# ZionSiphon — Ideologically Motivated .NET OT Malware Targeting Israeli Water & Desalination Infrastructure (Mekorot, Sorek, Hadera, Ashdod, Palmachim, Shafdan)

> ZionSiphon is a .NET malware sample disclosed by Darktrace on 2026-04-16 that targets Israeli water treatment and desalination operational technology (OT) environments. The author self-identifies as '0xICS' and embeds explicit anti-Zionist political messaging in support of Iran, Palestine, and Yemen. The malware combines hardcoded Israeli IP-range geofencing (2.52.0.0/14, 79.176.0.0/12, 212.150.0.0/16), water-utility process and file enumeration (Mekorot, Sorek, Hadera, Ashdod, Palmachim, Shafdan), Modbus/DNP3/S7comm subnet scanning, chlorine-control configuration tampering, USB propagation via .lnk shortcut hijacking, HKCU Run persistence under svchost.exe masquerade, and PowerShell-based UAC elevation. The analyzed build (SHA256 07c3bbe6...d6f5f) is non-functional due to a broken XOR target-validation check and incomplete DNP3/S7comm command construction, suggesting an unfinished development build, but the sabotage architecture and intended impact (potable-water poisoning) are real and operational on the Modbus path.

- **Published:** 2026-05-05T12:00:00Z
- **Last reviewed:** 2026-05-05T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0458
- **ID:** TL-2026-0458
- **Severity:** CRITICAL
- **Category:** ICS_SCADA
- **Status:** MONITORING
- **Actor:** 0xICS
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

ZionSiphon is a .NET (C#) malware family first publicly analyzed by Darktrace's Threat Research team on 2026-04-16 (Malpedia: win.zionsiphon; sample SHA256 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f). The sample is purpose-built to target Israeli water-treatment and seawater-desalination operational technology (OT) environments and represents one of the clearest examples to date of ideologically motivated, OT-aware sabotage malware authored by a self-identified hacktivist persona ('0xICS').

The malware embeds two unambiguous political artifacts inside the binary: a string referencing 'Netanyahu / In support of our brothers in Iran, Palestine, and Yemen against Zionist aggression. I am "0xICS".' and a separate string 'Dimona / Poisoning the population of Tel Aviv and Haifa', the latter describing the intended kinetic outcome of successful execution against a chlorine-dosing system. The political content places ZionSiphon in the same broad ideological lane as the Iran-aligned Cyber Av3ngers / IRGC-CEC operations that have repeatedly targeted Israeli (and post-2023, US-deployed Israeli-made) water-utility PLCs, although Darktrace's report does not assert formal attribution to any state-aligned group and the persona '0xICS' is not yet linked to a named actor.

Execution flow. On launch, ZionSiphon attempts a target-environment validation by XOR-decoding a hardcoded constant ('Nqvbdk') and comparing the result against the runtime output of EncryptDecrypt('Israel', 5). In the analyzed build the XOR key/length and the constant do not actually match, so the validation always fails on every host (including Israeli targets), and the malware writes 'Target not matched. Operation restricted to IL ranges. Self-destruct initiated.' to %TEMP%\target_verify.log, drops %TEMP%\delete.bat, and self-deletes. Darktrace concludes — and we concur — that this is a development bug rather than a deliberate decoy: the entire downstream code path (process enumeration, network scanning, OT protocol traffic, chlorine tampering) is reachable only from the success branch and is fully present in the binary.

If the validation branch were corrected, ZionSiphon proceeds to: (1) enumerate running processes for hardcoded ICS strings (DesalPLC, ROController, SchneiderRO, DamRO, ReverseOsmosis, WaterGenix, RO_Pump, ChlorineCtrl, WaterPLC, SeaWaterRO, BrineControl, OsmosisPLC, DesalMonitor, RO_Filter, ChlorineDose, RO_Membrane, DesalFlow, WaterTreat, SalinityCtrl); (2) enumerate the filesystem for water-utility-specific paths and configuration files (C:\Program Files\Desalination, C:\Program Files\Schneider Electric\Desal, C:\Program Files\IDE Technologies, C:\Program Files\Water Treatment, C:\Program Files\RO Systems, C:\Program Files\DesalTech, C:\Program Files\Aqua Solutions, C:\Program Files\Hydro Systems, C:\DesalConfig.ini, C:\ROConfig.ini, C:\DesalSettings.conf, C:\Program Files\Desalination\system.cfg, C:\WaterTreatment.ini, C:\ChlorineControl.dat, C:\RO_PumpSettings.ini, C:\SalinityControl.ini); (3) tamper with discovered configuration files by appending an 'unsafe' chlorine-and-pressure block (Chlorine_Dose=10, Chlorine_Pump=ON, Chlorine_Flow=MAX, Chlorine_Valve=OPEN, RO_Pressure=80) — the dose and pressure values are well outside normal potable-water operating envelopes and are explicitly intended to overdose chlorine into the distribution side; (4) scan the local /16 subnet on Modbus TCP/502, DNP3 TCP/20000, and Siemens S7comm TCP/102, with an observed Modbus payload of 01 03 00 00 00 0A (Read Holding Registers, function code 03, 10 registers from address 0) used as a cheap OT-fingerprint probe — the DNP3 and S7comm command-construction routines are present but not fully wired up in the analyzed build; (5) verify network reachability of one of three hardcoded Israeli IP-range blocks (2.52.0.0–2.55.255.255 = 2.52.0.0/14, 79.176.0.0–79.191.255.255 = 79.176.0.0/12, 212.150.0.0–212.150.255.255 = 212.150.0.0/16) — these CIDR ranges align with allocations to Israeli ISPs (Bezeq, HOT, Cellcom, Partner) and have historically been used as 'is-this-Israel?' geofences by Iran-aligned actors.

