Dark Engine is a pro-Russia hacktivist group associated with the broader ecosystem of Russia-aligned disruptive actors that evolved from denial-of-service activity into operational technology and industrial control system intrusions. The group has been linked to incidents affecting industrial environments and is part of a cluster of companion groups that includes Z-Pentest, Sector16, and CARR. Its activity reflects a broader shift among Russia-aligned hacktivists toward direct interference with operational technology in critical infrastructure sectors. Dark Engine has been associated with intrusions targeting industrial human-machine interfaces in water, energy, and agriculture environments. Reported activity indicates the group has been linked to multiple ICS incidents during 2025, suggesting a sustained focus on operational disruption or demonstrative access rather than purely symbolic website attacks. This pattern aligns with a wider trend in which pro-Russia hacktivist actors moved beyond DDoS and exposed-service abuse toward credential-based access into OT environments. The tradecraft associated with this ecosystem includes reconnaissance of exposed remote administration services, especially industrial remote-access interfaces, followed by abuse of weak authentication, reused passwords, default credentials, leaked credentials, and automated login attempts. Once access is obtained, operators may interact directly with industrial control interfaces, potentially manipulating parameters, suppressing alarms, or degrading operator visibility. These intrusions often rely on valid credentials and legitimate administrative functionality rather than advanced malware, allowing actors to bypass perimeter-focused defenses and blend into normal administrative activity. Dark Engine is best understood as part of a loosely connected Russia-aligned hacktivist milieu focused on critical infrastructure and politically motivated disruptive operations. High-confidence reporting supports its involvement in OT and ICS targeting, particularly in sectors such as water and energy, but does not provide sufficient corroborated detail to attribute a more specific organizational structure, state command relationship, or distinct malware lineage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist companion group described as expanding from DDoS into operational technology intrusions affecting industrial HMIs in water, energy, and agriculture sectors.
Hacktivist group linked to ICS incidents during the 2025 increase in attacks against critical infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.