ZionSiphon is a Windows-based OT-themed malware sample designed to target water treatment and desalination environments, with targeting logic and embedded messaging indicating a focus on Israeli water infrastructure. The sample combines conventional host-side malware behaviors with industrial-environment discovery and sabotage-oriented logic. Reported capabilities include privilege escalation attempts, user-level persistence, removable-media propagation, local subnet scanning for industrial services, and limited protocol-aware interaction focused primarily on Modbus, alongside incomplete DNP3 and S7comm code paths. It also searches for water-treatment-related processes, directories, and configuration artifacts, then attempts local configuration tampering intended to increase chlorine dosing and alter reverse-osmosis pressure-related settings.
The malware appears intended to bridge Windows host compromise and OT discovery rather than operate as a mature, deterministic ICS attack framework. Its most developed industrial functionality is Modbus-oriented logic that reads register values and attempts follow-on writes, while other industrial protocol routines are incomplete or malformed. Multiple analyses assess the sample as immature, broken, or likely non-operational in its observed form. A flaw in its geographic validation logic causes target verification to fail and triggers self-removal, and researchers have also noted unrealistic assumptions about plant processes, fictional or fabricated environment artifacts, and the absence of a credible pathway to reliable PLC manipulation. As a result, ZionSiphon is better characterized as a prototype, proof-of-concept, influence artifact, or low-quality experimental OT malware than as a validated deployable ICS weapon.
ZionSiphon has been discussed in connection with Iran-aligned activity and has been cited alongside MuddyWater in some reporting, but high-confidence attribution to a specific threat actor is not established. The sample’s anti-Israel political messaging and water-sector targeting indicate ideological or psychological intent in addition to attempted sabotage. Targeting is centered on critical water infrastructure, especially desalination and treatment operations in Israel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater (Iran) : malwares RustyWater et ZionSiphon contre Israël/Irak
26 distinct techniques documented for this family, organized by ATT&CK tactic.
It copies itself to connected drives, creates shortcut files that execute the payload, and hides legitimate files to increase the likelihood of user interaction.
Many strings in the sample are base64-encoded, presumably to evade basic detection mechanisms. However, other, more sensitive strings remain in plaintext.
The malware copies itself to a concealed location within the local application data directory, adopts a filename associated with legitimate Windows processes...
The sample also includes a self-destruct mechanism intended to restrict execution to targeted environments. However, this function writes the message “Target not matched. Operation restricted to IL ranges. Self-destruct initiated.” to a file named “target_verify.log,” a behaviour that contradicts any realistic requirement for stealth.
The sample also includes a self-destruct mechanism intended to restrict execution to targeted environments.
A compiler timestamp date set in the future is more likely to raise suspicion than to provide any real benefit. While malware authors often manipulate timestamps to obscure the true compilation date, using one that is clearly unrealistic is a crude approach that needlessly draws attention.
When the target check fails, the malware triggers a self-destruct routine. It removes its persistence from the registry...
These checks include process names, directory paths, and configuration files tied to industrial operations such as reverse osmosis control and chlorine dosing.
The malware includes a network discovery component designed to identify industrial devices on the local subnet.
It scans a /24 network range and probes ports associated with Modbus, DNP3, and S7comm protocols.
In the function ” IsDamDesalinationPlant() ”, the malware first inspects running process names for strings such as “ DesalPLC ”, “ ROController ”, “ SchneiderRO ”...
The malware searches for configuration files associated with chlorine dosing, pressure regulation, and flow control.
Iran-linked actors have increased the use of data wiping malware in recent attacks against Israel... The cyberattack against Stryker demonstrated... the deployment of a destructive wiper that abused the company’s Microsoft Intune environment and deleted data from thousands of mobile devices.
“ IncreaseChlorineLevel() ” checks a hardcoded list of configuration files... As soon as it finds any one of these file present, it appends a fixed block of text to it... The appended block of text contains the following entries: “ Chlorine_Dose=10 ”, “ Chlorine_Pump=ON ”, “ Chlorine_Flow=MAX ”, “ Chlorine_Valve=OPEN ”, and “ RO_Pressure=80 ”.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by MuddyWater in operations targeting Israel and Iraq.
An OT-themed malware/prototype focused on Israeli water-sector themes. The content says it lacks a credible C2, has broken execution paths, remains confined to the Windows host layer, and does not present a meaningful real-world ICS threat in its current form.
Malware reportedly targeting industrial control systems and operational technology in water facilities, intended to manipulate chlorine levels and poison water supplies, but researchers said the sample was broken, incorrectly configured, and ultimately dysfunctional.
Alleged OT-focused malware targeting water treatment/desalination environments, but the analysis concludes it is likely a mock-up or non-functional proof of concept rather than a credible deployable threat. It contains unrealistic configuration paths, flawed geofencing, inconsistent obfuscation, and implausible Modbus/plant-operation logic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.