Threat reportICS/SCADATL-2026-0458

ZionSiphon — Ideologically Motivated .NET OT Malware Targeting Israeli Water & Desalination Infrastructure (Mekorot, Sorek, Hadera, Ashdod, Palmachim, Shafdan)

criticalMONITORING

ZionSiphon — Ideologically Motivated .NET OT Malware (TL-2026-0458), also tracked as ZionSiphon, is a critical-severity ICS/SCADA threat, first published 2026-05-05. It is attributed to 0xICS with low confidence, affects Microsoft Windows (engineering workstations / HMIs / historians), maps to 28 MITRE ATT&CK techniques (T0826, T0829, T0831), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
28MITRE ATT&CK
Actors
10xICS
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0458

Threat ID
TL-2026-0458
Also known as
ZionSiphon, win.zionsiphon, 0xICS Water Sabotage Tool
Severity
CRITICAL
Status
MONITORING
Category
ICS_SCADA
First published
Last reviewed
Attribution
0xICS
Attribution confidence
LOW
Motivation
HACKTIVISM
Target sectors
water-and-wastewater, critical-infrastructure, utilities, government, public-health, manufacturing
Target regions
Israel, Middle East
Detection rules
9
Indicators of compromise
25

Malware and tooling in ZionSiphon — Ideologically Motivated .NET OT Malware

Malware and tooling: ZionSiphon

How ZionSiphon — Ideologically Motivated .NET OT Malware works

ZionSiphon is a .NET malware sample disclosed by Darktrace on 2026-04-16 that targets Israeli water treatment and desalination operational technology (OT) environments. The author self-identifies as '0xICS' and embeds explicit anti-Zionist political messaging in support of Iran, Palestine, and Yemen. The malware combines hardcoded Israeli IP-range geofencing (2.52.0.0/14, 79.176.0.0/12, 212.150.0.0/16), water-utility process and file enumeration (Mekorot, Sorek, Hadera, Ashdod, Palmachim, Shafdan), Modbus/DNP3/S7comm subnet scanning, chlorine-control configuration tampering, USB propagation via .lnk shortcut hijacking, HKCU Run persistence under svchost.exe masquerade, and PowerShell-based UAC elevation. The analyzed build (SHA256 07c3bbe6...d6f5f) is non-functional due to a broken XOR target-validation check and incomplete DNP3/S7comm command construction, suggesting an unfinished development build, but the sabotage architecture and intended impact (potable-water poisoning) are real and operational on the Modbus path.

ZionSiphon is a .NET (C#) malware family first publicly analyzed by Darktrace's Threat Research team on 2026-04-16 (Malpedia: win.zionsiphon; sample SHA256 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f). The sample is purpose-built to target Israeli water-treatment and seawater-desalination operational technology (OT) environments and represents one of the clearest examples to date of ideologically motivated, OT-aware sabotage malware authored by a self-identified hacktivist persona ('0xICS').

The malware embeds two unambiguous political artifacts inside the binary: a string referencing 'Netanyahu / In support of our brothers in Iran, Palestine, and Yemen against Zionist aggression. I am "0xICS".' and a separate string 'Dimona / Poisoning the population of Tel Aviv and Haifa', the latter describing the intended kinetic outcome of successful execution against a chlorine-dosing system. The political content places ZionSiphon in the same broad ideological lane as the Iran-aligned Cyber Av3ngers / IRGC-CEC operations that have repeatedly targeted Israeli (and post-2023, US-deployed Israeli-made) water-utility PLCs, although Darktrace's report does not assert formal attribution to any state-aligned group and the persona '0xICS' is not yet linked to a named actor.

Execution flow. On launch, ZionSiphon attempts a target-environment validation by XOR-decoding a hardcoded constant ('Nqvbdk') and comparing the result against the runtime output of EncryptDecrypt('Israel', 5). In the analyzed build the XOR key/length and the constant do not actually match, so the validation always fails on every host (including Israeli targets), and the malware writes 'Target not matched. Operation restricted to IL ranges. Self-destruct initiated.' to %TEMP%\target_verify.log, drops %TEMP%\delete.bat, and self-deletes. Darktrace concludes — and we concur — that this is a development bug rather than a deliberate decoy: the entire downstream code path (process enumeration, network scanning, OT protocol traffic, chlorine tampering) is reachable only from the success branch and is fully present in the binary.

