Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems
ID: 8b83e8f8-9133-59c5-a787-a7a713cbd350
STIX ID: report--8b83e8f8-9133-59c5-a787-a7a713cbd350
Feed Name: The Hacker News
_Executive summary:_ Cybersecurity firms disclosed three malicious implants: **ZionSiphon**, an unfinished but politically motivated ICS-targeting malware that scans local subnets, probes OT protocols (Modbus, DNP3, S7comm), tampers with water treatment parameters, and propagates via removable media; **RoadK1ll**, a Node.js reverse-tunneling implant that converts a compromised host into an access relay; and **AngrySpark**, a VM-obfuscated, multi-stage backdoor that ran on a U.K. host and used stealthy beaconing and encrypted payload execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