Persistence and stealth. ZionSiphon copies itself to %LOCALAPPDATA%\svchost.exe (basename masquerade against the legitimate Windows svchost.exe binary, which never resides under LOCALAPPDATA), sets Hidden + System file attributes, and writes the registry value HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemHealthCheck pointing to that path. Privilege escalation is attempted via a RunAsAdmin() routine that spawns powershell.exe with 'Start-Process -FilePath <self> -Verb RunAs', which triggers the standard UAC consent prompt — this is a UAC-prompt bypass attempt rather than a true UAC bypass and depends on user click-through.

USB propagation. The function CreateUSBShortcut (obfuscated as 'sdfsdfsfsdfsdfqw' in the analyzed build) iterates removable drives, copies the malware binary to each drive as a hidden+system svchost.exe, hides every existing user file on the drive, and replaces each file with a .lnk shortcut that uses shell32.dll icon index 4 (the standard Windows folder/file icon) and points to the malware copy. This is the same .lnk-icon-spoof technique used by Stuxnet, USB-Worm.Win32, and many subsequent OT-targeting USB worms, and it is particularly effective in air-gapped or DMZ-isolated water/desalination control networks where USB media remain a primary file-transfer mechanism.

Impact assessment. We rate this CRITICAL despite the broken target-validation gate because (a) the sabotage architecture is real, (b) fixing the XOR comparison is a single-line change for any author or follow-on maintainer, (c) the chlorine-overdose configuration block, if successfully written into a live SCADA HMI configuration file or pushed through a Modbus write, is a public-health-grade kinetic effect (residual chlorine concentrations far above the WHO 5 mg/L upper bound can cause acute respiratory and gastrointestinal harm), and (d) the explicit targeting of Mekorot (Israel's national water carrier), Sorek and Hadera (the two largest seawater desalination plants on the Mediterranean), and Palmachim/Ashdod/Shafdan (additional desalination and wastewater facilities) maps the malware to the specific physical infrastructure responsible for ~40-50% of Israel's potable water supply. The .NET-on-Windows nature of the malware constrains its direct impact to Windows-based engineering workstations, HMIs, and historians inside the OT environment rather than the PLCs themselves — but those workstations are precisely where chlorine setpoint changes are typically authored before being downloaded to the PLC. Defenders should treat ZionSiphon as a credible OT sabotage threat regardless of the analyzed build's broken validation gate.

## MITRE ATT&CK

- T1091 Replication Through Removable Media
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1547 Boot or Logon Autostart Execution
- T1548 Abuse Elevation Control Mechanism
- T1036 Masquerading
- T1564 Hide Artifacts
- T1112 Modify Registry
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1497 Virtualization/Sandbox Evasion
- T1083 File and Directory Discovery
- T1057 Process Discovery
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1614 System Location Discovery
- T1565 Data Manipulation
- T1485 Data Destruction
- T0836 Modify Parameter
- T0835 Manipulate I/O Image
- T0879 Damage to Property
- T0880 Loss of Safety
- T0829 Loss of View
- T0826 Loss of Availability
- T0831 Manipulation of Control
- T0840 Network Connection Enumeration
- T1694.001 Default Credentials
- T0847 Replication Through Removable Media

## Sources

- [Inside ZionSiphon: Darktrace's Analysis of OT Malware Targeting Israeli Water Systems](https://www.darktrace.com/blog/inside-zionsiphon-darktraces-analysis-of-ot-malware-targeting-israeli-water-systems)
- [Malpedia — win.zionsiphon](https://malpedia.caad.fkie.fraunhofer.de/library/1dcd3b9c-8b94-42f8-911d-0c8efce55915/)
- [VirusTotal — 07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f](https://www.virustotal.com/gui/file/07c3bbe60d47240df7152f72beb98ea373d9600946860bad12f7bc617a5d6f5f/details)
- [CISA Advisory AA23-335A — IRGC-Affiliated Cyber Av3ngers Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a)
- [MITRE ATT&CK for ICS — T0836 Modify Parameter](https://attack.mitre.org/techniques/T0836/)
- [MITRE ATT&CK — T1547.001 Registry Run Keys / Startup Folder](https://attack.mitre.org/techniques/T1547/001/)
- [MITRE ATT&CK — T1091 Replication Through Removable Media](https://attack.mitre.org/techniques/T1091/)
- [MITRE ATT&CK — T1565.001 Stored Data Manipulation](https://attack.mitre.org/techniques/T1565/001/)
- [WHO Guidelines for Drinking-water Quality — Chlorine residual limits](https://www.who.int/publications/i/item/9789241549950)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0458