If the validation branch were corrected, ZionSiphon proceeds to: (1) enumerate running processes for hardcoded ICS strings (DesalPLC, ROController, SchneiderRO, DamRO, ReverseOsmosis, WaterGenix, RO_Pump, ChlorineCtrl, WaterPLC, SeaWaterRO, BrineControl, OsmosisPLC, DesalMonitor, RO_Filter, ChlorineDose, RO_Membrane, DesalFlow, WaterTreat, SalinityCtrl); (2) enumerate the filesystem for water-utility-specific paths and configuration files (C:\Program Files\Desalination, C:\Program Files\Schneider Electric\Desal, C:\Program Files\IDE Technologies, C:\Program Files\Water Treatment, C:\Program Files\RO Systems, C:\Program Files\DesalTech, C:\Program Files\Aqua Solutions, C:\Program Files\Hydro Systems, C:\DesalConfig.ini, C:\ROConfig.ini, C:\DesalSettings.conf, C:\Program Files\Desalination\system.cfg, C:\WaterTreatment.ini, C:\ChlorineControl.dat, C:\RO_PumpSettings.ini, C:\SalinityControl.ini); (3) tamper with discovered configuration files by appending an 'unsafe' chlorine-and-pressure block (Chlorine_Dose=10, Chlorine_Pump=ON, Chlorine_Flow=MAX, Chlorine_Valve=OPEN, RO_Pressure=80) — the dose and pressure values are well outside normal potable-water operating envelopes and are explicitly intended to overdose chlorine into the distribution side; (4) scan the local /16 subnet on Modbus TCP/502, DNP3 TCP/20000, and Siemens S7comm TCP/102, with an observed Modbus payload of 01 03 00 00 00 0A (Read Holding Registers, function code 03, 10 registers from address 0) used as a cheap OT-fingerprint probe — the DNP3 and S7comm command-construction routines are present but not fully wired up in the analyzed build; (5) verify network reachability of one of three hardcoded Israeli IP-range blocks (2.52.0.0–2.55.255.255 = 2.52.0.0/14, 79.176.0.0–79.191.255.255 = 79.176.0.0/12, 212.150.0.0–212.150.255.255 = 212.150.0.0/16) — these CIDR ranges align with allocations to Israeli ISPs (Bezeq, HOT, Cellcom, Partner) and have historically been used as 'is-this-Israel?' geofences by Iran-aligned actors.

Persistence and stealth. ZionSiphon copies itself to %LOCALAPPDATA%\svchost.exe (basename masquerade against the legitimate Windows svchost.exe binary, which never resides under LOCALAPPDATA), sets Hidden + System file attributes, and writes the registry value HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemHealthCheck pointing to that path. Privilege escalation is attempted via a RunAsAdmin() routine that spawns powershell.exe with 'Start-Process -FilePath <self> -Verb RunAs', which triggers the standard UAC consent prompt — this is a UAC-prompt bypass attempt rather than a true UAC bypass and depends on user click-through.

USB propagation. The function CreateUSBShortcut (obfuscated as 'sdfsdfsfsdfsdfqw' in the analyzed build) iterates removable drives, copies the malware binary to each drive as a hidden+system svchost.exe, hides every existing user file on the drive, and replaces each file with a .lnk shortcut that uses shell32.dll icon index 4 (the standard Windows folder/file icon) and points to the malware copy. This is the same .lnk-icon-spoof technique used by Stuxnet, USB-Worm.Win32, and many subsequent OT-targeting USB worms, and it is particularly effective in air-gapped or DMZ-isolated water/desalination control networks where USB media remain a primary file-transfer mechanism.

Impact assessment. We rate this CRITICAL despite the broken target-validation gate because (a) the sabotage architecture is real, (b) fixing the XOR comparison is a single-line change for any author or follow-on maintainer, (c) the chlorine-overdose configuration block, if successfully written into a live SCADA HMI configuration file or pushed through a Modbus write, is a public-health-grade kinetic effect (residual chlorine concentrations far above the WHO 5 mg/L upper bound can cause acute respiratory and gastrointestinal harm), and (d) the explicit targeting of Mekorot (Israel's national water carrier), Sorek and Hadera (the two largest seawater desalination plants on the Mediterranean), and Palmachim/Ashdod/Shafdan (additional desalination and wastewater facilities) maps the malware to the specific physical infrastructure responsible for ~40-50% of Israel's potable water supply. The .NET-on-Windows nature of the malware constrains its direct impact to Windows-based engineering workstations, HMIs, and historians inside the OT environment rather than the PLCs themselves — but those workstations are precisely where chlorine setpoint changes are typically authored before being downloaded to the PLC. Defenders should treat ZionSiphon as a credible OT sabotage threat regardless of the analyzed build's broken validation gate.

