Stuxnet was the first malware found to spy on and sabotage industrial control systems, and the first to carry a rootkit for a programmable logic controller. It surfaced in June 2010 after a programming error in an update let it spread from an engineer’s laptop to the open internet, where a researcher at the Belarusian antivirus firm VirusBlokAda flagged it. At half a megabyte, it was enormous for malware. It used four zero-day exploits at once and drivers signed with keys stolen from Realtek and JMicron.
This episode explains how lines of code caused physical destruction at the Natanz enrichment facility in Iran. The worm infected more than 200,000 computers but stayed inert unless it found Siemens Step 7 software running motors at 807 to 1210 hertz, the speeds of gas centrifuges. Reporting cited here attributes it to a joint United States and Israeli program code-named Operation Olympic Games, though neither government has openly admitted building it.
- Because the target network was air-gapped, the worm traveled on USB drives, limited itself to three further machines per infected computer, and was set to erase itself on June 24, 2012.
- It pushed centrifuge rotors to 1410 hertz, dropped them to 2 hertz, then returned to normal and waited weeks before repeating the cycle.
- A man-in-the-middle trick recorded 21 seconds of normal sensor data and replayed it to control room monitors while the machines tore themselves apart.
- Roughly 1,000 centrifuges were degraded or destroyed, almost one-fifth of Iran’s fleet at the time.
- Iran built up its own cyber forces in response, and later attacks included Operation Ababil against U.S. banks and the 2012 Shamoon wipe of Saudi Aramco computers.
Leave a Reply