T1#security#military

Stuxnet — The First State-Built Cyberweapon for Physical Destruction

Buildings at the Natanz uranium enrichment facility in Iran
SourceHamed Saber (Wikimedia Commons) · CC BY 2.0 · View on Commons

Metadata

Date
Decade
2010s
Tier
T1
Sources
06
Connections
00
Tags
#security#military

In June 2010 Sergey Ulasen, an analyst at the Belarusian anti-virus vendor VirusBlokAda, received a complaint from an Iranian customer about a machine that kept rebooting. The malware he eventually extracted was unlike anything the security industry had seen — and would shortly be named Stuxnet. On the public record it is the first cyberweapon engineered, by a state, to destroy things in the physical world.

An Unusual Technical Stack

What set Stuxnet apart from earlier malware was the sheer scale of the resources poured into it.

  • Four zero-day vulnerabilities. A single piece of malware using multiple zero-days at once was unprecedented. Stuxnet deployed MS10-046 / CVE-2010-2568 (LNK shortcut), MS10-061 / CVE-2010-2729 (print spooler), MS10-073 / CVE-2010-2743 (Win32k.sys keyboard-layout privilege escalation) and MS10-092 / CVE-2010-3338 (Task Scheduler privilege escalation). Symantec's analysis found the last two were used selectively: Win32k.sys on Windows XP and 2000, and the then-undisclosed Task Scheduler flaw on Vista and later.
  • Compromised legitimate code-signing certificates. Certificates belonging to Taiwan's Realtek Semiconductor and JMicron Technology let Stuxnet's Windows drivers load as legitimate software. Verisign revoked the Realtek certificate on 16 July 2010 and the JMicron one on 22 July 2010. Both firms have offices in the same Hsinchu Science Park, which invited speculation about physical theft; how the keys were obtained has never been published.
  • Deep knowledge of Siemens industrial control. The target was an S7-315-2 PLC (the S7-300 family) running under Step7/WinCC. Stuxnet fired only when frequency-converter drives from Fararo Paya (Tehran, Iran) or Vacon (Finland) were present in a specific configuration. A second sabotage routine aimed at S7-417 PLCs was also found, but Symantec concluded it was unfinished and never executed. Either way, the attackers knew the target's physical configuration in advance.

No criminal gang or hobbyist group has resources of this order. Stuxnet's existence was itself technical proof of state involvement.

What Happened at Natanz

Iran's Natanz uranium-enrichment facility ran thousands of IR-1 centrifuges in cascades. Because the Natanz control systems are not connected to the Internet, Stuxnet is understood to have crossed the air gap by copying itself onto removable drives from infected Windows hosts and being carried in by hand. Symantec traced the earliest infections to five organisations inside Iran, which points at contractors to the plant as the likely stepping stone.

Once on a target PLC, Stuxnet ran two attack routines:

  1. Frequency manipulation. Per Symantec's reconstruction, the worm first watches for roughly 13 days, confirming the plant is running in its normal 807–1,210 Hz band. It then drives the frequency up to 1,410 Hz and lets normal operation resume. About 27 days later it runs the second sequence: down to 2 Hz, then back to 1,064 Hz. The two sequences alternate at roughly 27-day intervals.
  2. Sensor spoofing. During an attack, the PLC replayed previously recorded normal telemetry to the SCADA monitoring screens. Nothing showed up on the operators' displays.

The physical damage has never been directly confirmed. The basis for the usual claim is a preliminary assessment published by the Institute for Science and International Security (ISIS) on 22 December 2010, which read IAEA safeguards data as showing that about 1,000 IR-1 centrifuges were decommissioned and replaced at Natanz's Fuel Enrichment Plant in late 2009 or early 2010. IR-1s break often, ISIS noted, but this level of breakage exceeded expectations and could have resulted from a Stuxnet infection — that is as far as the report goes. It also observed that if Stuxnet's goal had been the destruction of all the centrifuges at the plant, Stuxnet failed.

Attribution — Olympic Games

In June 2012, The New York Times' David Sanger reported, based on Obama-administration sources, that Stuxnet was part of a joint US NSA / Israeli Unit 8200 operation codenamed Olympic Games, begun under the Bush administration and expanded under Obama.

That attribution rests on reporting. Neither the United States nor Israel has ever formally acknowledged it. Technical analysis can establish that state-scale resources were spent; it cannot name the state. On the Iranian side, President Ahmadinejad told reporters in November 2010 that a software attack had affected a limited number of centrifuges, and Ali Akbar Salehi, then head of Iran's Atomic Energy Organization, confirmed to IRNA that malware had reached the country's nuclear sites — but Iran has not conceded that Stuxnet attacked Natanz.

The goal, as Sanger's sources described it, was twofold: physically delay Iran's nuclear programme, and reduce Israel's incentive to launch an air strike of its own. That too comes from reporting, not from any official record.

The Fifth Domain of Warfare

Before Stuxnet, state cyber-activity was understood mainly as espionage (data theft) and denial of service. Malware that physically destroys infrastructure, however, is — in the public record — Stuxnet's first instance. With that, the cyber domain stopped being merely a venue for spying and disruption and became reclassified as a fifth domain of warfare, capable of kinetic effect.

Secondary consequences were also significant. Duqu, found in 2011, was built on the same development platform as Stuxnet; Flame, found in 2012, shared a module with early Stuxnet — both are read as products of the same lineage of developers. The industrial-control malware that followed, such as Industroyer (which cut power in Ukraine) and Triton (which targeted a safety instrumented system), are successors in method rather than derivatives of Stuxnet's code. On the defensive side, industrial-control-system security — what is now called OT security — was established as an independent engineering discipline largely in Stuxnet's wake.

As the starting point of the era in which "states break things with code", Stuxnet remains the canonical reference.

Questions this page answers

When and where was Stuxnet discovered?
In June 2010, by Sergey Ulasen of the Belarusian anti-virus vendor VirusBlokAda, on the systems of an Iranian customer who had complained about a machine that kept rebooting.
Who built Stuxnet?
The New York Times reported in 2012 that it was part of a joint US NSA and Israeli Unit 8200 operation codenamed Olympic Games. Neither government has ever formally acknowledged it.

Sources

  1. TertiaryStuxnet — Wikipedia

    Accessed 2026-08-03

  2. PrimaryW32.Stuxnet Dossier — Symantec, Feb 2011 (v1.4)

    Accessed 2026-08-03

  3. SecondaryCountdown to Zero Day — Kim Zetter, 2014

    Accessed 2026-05-25

Last updated:

Share