MITRE ATT&CK techniques used in TL-2026-0458

ICS Impact

T0826 Loss of Availability; T0829 Loss of View; T0831 Manipulation of Control; T0879 Damage to Property; T0880 Loss of Safety

ICS Inhibit Response Function

T0835 Manipulate I/O Image

ICS Impair Process Control

T0836 Modify Parameter

ICS Discovery

T0840 Network Connection Enumeration

ICS Initial Access

T0847 Replication Through Removable Media

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1057 Process Discovery; T1083 File and Directory Discovery; T1614 System Location Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Initial Access

T1091 Replication Through Removable Media

defense-impairment

T1112 Modify Registry

Impact

T1485 Data Destruction; T1565 Data Manipulation

Persistence

T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

ICS Lateral Movement

T1694.001 Default Credentials

Affected products and versions in ZionSiphon — Ideologically Motivated .NET OT Malware

  • Microsoft — Windows (engineering workstations / HMIs / historians)
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022
  • Schneider Electric — Modicon PLCs and SCADA software (DesalPLC, SchneiderRO targeting strings)
    Vulnerable versions: All versions reachable on Modbus TCP/502 from a compromised engineering workstation
  • Siemens — SIMATIC S7 PLCs (S7comm TCP/102 scanning target)
    Vulnerable versions: All S7-300/400/1200/1500 reachable on TCP/102 from a compromised host
  • DNP3 vendors (multiple) — DNP3-speaking RTUs and outstations (TCP/20000 scanning target)
    Vulnerable versions: All DNP3 outstations reachable on TCP/20000
  • IDE Technologies — Desalination plant control systems (C:\Program Files\IDE Technologies path targeting)
    Vulnerable versions: All deployments with default install paths
  • Mekorot — Israeli national water carrier infrastructure (Mekorot string targeting)
    Vulnerable versions: All sites with Windows-based engineering workstations
  • Sorek Desalination Plant (IDE Technologies / Hutchison) — Sorek 1 / Sorek 2 SWRO desalination operations
    Vulnerable versions: All sites with Windows-based HMIs
  • Hadera Desalination Plant (H2ID / IDE Technologies) — Hadera SWRO desalination operations
    Vulnerable versions: All sites with Windows-based HMIs
  • Ashdod Desalination Plant (Mekorot) — Ashdod SWRO desalination operations
    Vulnerable versions: All sites with Windows-based HMIs
  • Palmachim Desalination Plant (Granite Hacarmel / Via Maris) — Palmachim SWRO desalination operations
    Vulnerable versions: All sites with Windows-based HMIs

Remediation for ZionSiphon — Ideologically Motivated .NET OT Malware

Patches

  • No vendor patch applies — ZionSiphon is malware, not a CVE. Detection, containment, segmentation, and physical safety interlocks are the controls.

Immediate actions

  • Block egress and inbound TCP/502 (Modbus), TCP/20000 (DNP3), and TCP/102 (S7comm) from any IT-zone host that does not have a documented OT business need; Modbus/DNP3/S7comm should never traverse the IT/OT boundary unbrokered.
  • Disable USB autorun and removable-media write access on all engineering workstations, HMIs, and historians in water/desalination OT environments; deploy USB sanitization kiosks for required media transfers.
  • Audit HKCU\Software\Microsoft\Windows\CurrentVersion\Run for the value 'SystemHealthCheck' across all engineering workstations; any presence is a strong indicator of ZionSiphon installation.
  • Search %LOCALAPPDATA% for any file named svchost.exe — legitimate svchost.exe never resides under LOCALAPPDATA. Treat any hit as confirmed compromise pending IR triage.
  • Block known sample hash 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f at EDR and email/web filtering layers.
  • Review chlorine-dosing setpoint configuration files (e.g. C:\ChlorineControl.dat, C:\WaterTreatment.ini, C:\Program Files\Desalination\system.cfg) for unauthorized appended Chlorine_Dose=10 / Chlorine_Pump=ON / Chlorine_Flow=MAX / Chlorine_Valve=OPEN / RO_Pressure=80 entries; revert to known-good baseline.

