Discovery
| Parameter | Value |
|---|---|
| Discovery date | June 2010 (VirusBlokAda, Belarus) |
| Estimated active period | 2007–2010 |
| Probable attribution | NSA (United States) + Unit 8200 (Israel) — Operation "Olympic Games" |
| Target | Iranian IR-1 centrifuges driven by Siemens S7 controllers, Natanz enrichment facility, Iran |
| Code size | ~500 KB (extremely compact for its complexity) |
| Zero-days exploited | 4 (Windows: LNK, Print Spooler, Win32k, Task Scheduler) |
| Stolen certificates | 2 (Realtek Semiconductor, JMicron Technology) |
Technical Explanation
1. Initial infection vector: USB drive. Natanz was air-gapped (not connected to the Internet). Stuxnet spread via infected USB drives, exploiting the LNK vulnerability (CVE-2010-2568): simply displaying the icon of the .lnk file was enough to execute the malicious code. The worm then replicated across network shares via MS08-067 (Server Service vulnerability).
2. Reconnaissance and precision targeting. Once inside the local network, Stuxnet specifically searched for Siemens STEP 7 software and the S7-315/S7-417 programmable logic controller. It verified the presence of frequency converters by Vacon (Finland) or Fararo Paya (Iran) operating between 807 Hz and 1,210 Hz — the exact signature of IR-1 centrifuge cascades. If the environment did not match, the worm remained dormant.
3. Man-in-the-middle attack on the PLC. Stuxnet intercepted the communication between STEP 7 and the PLC by modifying the s7otbxdx.dll library. It injected commands that varied centrifuge frequency: ramp up to 1,410 Hz (+33%) for 15 minutes, then crash down to 2 Hz, then return to 1,064 Hz. During the manipulation, the PLC replayed the last "normal" recorded data to operators — a hardware-level replay attack.
4. Physical destruction mechanism. The IR-1 centrifuges (Iranian, derived from the Pakistani P-1 design) use an aluminium rotor with maraging-steel bellows, spinning at 1,064 Hz (~63,840 rpm). At 1,410 Hz (~84,600 rpm), the rotor approached its critical resonance speed, causing vibrations that damaged the bearings and caused UF₆ leaks. The drop to 2 Hz produced a mechanical shock from sudden deceleration, shattering the bearings.
Why It Worked
Stuxnet combined two innovations: surgical targeting — it only activated in a very specific industrial environment — and SCADA camouflage — operators saw normal data throughout. This "man-in-the-middle" approach transposed to the physical world was unprecedented. Iranian engineers initially believed the centrifuge failures were manufacturing defects — it took months before they suspected a cyberattack.
The sophistication of the code (4 zero-days, 2 stolen certificates, intimate knowledge of the Siemens Profibus/Profinet protocol) pointed to state-level resources. The development budget is estimated at $1–2 million over several years of effort.
Causal Chain
Iranian nuclear programme accelerates (2003–2006) → Operation "Olympic Games" launched under Bush, continued under Obama → Stuxnet deployed via USB drives (2007–2010) → ~1,000 IR-1 centrifuges destroyed → Iranian programme delayed by 1–2 years → Accidental discovery through off-target propagation (2010) → Analyses published (Symantec, Langner) → All developed nations build offensive cyber capabilities → Birth of the "cyber-warfare" doctrine
Anecdote
Stuxnet contained an infection counter limited to 3 propagations per USB drive. Despite this precaution, the worm escaped from Natanz — probably via the laptop of an Iranian engineer who connected to the Internet — and infected ~100,000 machines across more than 155 countries, without ever activating its destructive payload outside the target environment.
Sources
References verified during the August 2026 fact-checking audit: these are the pages
against which this bulletin's claims were checked.
