromising SCADA systems and critical infrastructure, they aim to disrupt production, compromise safety protocols, and erode confidence in national security capabilities. Typical victims include water treatment plants, manufacturing facilities, aviation control centers, and large enterprise OT environments.

Enhanced Description

Key Capabilities

  • Advanced supply‑chain compromise of web platforms
  • Automated phishing campaigns via legitimate services (Telegram, email)
  • Custom malware development (InvisiMole, VERMIN, Anchor)
  • OT/SCADA targeted exploitation and sabotage
  • Credential harvesting through embedded CAPTCHA fraud in WordPress sites
  • Domain-based C2 infrastructure using bulletproof hosting
  • Lateral movement in industrial networks, including lateral movement via compromised endpoints

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Discovery
Lateral Movement
Defense Evasion
Credential Access
Impact

ATT&CK Techniques

T1566.001
T1204.002
T1059.003
T1071.004
T1195.001
T1508.001
T1595.006
T1486
T1490

Software / Tooling

InvisiMole
VERMIN
Anchor
Spear‑phishing Kit
WordPress Exploit Module

Campaigns & Victims

The squad’s campaign patterns exhibit a high level of automation and rapid deployment, with multiple attacks executed within weeks across three continents. Their focus on industrial environments indicates an operational doctrine that prioritizes quick gains through disruption. Victims are generally mid to large‑scale organizations with exposed OT interfaces or insufficient segmentation. Historically, the group has leveraged known vulnerabilities in SCADA software and popular CMS platforms to establish footholds before escalating privileges and executing sabotage scripts. Recent notable operations include a 2025 incident that shut down an Italian water treatment plant for over eight hours and a 2026 attack on a Japanese petrochemical monitoring system that left critical safety alerts offline. These incidents demonstrate the squad’s capacity to blend cyber‑crime with tactical sabotage, enhancing the strategic value of their attacks beyond direct financial theft.

IOC Patterns

  • Malicious domain-based C2 over HTTPS/DNS (e.g., demo-cloud.space, TEMP.* domains)
  • Compromised WordPress sites with injected fraudulent CAPTCHA for credential harvesting
  • Phishing emails delivered via Telegram or email attachments
  • Use of bulletproof hosting for staging infrastructure
  • JavaScript obfuscation via Object.defineProperty and performance.mark functions

Recommended Actions

  • Implement strict network segmentation between enterprise IT and OT environments; enforce zero‑trust access controls to SCADA interfaces.
  • Continuously monitor for unusual domain resolution activity, especially connections to known malicious or newly registered domains.
  • Deploy comprehensive web application firewall rules to detect injected JavaScript and CAPTCHA manipulation on WordPress sites.
  • Enforce multi-factor authentication across all user accounts, particularly those granting administrative privileges to OT devices. Regularly update and patch SCADA software and associated web portals; conduct vulnerability scans on exposed industrial interfaces.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. cloud.google.com — Cited by web research for: coordinat
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. www.group-ib.com — Cited by web research for: Global
  4. www.nccgroup.com — Cited by web research for: Carbon
  5. www.group-ib.com — Cited by web research for: United Kingdom
  6. www.ppln.co — Cited by web research for: Date.now

Intel Summary

9

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

Critical Infrastructure
APT
Infrastructure targeting
Phishing
Web application attacks

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.