Also known as: Dark Engine, tracked as, the Newscaster Team, primarily exposing HMIs, Sector 16, coordinat, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, JokerDPR, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
Infrastructure Destruction Squad emerged as a significant adversary targeting industrial control systems (ICS) and SCADA networks in sectors such as metallurgy and food processing. Their operations intensified during June 2025, with multiple attacks on water treatment facilities in Italy, production lines at HYBUSUNG TECH, and monitoring interfaces of Jeonnam Technopark. Beyond physical sabotage, the group also engaged in cyber‑crime campaigns that embedded fraudulent CAPTCHA prompts into legitimate WordPress sites to harvest login credentials, leveraging SEO poisoning for credential harvesting. Detailed investigation by Group‑IB in January 2026 confirmed that Infrastructure Destruction Squad exploited a range of vulnerabilities to breach Italian water systems and other OT environments. Their tactics include automated phishing via Telegram, exploitation of known WordPress exploits for C2 staging, and the deployment of custom malware such as InvisiMole, VERMIN, and Anchor. The actor’s operations have shown advanced persistence capabilities, including the use of bulletproof hosting domains (e.g., demo‑cloud.space) to evade detection. The group remains primarily motivated by disruption rather than financial gain. Their campaigns often culminate in operational shutdowns or data exfiltration that can cripple critical services. Recent evidence also highlights a data leak exposing sensitive phone information within the United States, indicating their willingness to use publicly visible channels for broader sabotage objectives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Infrastructure Destruction Squad, also known as Dark Engine or Newscaster Team, is a pro‑Russian threat actor focused on disrupting industrial control and SCADA systems across a broad spectrum of sectors worldwide. They deploy automated phishing, supply‑chain compromise via compromised WordPress sites, and custom malware such as InvisiMole to infiltrate OT environments, causing potential operational shutdowns. Recent activity in 2025–2026 shows an increasing tempo against critical infrastructure in Europe and Asia.
Goals & Targeting
Infrastructure Destruction Squad targets a wide range of governments and industries—from defense and energy to maritime transport and healthcare—in order to cause systemic disruption and sow operational uncertainty. The actor focuses on countries with significant industrial outputs or geopolitical tensions (US, UK, Germany, China, Russia, Ukraine, Japan). By compromising SCADA systems and critical infrastructure, they aim to disrupt production, compromise safety protocols, and erode confidence in national security capabilities. Typical victims include water treatment plants, manufacturing facilities, aviation control centers, and large enterprise OT environments.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The squad’s campaign patterns exhibit a high level of automation and rapid deployment, with multiple attacks executed within weeks across three continents. Their focus on industrial environments indicates an operational doctrine that prioritizes quick gains through disruption. Victims are generally mid to large‑scale organizations with exposed OT interfaces or insufficient segmentation. Historically, the group has leveraged known vulnerabilities in SCADA software and popular CMS platforms to establish footholds before escalating privileges and executing sabotage scripts. Recent notable operations include a 2025 incident that shut down an Italian water treatment plant for over eight hours and a 2026 attack on a Japanese petrochemical monitoring system that left critical safety alerts offline. These incidents demonstrate the squad’s capacity to blend cyber‑crime with tactical sabotage, enhancing the strategic value of their attacks beyond direct financial theft.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
9
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics