{"id":899651,"date":"2026-04-17T03:12:31","date_gmt":"2026-04-17T08:12:31","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2026\/04\/17\/zionsiphon-malware-designed-to-sabotage-water-treatment-systems\/"},"modified":"2026-04-17T03:12:31","modified_gmt":"2026-04-17T08:12:31","slug":"zionsiphon-malware-designed-to-sabotage-water-treatment-systems","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2026\/04\/17\/zionsiphon-malware-designed-to-sabotage-water-treatment-systems\/","title":{"rendered":"ZionSiphon malware designed to sabotage water treatment systems"},"content":{"rendered":"<div>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"ZionSiphon malware designed to sabotage water treatment systems\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/09\/24\/water-plant-hacker.jpg\" width=\"1600\"><\/p>\n<p>A new malware called ZionSiphon, specifically designed for operational technology, is targeting water treatment and desalination environments to sabotage their operations.<\/p>\n<p>The threat can adjust hydraulic pressures and raise chlorine levels to dangerous levels, researchers found during their analysis.<\/p>\n<p>Based on its IP targeting and political messages embedded in its strings, ZionSiphon appears to focus on targets based in Israel.<\/p>\n<p><a href=\"https:\/\/www.adaptivesecurity.com\/demo\/security-awareness-training?utm_source=display_network&#038;utm_medium=paid_display&#038;utm_campaign=2026_04_display_bleepingcomputer&#038;utm_id=701Rd00000fE8REIA0&#038;utm_content=970x250\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/a\/as-tour-the-platform-970-x250.jpg\" alt=\"Wiz\"><\/a>\n<\/p>\n<p>Researchers at AI-powered cybersecurity company Darktrace found a flawed encryption logic error in the malware\u2019s validation mechanism that makes it non-functional but warn that future ZionSiphon releases could fix the flaw to unleash its power in attacks.<\/p>\n<p>Upon deployment, the malware checks whether the host IP falls within Israeli ranges and whether the system contains water\/OT-related software or files, to ensure it is running in water treatment or desalination systems.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Strings from the targets list\" height=\"558\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/April\/Israel-water.jpg\" width=\"800\"><figcaption><strong>Strings from the targets list<\/strong><br \/><em>Source: Darktrace<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Darktrace notes that the logic for country verification is broken due to an XOR mismatch, causing the targeting to fail and triggering the self-destruct mechanism instead of executing the payload.<\/p>\n<p>If ZionSiphon were to activate, it could cause significant damage by increasing chlorine levels and maximizing the flaw and pressure.<\/p>\n<p>It does this via a function named \u201cIncreaseChlorineLevel(),\u201d which appends a text block on existing configuration files to maximize the chlorine dose and flow as much as it is physically supported by the plant\u2019s mechanical systems.<\/p>\n<p>\u201cIncreaseChlorineLevel()\u201d checks a hardcoded list of configuration files associated with desalination, reverse osmosis, chlorine control, and water treatment OT\/Industrial Control Systems (ICS),\u201d <a href=\"https:\/\/www.darktrace.com\/blog\/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems\" rel=\"nofollow noopener\">Darktrace says<\/a>.<\/p>\n<p>\u201cAs soon as it finds any one of these files present, it appends a fixed block of text to it and returns immediately.\u201d<\/p>\n<p>\u201cThe appended block of text contains the following entries: \u201cChlorine_Dose=10\u201d, \u201cChlorine_Pump=ON\u201d, \u201cChlorine_Flow=MAX\u201d, \u201cChlorine_Valve=OPEN\u201d, and \u201cRO_Pressure=80\u201d.\u201d<\/p>\n<p>The intention to interact with industrial control systems (ICS) is obvious from scanning the local subnet for the Modbus, DNP3, and S7comm communication protocols.<\/p>\n<p>However, Darktrace has found only partially functional code for Modbus, and merely placeholders for the other two, indicating that the malware is still in an early development phase.<\/p>\n<p>ZionSiphon also has a USB propagation mechanism that copies itself to removable drives as a hidden \u2018svchost.exe\u2019 process and creates malicious shortcut files that execute the malware when clicked.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Creating shortcuts on removable drives\" height=\"428\" width=\"900\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/April\/usb-shortcut.jpg\" previous-src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/April\/usb-shortcut.jpg\"><figcaption><strong>Creating shortcuts on removable drives<\/strong><br \/><em>Source: Darktrace<\/em><\/figcaption><\/figure>\n<\/div>\n<p>USB propagation is key in critical infrastructure systems, where computers that manage security-critical functions are often \u201cair-gapped,\u201d meaning they are not directly connected to the internet.<\/p>\n<p>While ZionSiphon isn\u2019t operational in its current version, its intent and potential for damage are concerning, and all that&#8217;s needed to unlock both is to fix a minor verification error.<\/p>\n<div>\n<p><a href=\"https:\/\/hubs.li\/Q04crVgD0\" target=\"_blank\" rel=\"noopener sponsored\"><br \/>\n            <img decoding=\"async\" alt=\"tines\" src=\"https:\/\/www.bleepstatic.com\/c\/p\/autonomous-validation2.jpg\" previous-src=\"https:\/\/www.bleepstatic.com\/c\/p\/autonomous-validation2.jpg\"><\/a>\n    <\/p>\n<div>\n<h2><a href=\"https:\/\/hubs.li\/Q04crVgD0\" target=\"_blank\" rel=\"noopener sponsored\">99% of What Mythos Found Is Still Unpatched.<\/a><\/h2>\n<p>AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.<\/p>\n<p>At the Autonomous Validation Summit (May 12 &#038; 14), see how autonomous, context-rich validation finds what&#8217;s exploitable, proves controls hold, and closes the remediation loop.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/zionsiphon-malware-designed-to-sabotage-water-treatment-systems\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Bill Toulas<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new malware called ZionSiphon, specifically designed for operational technology, is targeting water treatment and desalination environments to sabotage their operations. The threat can adjust hydraulic pressures and raise chlorine levels to dangerous levels, researchers found during their analysis. Based on its IP targeting and political messages embedded in its strings, ZionSiphon appears to focus<\/p>\n","protected":false},"author":1,"featured_media":899652,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4551,46,148894],"tags":[],"class_list":{"0":"post-899651","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-malware","8":"category-technology","9":"category-zionsiphon"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/899651","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=899651"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/899651\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/899652"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=899651"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=899651"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=899651"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}