ZionSiphon malware designed to sabotage water treatment systems

ZionSiphon malware designed to sabotage water treatment systems

A new malware called ZionSiphon, specifically designed for operational technology, is targeting water treatment and desalination environments to sabotage their operations.

The threat can adjust hydraulic pressures and raise chlorine levels to dangerous levels, researchers found during their analysis.

Based on its IP targeting and political messages embedded in its strings, ZionSiphon appears to focus on targets based in Israel.

Wiz

Researchers at AI-powered cybersecurity company Darktrace found a flawed encryption logic error in the malware’s validation mechanism that makes it non-functional but warn that future ZionSiphon releases could fix the flaw to unleash its power in attacks.

Upon deployment, the malware checks whether the host IP falls within Israeli ranges and whether the system contains water/OT-related software or files, to ensure it is running in water treatment or desalination systems.

Strings from the targets list
Strings from the targets list
Source: Darktrace

Darktrace notes that the logic for country verification is broken due to an XOR mismatch, causing the targeting to fail and triggering the self-destruct mechanism instead of executing the payload.

If ZionSiphon were to activate, it could cause significant damage by increasing chlorine levels and maximizing the flaw and pressure.

It does this via a function named “IncreaseChlorineLevel(),” which appends a text block on existing configuration files to maximize the chlorine dose and flow as much as it is physically supported by the plant’s mechanical systems.

“IncreaseChlorineLevel()” checks a hardcoded list of configuration files associated with desalination, reverse osmosis, chlorine control, and water treatment OT/Industrial Control Systems (ICS),” Darktrace says.

“As soon as it finds any one of these files present, it appends a fixed block of text to it and returns immediately.”

“The appended block of text contains the following entries: “Chlorine_Dose=10”, “Chlorine_Pump=ON”, “Chlorine_Flow=MAX”, “Chlorine_Valve=OPEN”, and “RO_Pressure=80”.”

The intention to interact with industrial control systems (ICS) is obvious from scanning the local subnet for the Modbus, DNP3, and S7comm communication protocols.

However, Darktrace has found only partially functional code for Modbus, and merely placeholders for the other two, indicating that the malware is still in an early development phase.

ZionSiphon also has a USB propagation mechanism that copies itself to removable drives as a hidden ‘svchost.exe’ process and creates malicious shortcut files that execute the malware when clicked.

Creating shortcuts on removable drives
Creating shortcuts on removable drives
Source: Darktrace

USB propagation is key in critical infrastructure systems, where computers that manage security-critical functions are often “air-gapped,” meaning they are not directly connected to the internet.

While ZionSiphon isn’t operational in its current version, its intent and potential for damage are concerning, and all that’s needed to unlock both is to fix a minor verification error.


tines

99% of What Mythos Found Is Still Unpatched.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Read More
Bill Toulas

Latest

Mentalist Oz Pearlman Will Get Inside Trump’s Mind at the White House Correspondents’ Dinner

Typically, the White House Correspondents’ Dinner features a comedian for its star act. In years past, the journalists, executives, agents, and miscellaneous members of the DC establishment have gathered at the Washington Hilton to hear speeches from the head of the correspondents’ association and the president. Then a comedian gets up to properly skewer the

David Pollack Reflects on Being Laid Off From ESPN College GameDay

Moving from the Saturday morning spotlight to a home studio was a major shift for one of the most decorated defensive players in college football history. David Pollack, the former Georgia Bulldog and longtime ESPN mainstay, recently shared his perspective on the day his 13-year tenure at the network came to an abrupt end. Appearing

Star High School Football Player Shot and Killed in Texas

Star High School Football Player Shot and Killed in Texas A Lancaster High School football player was shot and killed during an off-campus shooting this week. Myers Anthony, a 16-year-old football star at Lancaster High School in Lancaster. The shooting is still being investigated as a homicide and appears to be an isolated incident. Anthony

New Orleans Saints News, April 16: Could Arvell Reese fall to the Saints?

Skip to main content Here are today’s Saints news links Apr 16, 2026, 12:30 PM UTC Welcome to today’s roundup of New Orleans Saints and NFL news! Some Saints players are showing up off the football field. A worrying trend. Without a doubt for the Saints. New Orleans Saints News Apr 15 New Orleans Saints

Newsletter

Don't miss

Mentalist Oz Pearlman Will Get Inside Trump’s Mind at the White House Correspondents’ Dinner

Typically, the White House Correspondents’ Dinner features a comedian for its star act. In years past, the journalists, executives, agents, and miscellaneous members of the DC establishment have gathered at the Washington Hilton to hear speeches from the head of the correspondents’ association and the president. Then a comedian gets up to properly skewer the

David Pollack Reflects on Being Laid Off From ESPN College GameDay

Moving from the Saturday morning spotlight to a home studio was a major shift for one of the most decorated defensive players in college football history. David Pollack, the former Georgia Bulldog and longtime ESPN mainstay, recently shared his perspective on the day his 13-year tenure at the network came to an abrupt end. Appearing

Star High School Football Player Shot and Killed in Texas

Star High School Football Player Shot and Killed in Texas A Lancaster High School football player was shot and killed during an off-campus shooting this week. Myers Anthony, a 16-year-old football star at Lancaster High School in Lancaster. The shooting is still being investigated as a homicide and appears to be an isolated incident. Anthony

New Orleans Saints News, April 16: Could Arvell Reese fall to the Saints?

Skip to main content Here are today’s Saints news links Apr 16, 2026, 12:30 PM UTC Welcome to today’s roundup of New Orleans Saints and NFL news! Some Saints players are showing up off the football field. A worrying trend. Without a doubt for the Saints. New Orleans Saints News Apr 15 New Orleans Saints

How NFL Prospects Can Build a Winning Football Resume

How NFL Prospects Can Build a Winning Football Resume For serious football players, a clean, well-structured football resume example can help turn game film into something a coach, scout, recruiter, or personnel staffer can scan fast and actually use. The competition is brutal at every level, with only 1.4% of NCAA football players drafted into the NFL

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and