Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-24 and was added to the RWP archive on 2026-09-07.
ZionSiphon was not water-sector malware — Nozomi called it a mock-up
24 April 2026 Labs takedown — fabricated INI paths, broken geofence, chlorine functions that read like an LLM homework assignment. Do not put it in the ICS malware canon.
Bottom line up front
CONFIRMED Nozomi Labs, 24 April 2026 — after reversing a sample marketed as OT malware against water treatment, they assess ZionSiphon as unlikely to be a genuine operational threat. Incomplete execution paths, no coherent plant model, config files that look invented (C:\DesalConfig.ini, C:\WaterTreatment.ini, C:\ChlorineControl.dat), chlorine setpoints as theater (Chlorine_Dose=10, Chlorine_Pump=ON), geofence logic that does not actually bind execution to Israel. Labs' conclusion: demonstrative / non-functional PoC, possibly LLM-shaped, not a deployable ICS capability. RWP will not list ZionSiphon beside Industroyer, FrostyGoop, or PIPEDREAM. Process impact: NONE demonstrated. Social-media "water malware" claims: REPORTED and rejected on technical grounds.
Historical backfill of 24 April 2026 reporting; added 7 September 2026.
What happened
A sample circulated. Labs did the unglamorous work: it does not drive a plant.
Why it mattered
OT rumor moves faster than reversing. Boards that fund against ZionSiphon and skip internet-facing MicroLogix have the risk register inverted.
Who / what was affected
Nobody, if Nozomi is right. Water utilities still have real problems (FBI/EPA seven-state PSA; Cal Water IT dump).
Technical context
ICS malware that matters talks protocols, IOAs, and vendor engineering paths. Hardcoded Windows INI fanfic is a tell.
Exploitation / threat status at the time
CONFIRMED Labs negative assessment.
UNKNOWN who built the mock-up and why.
What defenders should have done
- Do not add ZionSiphon IOCs to the plant IDS as if they were FrostyGoop.
- Keep hunting exposed PLCs.
- Demand samples before repeating "OT malware" headlines.
RWP assessment
Confidence: High that this sample is not operational ICS malware.
Defensive actions
- Source-criticism rule for OT claims.
- Real water work: pull internet-facing controllers (already in this archive).
- File this next to "Handala was billing, not OT."
Sources
- Nozomi Networks Labs — ZionSiphon — why OT threat claims need scrutiny
- Dragos Q2 2026 ransomware analysis (no Stage 2 ICS ransomware cases) — https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026
- RWP — Handala vs Cal Water — what it wasn't