- ZionSiphonOT-focused malware targeting Israeli water treatment plants
- svchost.exe (fake)Masqueraded Windows process used by ZionSiphon for persistence
ThreatNoir Afternoon Brief — April 17
Afternoon Review in IT Security — April 17, 2026
The threat landscape continues to evolve with critical vulnerabilities being actively exploited and sophisticated malware campaigns targeting both critical infrastructure and software supply chains. Today's review covers emerging threats ranging from nation-state attacks on water systems to widespread exploitation of long-dormant software flaws.
New ZionSiphon Malware Discovered Targeting Israeli Water Systems
Researchers at Darktrace have identified a new malware strain called ZionSiphon that is specifically designed to target Israeli water treatment plants. This threat represents a significant concern for operational technology environments, as the malware is engineered to exploit vulnerabilities in industrial control systems and supervisory control and data acquisition (SCADA) networks. The discovery highlights the ongoing threat posed by nation-state actors seeking to compromise critical infrastructure through specialized attack vectors including USB-based delivery and ICS protocol exploitation. Source: New ZionSiphon Malware Discovered Targeting Israeli Water Systems
Recent Apache ActiveMQ Vulnerability Exploited in the Wild
A remote code execution vulnerability in Apache ActiveMQ, tracked as CVE-2026-34197, has been actively exploited in the wild following its discovery in early April. This vulnerability represents a critical risk to organizations running affected versions of the widely-used open-source messaging platform. The active exploitation underscores the importance of rapid patching cycles for critical infrastructure components, particularly those that manage message queuing and enterprise communications. Source: Recent Apache ActiveMQ Vulnerability Exploited in the Wild
CISA Flags Apache ActiveMQ Flaw as Actively Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency has officially warned that attackers are now actively exploiting a high-severity Apache ActiveMQ vulnerability that remained undetected for thirteen years before being patched earlier this month. The vulnerability, tracked as CVE-2026-34197, has become a focal point for threat actors seeking to compromise enterprise systems. Additionally, CISA noted that related vulnerabilities including CVE-2023-46604 and CVE-2016-3088 are also being leveraged in coordinated attacks, with the TellYouThePass malware being deployed as a payload in some incidents. Source: CISA flags Apache ActiveMQ flaw as actively exploited in attacks
New CGrabber and Direct-Sys Malware Spread Through GitHub ZIP Files
A sophisticated malware campaign is distributing two distinct threats—CGrabber Stealer and Direct-Sys Loader—through malicious ZIP files hosted on GitHub. The attackers have employed advanced evasion techniques to bypass security tools while stealing passwords, cryptocurrency wallet credentials, and sensitive user data. The campaign utilizes multiple components including Launcher_x64.exe, msys-crypto-3.dll, and packages distributed under names such as Eclipsyn.zip to maximize infection rates and evade detection mechanisms. This supply chain attack vector demonstrates how legitimate platforms can be weaponized to distribute credential-stealing malware at scale. Source: New CGrabber and Direct-Sys Malware Spread Through GitHub ZIP Files
The convergence of nation-state targeting of critical infrastructure, exploitation of long-unpatched vulnerabilities, and supply chain-based malware distribution reflects a threat environment requiring heightened vigilance across both enterprise and critical infrastructure sectors.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Older vulnerability that can be chained with CVE-2026-34197 for unauthenticated RCE
- Remote code execution in Apache ActiveMQ Classic via Jolokia API, exploited in wild
- Apache ActiveMQ vulnerability previously targeted as zero-day by TellYouThePass ransomware
- High-severity Apache ActiveMQ vulnerability actively exploited, improper input validation leading to arbitrary code execution
- Apache ActiveMQ vulnerability previously exploited in the wild
- TellYouThePassRansomware gang that exploited CVE-2023-46604 as zero-day
- CGrabber StealerInformation stealer targeting passwords, credit cards, crypto keys, and browser data
- Eclipsyn.zipZIP archive filename used to distribute malware via GitHub attachment links
- msys-crypto-3.dllMalicious DLL sideloaded as fake dependency to execute loader payload
- Launcher_x64.exeLegitimate Microsoft-signed executable abused via DLL sideloading in attack chain
- Direct-Sys LoaderMulti-stage loader performing security tool detection and syscall-based evasion