ZionSiphon is an immature Windows operational-technology-themed malware sample designed to identify Israeli water-treatment and desalination environments. It combines user-level persistence, attempted privilege elevation, removable-media propagation, local network scanning, and purported industrial-protocol interaction. Its targeting logic searches for water- and desalination-related processes, software artifacts, and configuration data, then attempts to locate Modbus, DNP3, and S7comm services on the local network. The most developed industrial component attempts Modbus register reads followed by writes associated with chlorine dosing; its DNP3 and S7comm implementations are incomplete. The sample also contains logic intended to alter local configuration settings related to chlorine dosing, pump and valve states, flow, and reverse-osmosis pressure. Embedded political messaging and Israel-specific targeting references indicate apparent anti-Israel ideological intent focused on water-sector critical infrastructure. The analyzed build is nonfunctional: a defect in its geographic target-validation routine causes it to fail validation and self-delete before its intended payload executes. Independent technical assessments also found fictional or implausible environment artifacts, unrealistic OT assumptions, incomplete protocol support, and no viable pathway to reliable PLC manipulation. ZionSiphon is therefore assessed as an incomplete prototype or influence-oriented artifact rather than a credible operational ICS sabotage capability. No threat actor attribution is confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater (Iran) : malwares RustyWater et ZionSiphon contre Israël/Irak
27 distinct techniques documented for this family, organized by ATT&CK tactic.
It copies itself to connected drives, creates shortcut files that execute the payload, and hides legitimate files to increase the likelihood of user interaction.
Many strings in the sample are base64-encoded, presumably to evade basic detection mechanisms. However, other, more sensitive strings remain in plaintext.
The malware copies itself to a concealed location within the local application data directory, adopts a filename associated with legitimate Windows processes...
The sample also includes a self-destruct mechanism intended to restrict execution to targeted environments. However, this function writes the message “Target not matched. Operation restricted to IL ranges. Self-destruct initiated.” to a file named “target_verify.log,” a behaviour that contradicts any realistic requirement for stealth.
The sample also includes a self-destruct mechanism intended to restrict execution to targeted environments.
A compiler timestamp date set in the future is more likely to raise suspicion than to provide any real benefit. While malware authors often manipulate timestamps to obscure the true compilation date, using one that is clearly unrealistic is a crude approach that needlessly draws attention.
When the target check fails, the malware triggers a self-destruct routine. It removes its persistence from the registry...
These checks include process names, directory paths, and configuration files tied to industrial operations such as reverse osmosis control and chlorine dosing.
The malware includes a network discovery component designed to identify industrial devices on the local subnet.
It scans a /24 network range and probes ports associated with Modbus, DNP3, and S7comm protocols.
In the function ” IsDamDesalinationPlant() ”, the malware first inspects running process names for strings such as “ DesalPLC ”, “ ROController ”, “ SchneiderRO ”...
The malware searches for configuration files associated with chlorine dosing, pressure regulation, and flow control.
A logic error in its own targeting check fires the self-destruct routine instead.
Iran-linked actors have increased the use of data wiping malware in recent attacks against Israel... The cyberattack against Stryker demonstrated... the deployment of a destructive wiper that abused the company’s Microsoft Intune environment and deleted data from thousands of mobile devices.
“ IncreaseChlorineLevel() ” checks a hardcoded list of configuration files... As soon as it finds any one of these file present, it appends a fixed block of text to it... The appended block of text contains the following entries: “ Chlorine_Dose=10 ”, “ Chlorine_Pump=ON ”, “ Chlorine_Flow=MAX ”, “ Chlorine_Valve=OPEN ”, and “ RO_Pressure=80 ”.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware tied to Iranian-linked activity targeting OT environments, combining espionage and disruption objectives.
Operational-technology-focused malware intended to sabotage water and desalination processes, including raising chlorine and maximizing flow and pressure, but rendered ineffective by a self-destruct logic flaw and incomplete protocol support.
Malware used by MuddyWater in operations targeting Israel and Iraq.
An OT-themed malware/prototype focused on Israeli water-sector themes. The content says it lacks a credible C2, has broken execution paths, remains confined to the Windows host layer, and does not present a meaningful real-world ICS threat in its current form.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.