ZionSiphon is an OT-themed Windows malware sample designed to target water treatment and desalination environments, with targeting logic and embedded messaging indicating a focus on Israeli water infrastructure. The malware combines conventional host-side tradecraft with attempted industrial sabotage logic. Reported capabilities include privilege escalation, user-level persistence, self-deletion, removable-media propagation, local subnet scanning for industrial services, and partial interaction with Modbus, alongside incomplete DNP3 and S7comm code paths. It also searches for water-treatment-related processes, directories, and configuration artifacts, then attempts to tamper with chlorine dosing, flow, valve, and reverse-osmosis pressure settings through local file modification and Modbus write logic.
The sample appears intended to identify hosts associated with desalination or water-treatment operations and then manipulate process-related parameters in ways that could disrupt operations or degrade water safety. It includes geofencing tied to Israeli network ranges and politically motivated anti-Israel messaging. ZionSiphon has been discussed in connection with activity affecting Israeli water-sector targets, and some reporting has associated it with MuddyWater, but public attribution remains unconfirmed at high confidence.
Multiple independent technical assessments conclude that the analyzed sample is immature and not a credible operational ICS weapon in its current form. A flaw in its target-country validation causes the malware to fail its own targeting checks and trigger self-destruction before reaching its intended payload. Additional analysis found fictional or implausible environment markers, incomplete execution paths, unrealistic assumptions about industrial protocols and plant operations, and only partial protocol support. The Modbus functionality is the most developed portion, but even that lacks the target-specific engineering knowledge and environment-specific mapping required for reliable physical impact. ZionSiphon is best characterized as an unfinished prototype, proof of concept, or influence-oriented artifact rather than a validated deployable OT attack capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater (Iran) : malwares RustyWater et ZionSiphon contre Israël/Irak
27 distinct techniques documented for this family, organized by ATT&CK tactic.
It copies itself to connected drives, creates shortcut files that execute the payload, and hides legitimate files to increase the likelihood of user interaction.
Many strings in the sample are base64-encoded, presumably to evade basic detection mechanisms. However, other, more sensitive strings remain in plaintext.
The malware copies itself to a concealed location within the local application data directory, adopts a filename associated with legitimate Windows processes...
The sample also includes a self-destruct mechanism intended to restrict execution to targeted environments. However, this function writes the message “Target not matched. Operation restricted to IL ranges. Self-destruct initiated.” to a file named “target_verify.log,” a behaviour that contradicts any realistic requirement for stealth.
The sample also includes a self-destruct mechanism intended to restrict execution to targeted environments.
A compiler timestamp date set in the future is more likely to raise suspicion than to provide any real benefit. While malware authors often manipulate timestamps to obscure the true compilation date, using one that is clearly unrealistic is a crude approach that needlessly draws attention.
When the target check fails, the malware triggers a self-destruct routine. It removes its persistence from the registry...
These checks include process names, directory paths, and configuration files tied to industrial operations such as reverse osmosis control and chlorine dosing.
The malware includes a network discovery component designed to identify industrial devices on the local subnet.
It scans a /24 network range and probes ports associated with Modbus, DNP3, and S7comm protocols.
In the function ” IsDamDesalinationPlant() ”, the malware first inspects running process names for strings such as “ DesalPLC ”, “ ROController ”, “ SchneiderRO ”...
The malware searches for configuration files associated with chlorine dosing, pressure regulation, and flow control.
A logic error in its own targeting check fires the self-destruct routine instead.
Iran-linked actors have increased the use of data wiping malware in recent attacks against Israel... The cyberattack against Stryker demonstrated... the deployment of a destructive wiper that abused the company’s Microsoft Intune environment and deleted data from thousands of mobile devices.
“ IncreaseChlorineLevel() ” checks a hardcoded list of configuration files... As soon as it finds any one of these file present, it appends a fixed block of text to it... The appended block of text contains the following entries: “ Chlorine_Dose=10 ”, “ Chlorine_Pump=ON ”, “ Chlorine_Flow=MAX ”, “ Chlorine_Valve=OPEN ”, and “ RO_Pressure=80 ”.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operational-technology-focused malware intended to sabotage water and desalination processes, including raising chlorine and maximizing flow and pressure, but rendered ineffective by a self-destruct logic flaw and incomplete protocol support.
Malware used by MuddyWater in operations targeting Israel and Iraq.
An OT-themed malware/prototype focused on Israeli water-sector themes. The content says it lacks a credible C2, has broken execution paths, remains confined to the Windows host layer, and does not present a meaningful real-world ICS threat in its current form.
Malware reportedly targeting industrial control systems and operational technology in water facilities, intended to manipulate chlorine levels and poison water supplies, but researchers said the sample was broken, incorrectly configured, and ultimately dysfunctional.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.