HarmonyFidelisHarmonyFidelis
Login
NewsMajor ProjectsActorsAcademy

Stuxnet — The First Cyber Weapon in History

Discovered in June 2010 by the Belarusian firm VirusBlokAda, Stuxnet is a 500 KB worm exploiting 4 Windows zero-day vulnerabilities to alter the rotational frequency of the Iranian IR-1 centrifuges at Natanz (Iran), driven by Siemens S7 controllers — from 1,064 Hz to 1,410 Hz then down to 2 Hz — while displaying normal data to operators. Result: ~1,000 centrifuges destroyed out of the ~9,000 installed.

Source: nsarchive2.gwu.edu

Stuxnet — The First Cyber Weapon in History

Discovery

ParameterValue
Discovery dateJune 2010 (VirusBlokAda, Belarus)
Estimated active period2007–2010
Probable attributionNSA (United States) + Unit 8200 (Israel) — Operation "Olympic Games"
TargetIranian IR-1 centrifuges driven by Siemens S7 controllers, Natanz enrichment facility, Iran
Code size~500 KB (extremely compact for its complexity)
Zero-days exploited4 (Windows: LNK, Print Spooler, Win32k, Task Scheduler)
Stolen certificates2 (Realtek Semiconductor, JMicron Technology)

Technical Explanation

1. Initial infection vector: USB drive. Natanz was air-gapped (not connected to the Internet). Stuxnet spread via infected USB drives, exploiting the LNK vulnerability (CVE-2010-2568): simply displaying the icon of the .lnk file was enough to execute the malicious code. The worm then replicated across network shares via MS08-067 (Server Service vulnerability).

2. Reconnaissance and precision targeting. Once inside the local network, Stuxnet specifically searched for Siemens STEP 7 software and the S7-315/S7-417 programmable logic controller. It verified the presence of frequency converters by Vacon (Finland) or Fararo Paya (Iran) operating between 807 Hz and 1,210 Hz — the exact signature of IR-1 centrifuge cascades. If the environment did not match, the worm remained dormant.

3. Man-in-the-middle attack on the PLC. Stuxnet intercepted the communication between STEP 7 and the PLC by modifying the s7otbxdx.dll library. It injected commands that varied centrifuge frequency: ramp up to 1,410 Hz (+33%) for 15 minutes, then crash down to 2 Hz, then return to 1,064 Hz. During the manipulation, the PLC replayed the last "normal" recorded data to operators — a hardware-level replay attack.

4. Physical destruction mechanism. The IR-1 centrifuges (Iranian, derived from the Pakistani P-1 design) use an aluminium rotor with maraging-steel bellows, spinning at 1,064 Hz (~63,840 rpm). At 1,410 Hz (~84,600 rpm), the rotor approached its critical resonance speed, causing vibrations that damaged the bearings and caused UF₆ leaks. The drop to 2 Hz produced a mechanical shock from sudden deceleration, shattering the bearings.

Why It Worked

Stuxnet combined two innovations: surgical targeting — it only activated in a very specific industrial environment — and SCADA camouflage — operators saw normal data throughout. This "man-in-the-middle" approach transposed to the physical world was unprecedented. Iranian engineers initially believed the centrifuge failures were manufacturing defects — it took months before they suspected a cyberattack.

The sophistication of the code (4 zero-days, 2 stolen certificates, intimate knowledge of the Siemens Profibus/Profinet protocol) pointed to state-level resources. The development budget is estimated at $1–2 million over several years of effort.

Causal Chain

Iranian nuclear programme accelerates (2003–2006) → Operation "Olympic Games" launched under Bush, continued under Obama → Stuxnet deployed via USB drives (2007–2010) → ~1,000 IR-1 centrifuges destroyed → Iranian programme delayed by 1–2 years → Accidental discovery through off-target propagation (2010) → Analyses published (Symantec, Langner) → All developed nations build offensive cyber capabilities → Birth of the "cyber-warfare" doctrine

Anecdote

Stuxnet contained an infection counter limited to 3 propagations per USB drive. Despite this precaution, the worm escaped from Natanz — probably via the laptop of an Iranian engineer who connected to the Internet — and infected ~100,000 machines across more than 155 countries, without ever activating its destructive payload outside the target environment.

Sources

References verified during the August 2026 fact-checking audit: these are the pages
against which this bulletin's claims were checked.

  1. W32.Stuxnet Dossier — Symantec (copie National Security Archive)
  2. Did Stuxnet Take Out 1000 Centrifuges at the Natanz Enrichment Plant? — ISIS
  3. Explainer: Iran's Centrifuges (IR-1, matériaux du rotor) — Iran Watch