Stuxnet

lore

securityops culture

The 2010 worm that sabotaged Iranian nuclear centrifuges, the first known cyberweapon to cause physical damage.

Stuxnet spread widely but activated only on specific Siemens industrial controllers, subtly altering centrifuge speeds while reporting normal readings to operators. Its use of multiple zero-days and its physical target marked the arrival of state-level cyber-sabotage.

Stuxnet, discovered in 2010, was malware built to damage a specific physical target: uranium enrichment centrifuges at Natanz. It spread widely and did nothing on almost every machine it reached, activating only when it found a particular configuration of Siemens industrial controllers driving particular hardware.

Technically it was unprecedented in resources. It used several zero-day vulnerabilities at once, at a time when a single one had substantial market value, carried stolen but validly signed driver certificates, and crossed air gaps via removable media. Once resident it altered centrifuge speeds to cause mechanical failure while replaying recorded normal readings to the monitoring systems, so operators saw nothing wrong while equipment destroyed itself.

Its significance is that it moved a category from theory to precedent. Before Stuxnet, cyber attack causing physical destruction was a scenario in papers; afterwards it was a demonstrated capability, and every industrial operator had to reconsider the assumption that isolation was sufficient protection. Attribution was never officially claimed, the analysis pointing to a state programme is widely accepted, and the code became a template that later actors studied.

Also known as: Stuxnet, SCADA worm

Sources

  • Symantec, 'W32.Stuxnet Dossier' (2011)

All glossary entries