ZionSiphon Malware Targets Water Infrastructure Systems
2026-04-20T20:52:23Z•372849594b4b8e6d04ede5b8f532f611ecbba98b0f5f2e71d1a7a5243d299047
AI-assisted-exploit-developmentAPK-malformationCVE-2024-3721CVE-2026-33032CVE-programsupply-chain-security (signed-updates)DLL-side-loadingDVRENISAFormbookMCP-protocolMiraiNIST-NVDRhysidaZionSiphonadwareandroid-malwareantivirus-killdata-breachjavascript-obfuscationmalwarenginx-uioperational-technologyransomwarevulnerability-researchwater-infrastructure
What happened
A cluster of high-risk threats and ecosystem shifts: ZionSiphon malware has been observed targeting operational technology in water systems with ICS scanning and sabotage capabilities, while Formbook and other commodity malware campaigns use advanced obfuscation (DLL side‑loading, JS) to evade detection. Active exploitation campaigns include a Mirai-based botnet leveraging CVE-2024-3721 against TBK DVRs and an actively exploited critical nginx-ui MCP authentication bypass (CVE-2026-33032, CVSS ~9.8). Incidents also include large-scale ransomware/data exposures (Rhysida impacting >337k patients
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 372849594b4b8e6d04ede5b8f532f611ecbba98b0f5f2e71d1a7a5243d299047
- Enrichment time
- 2026-04-20T20:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.