Workarounds

  • Where USB transfers cannot be eliminated, configure Group Policy to disable .lnk file auto-resolution on removable drives and to prevent Hidden+System files from being executed from removable media.
  • Disable PowerShell for non-administrative users on engineering workstations to break the RunAsAdmin() UAC-prompt path.

Longer-term hardening

  • Enforce strict IT/OT segmentation per ISA/IEC 62443 zone-and-conduit model; place engineering workstations and HMIs in a Level 2/3 OT zone with no direct internet egress and no peer-to-peer reachability to corporate IT.
  • Deploy ICS-aware network detection (Dragos, Claroty, Nozomi, Darktrace/OT, or equivalent) with signatures for hardcoded chlorine-overdose payloads, anomalous Modbus 01 03 00 00 00 0A scans from non-engineering hosts, and Israeli IP-range geofence checks.
  • Implement application allowlisting (WDAC, AppLocker, or vendor equivalent) on all engineering workstations, with svchost.exe execution restricted to %SystemRoot%\System32 paths only.
  • Establish a chlorine-residual physical safety interlock independent of the SCADA setpoint — a hard upper-limit cutoff at the dosing pump that cannot be overridden from software regardless of HMI configuration.
  • Conduct periodic OT-environment USB media audits and require all removable media used in OT to be issued, tracked, and sanitized through a controlled program.

Weaknesses (CWE) in ZionSiphon — Ideologically Motivated .NET OT Malware

CWE-506, CWE-829, CWE-693, CWE-1188

Timeline of ZionSiphon — Ideologically Motivated .NET OT Malware

  • Iran-attributed cyberattack targets Israeli water and wastewater facilities operated by Mekorot, attempting to alter chlorine dosing levels — first publicly reported intent to weaponize chlorine setpoints against Israeli potable water (Israel National Cyber Directorate disclosure).
  • IRGC-affiliated 'Cyber Av3ngers' compromise Unitronics Vision-series PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, demonstrating ideologically motivated, Iran-aligned targeting of water-utility PLCs and establishing the broader threat pattern within which ZionSiphon emerges.
  • CISA, FBI, NSA, EPA, and INCD publish joint advisory AA23-335A on IRGC-Affiliated Cyber Av3ngers exploiting PLCs in U.S. and Israeli water-and-wastewater systems.
  • Sample 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f first observed by Darktrace's Threat Research team during routine .NET malware triage; preliminary review identifies hardcoded Israeli IP ranges and Mekorot/Sorek/Hadera targeting strings.
  • Malpedia indexes the family as win.zionsiphon (entry 1dcd3b9c-8b94-42f8-911d-0c8efce55915); VirusTotal sample page becomes publicly viewable with broad multi-engine detection.
  • Darktrace publishes 'Inside ZionSiphon: Darktrace's Analysis of OT Malware Targeting Israeli Water Systems' on the Darktrace blog, releasing the full reverse-engineering writeup including the broken XOR target-validation finding, the chlorine-tampering configuration block, the USB propagation routine, and the '0xICS' political messaging.
  • Israeli National Cyber Directorate (INCD) and water-sector CERTs receive Darktrace's IOC package and begin internal sweeps of Mekorot, Sorek, Hadera, Ashdod, Palmachim, and Shafdan engineering-workstation environments.
  • Threadlinqs Intelligence publishes TL-2026-0458 with full D1-aligned threat record, MITRE mapping, IOC catalog, simulation matrix, and SPL/KQL/Sigma/CQL detection coverage.
  • As of 2026-05-29, ZionSiphon is not a live operational threat: the analyzed build self-destructs on every host (broken XOR check) and Dragos and Nozomi assess it as flawed, likely LLM-generated malware with fictional ICS strings and no credible OT impact. No confirmed in-the-wild deployment, fixed build, or successor exists; the 0xICS persona is unattributed, though the Iran-aligned water-sector pattern persists, warranting monitoring.

Sources cited for ZionSiphon — Ideologically Motivated .NET OT Malware

Detection coverage for TL-2026-0458

As of 2026-05-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0458 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats