
Executive Summary
Infrastructure Destruction Squad has introduced an updated version of TRK25 Advanced SCADA, a tool previously observed by iQBlack in publicly declared activity involving industrial and municipal interfaces, with a significant expansion of the capabilities attributed to it by the actor.
The new version is presented as an integrated platform for operations against industrial systems and critical infrastructure. According to the announcement, TRK25 now incorporates recognition of multiple industrial protocols, exploitation of known vulnerabilities, DDoS capabilities, geographically targeted system discovery, remote-service access, screenshot capture, structured data storage, and report generation.
The most significant change does not lie in any individual feature, but in their convergence. TRK25 is moving from being presented primarily as a tool for industrial discovery and exposure analysis toward a single interface combining reconnaissance, assessment, access, exploitation, disruption, and information collection.
A broader tool than its previous version
iQBlack had already documented TRK25 ADVANCED ICS in July 2026, when it appeared in publications associated with claimed access to industrial and municipal systems in Argentina. At the time, the tool served as a relevant indicator for correlating that activity with Infrastructure Destruction Squad and its broader ICS/OT ecosystem.
The newly announced update considerably expands that scope. According to the actor’s description, TRK25 now incorporates an integrated engine targeting environments using MODBUS, Siemens S7, DNP3, BACnet, OPC UA, Profinet, and Ethernet/IP, alongside functionality for detecting active industrial devices and assessing their risk level.
The platform is also presented as capable of processing address ranges associated with specific countries, scanning them in parallel, and classifying discovered systems according to exposed services and identified vulnerabilities.
This introduces an important distinction from a tool limited to scanning: the product Infrastructure Destruction Squad is now projecting integrates target discovery with subsequent assessment and exploitation stages.
OT on the surface, supporting software underneath
One of the most relevant elements of the update appears outside the industrial protocols themselves. Among the vulnerabilities the actor says it has incorporated are BlueKeep, Log4J, SMBGhost, and PrintSpooler. That combination shifts part of the focus away from the SCADA protocol or industrial device itself and toward the software and services that support, administer, or provide access to the environment.
The same logic had already emerged in a recent iQBlack analysis of NoName057(16)’s expanding OT activity: the SCADA application may be the ultimate target, but not necessarily the initial point of exploitation. Operating systems, remote-access services, gateways, authentication layers, and other supporting technologies are also part of the chain.
TRK25 appears to be evolving precisely around that intersection, combining industrial visibility with capabilities directed against the technological infrastructure that makes OT environments reachable and operable.
Access, disruption, and collection within a single platform
The announced version also adds access capabilities through VNC, RDP, and SSH, including claimed password-guessing functionality, together with screenshot capture from the targeted system.
It also includes local data storage using SQLite, result exports in JSON and CSV formats, and an encryption engine presented as a mechanism for protecting information obtained during operations.
According to the actor, the tool also incorporates several DDoS modes — including SYN, UDP, TCP, HTTP, and ICMP traffic — with control over concurrency and attack duration.
Individually, several of these capabilities are common across offensive tooling. Their relevance within TRK25 comes from their consolidation around a platform explicitly positioned to discover and operate against industrial environments.
The declared architecture would allow a single tool to accompany several stages of an operation: locating systems, classifying them, identifying vulnerable surfaces, attempting to obtain access, collecting information, and potentially generating disruption.
More than a functional update
TRK25’s evolution also provides insight into the direction Infrastructure Destruction Squad appears to be taking with its offensive portfolio.
The previous version had already been associated with industrial scanning, technical information extraction, and vulnerability recording. In the activity observed in Argentina, its appearance helped connect claimed access to HMI/SCADA interfaces with a tool attributed to the actor.
The new presentation is more ambitious. TRK25 is no longer described solely as an instrument for identifying industrial exposure. Infrastructure Destruction Squad is attempting to position it as a platform capable of accompanying the broader operational cycle against OT environments and the technologies surrounding them.
This does not establish that every advertised capability operates with the depth or effectiveness claimed. But the direction of development itself is relevant from an intelligence perspective: industrial discovery, exploitation of supporting technological infrastructure, remote access, collection, and disruption are beginning to converge within a single offensive proposition.
Analytical Closing
The TRK25 Advanced SCADA update reinforces a trend that extends beyond any single tool. Attacking an industrial environment does not necessarily require starting with the industrial protocol itself. The path may instead lie in the technologies that keep that environment connected, manageable, and accessible: operating systems, applications, remote services, and supporting components.
TRK25 appears to be evolving around precisely that intersection. The visible surface remains OT/ICS. But the exploitable surface may begin well before an attacker ever reaches the industrial process.
Explore 3C-INT
Expand actor, campaign and operational-link tracking through a structured intelligence layer.
Get new publications
Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.