Stuxnet - The Cyber Weapon that destroyed physical machines
A new Kind of weapon
In june 2010, a small Belarusian security firm called VirusBlokAda discovered something strange on a customer's computer in Iran. A piece of malware was exploiting a Windows vulnerability nobody had seen before.
That malware was Stuxnet. It was designed to destroy physical machinery and specifically, the centrifuges enriching uranium at Iran's Natanz nuclear facility.
What was Stuxnet targeting?
To enrich uranium, you need centrifuges. These are tall, thin machines that spin uranium gas very fast.
Centrifuges are controlled by industrial computers called PLCs (Programmable Logic Controllers). The PLCs run software called Step 7. If you could modify the Step 7 code, you could control the centrifuges.
But here's the problem for any attacker: Natanz was air-gapped (isolated). Its network had no connection to the internet. You couldn't hack it remotely.
How Stuxnet Crossed the Air Gap
Stuxnet spread via USB drives. Someone — likely an unwitting engineer or contractor — plugged an infected USB stick into a computer inside Natanz.
From that single USB stick, Stuxnet:
-
Used four different zero-day vulnerabilities to spread from machine to machine. A zero-day is a vulnerability the software vendor doesn't know about yet — no patch exists.
-
Spread through Windows network shares, print spoolers, and removable drives. Any USB stick plugged into an infected machine became a carrier.
-
Checked every machine it infected for Siemens Step 7 software. If it didn't find it, it spread further. If it did, it stopped — it had reached its target.
Stuxnet was a guided missile disguised as a worm. It infected over 100,000 machines worldwide, but only activated its payload on the specific computers controlling centrifuges at Natanz.
The Payload: What Stuxnet Actually Did
Once Stuxnet found a machine running Step 7, it did two things:
1. It lied to the operators.
Stuxnet recorded normal centrifuge operation for 21 seconds, then played that recording on a loop in the control room. While the centrifuges were being destroyed, the operators saw normal RPMs, normal temperatures, normal everything.
2. It destroyed the centrifuges.
Stuxnet periodically changed the rotational speed of the centrifuges. It would spin them up to dangerously high speeds, then suddenly slow them down, then speed up again. Centrifuges are designed to spin at a constant speed — sudden changes cause catastrophic physical stress. Rotors warp. Casing cracks. Machines tear themselves apart.
And the whole time, the control room monitors showed everything was fine.
The Four Zero-Days
Stuxnet exploited four completely unknown Windows vulnerabilities. To put that in perspective: a single zero-day exploit can sell for $1 million or more on the black market. Stuxnet used four.
And it used them for one purpose: to spread until it found Siemens software. These weren't stolen tools. These were custom-built, flawlessly engineered, and used in combination. Security researchers estimated Stuxnet took a team of 10-15 people working for 6-12 months — with access to millions of dollars and a physical uranium enrichment facility to test against.
Who Did It?
In 2012, journalists at The New York Times revealed that Stuxnet was part of a joint US-Israeli operation codenamed Operation Olympic Games. It had been running since 2006 under President George W. Bush and continued under President Barack Obama.
The goal: slow Iran's nuclear program without a military strike. Stuxnet destroyed an estimated 1,000 centrifuges and set Iran's enrichment program back by 18 to 24 months.
It was the world's first major act of cyberwar — and it worked.
How It Was Stopped
Once discovered in June 2010, the security community acted fast:
- Reverse engineering: Researchers at Microsoft and security firm Langner Communications decompiled Stuxnet and discovered it was targeting Siemens PLCs at Iranian nuclear facilities.
- C2 takedown: Stuxnet communicated with two command-and-control servers in Denmark and Malaysia. Security researchers worked with hosting providers to seize those domains in July 2010, cutting off the malware's ability to receive updates.
- Patching: Microsoft issued emergency patches for all four zero-day vulnerabilities. Siemens released detection tools for infected PLCs.
- Cleanup: Iran admitted the infection and reportedly replaced over 1,000 damaged centrifuges. The enrichment program was set back by roughly 18 months.
What Happened After
Stuxnet's code leaked onto the internet. Any nation, any criminal group, any researcher could download it and study it. The techniques it used — USB propagation, zero-day exploitation, PLC manipulation — became templates for future attacks.
In 2015, a cyberattack on Ukraine's power grid used similar methods to shut down 30 substations, leaving 230,000 people without electricity. In 2017, the NotPetya malware used Stuxnet-inspired spreading mechanisms to cause $10 billion in damage worldwide.