Latest
When a Client Thinks the Ghostwriter Used AIThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe One-Hour Call Before I Quote Your BookThe Work You Would Never Have StartedWhen Your Own Memoir Sounds Like BraggingMonthly or Milestone: How Ghostwriting Gets BilledWhat It Costs to Fix an AI-Written ManuscriptThe Quotation Marks That Get Authors SuedThe Hugging Face AI Agent Attack: An Operations ReadingBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreThe Web Got Fenced: What AI Search Costs Small SitesBlack Tuesday: The Web Ring War Nobody Outside It NoticedWhat the AI Visibility Industry Sells, and What the Evidence SaysBlack Tuesday: The Original ring-master.net Page, 2000Behind the Book: Peacekeeper, The Dissolution WarsBehind the Book: Real World SurvivalBehind the Book: Publish Your BookBehind the Book: ReincarnationBehind the Book: Sell Your BooksBehind the Book: Selling on eBay

After Stuxnet: The Weapons It Loosed on the World

This entry is part 4 of 13 in the series Nothing Is Isolated
TL;DR: Stuxnet set Iran’s nuclear program back, but the bigger cost came after. Once it escaped and was studied worldwide, it proved that code could break physical infrastructure, and it handed every government a blueprint. What followed was a decade of state-built weapons aimed at the physical world: Duqu and Flame for spying, Shamoon wiping 30,000 hard drives at a Saudi oil company, two attacks that shut off power in Ukraine, and Triton, built to go after the safety systems that keep a plant from exploding. This is the fourth article in a series on attacks that beat isolation, and it covers the world Stuxnet made.
Series Navigation  (13 parts)

There’s an old rule about weapons that every military eventually learns the hard way. Once you use a new one, you have shown everyone else how it’s done, and you no longer have it to yourself. The catapult, the machine gun, the atomic bomb, each one changed the world the day it was used, and each one was copied by everyone who saw what it could do.

Stuxnet was that kind of weapon, and the people who built it should have known the rule. They built the first piece of software proven to destroy physical machines, they used it, and it got loose. After that, the idea was free. Any government with the money and the will could see that it worked, take the concept apart, and build its own. What they built fills the rest of these pages.

What happened to Iran after Stuxnet?

Start with the target, because the results there are more modest than the legend.

Stuxnet destroyed roughly a thousand centrifuges and cost Iran time, by most estimates somewhere between a few months and two years of delay. It did that without an airstrike and without giving Iran a clear enemy to blame in the early going. As a piece of sabotage, it did real work.

But it did not stop the program. Iran replaced the broken centrifuges, kept enriching, and came out of the episode with something it hadn’t had before: a reason and a template to build its own offensive cyber force. A country that gets hit with a new kind of weapon does not sit still. It studies what happened and it answers. Within a few years, Iran had stood up cyber capabilities of its own and started using them. That brings us to the first of the weapons that followed.

Shamoon: the answer that wiped 30,000 machines

In 2012, a piece of malware called Shamoon hit Saudi Aramco, the Saudi national oil company and one of the most valuable companies on earth. It did not spy and it did not steal. It wiped, erasing the data on some 30,000 computers and replacing it with a burning image, then doing the same at a second energy company.

Shamoon is widely attributed to Iran, and the timing tells the story. A few years after Stuxnet taught Iran that infrastructure could be attacked through code, Iran was reportedly running that lesson against the oil industry of a regional rival. This is the pattern that repeats through the whole aftermath: the weapon does not stay with its inventor, and the first people to copy it are often the people it was first used against.

Duqu and Flame: the family that came with it

Even before the copies came from other countries, Stuxnet turned out not to be alone. Researchers taking it apart found close relatives that appeared to share its origins.

Duqu, found in 2011, was built for intelligence, not sabotage. It logged keystrokes and gathered system information, the kind of reconnaissance you run before an attack, and its code shared enough with Stuxnet that analysts concluded the two came from the same workshop.

Flame, uncovered in 2012, was a sprawling spying tool that could record conversations, capture screenshots, log keystrokes, and pull data off machines, aimed mostly at targets in Iran and the wider Middle East. Together they showed that Stuxnet was not a single weapon but the visible piece of a larger, sustained program of the same kind, most of it built to watch instead of break.

I find this the quietly unsettling part. The centrifuge attack got the headlines because it broke something, but the reconnaissance tools running alongside it are the ones built to sit inside a system for months, saying nothing, learning everything. In my operations years, the intrusion that scared me was never the loud one. It was the one that had been there a long time before anybody noticed, because that one had already learned where everything was.

The Ukraine grid: turning off the lights

Then the pattern moved from data to the physical world. Stuxnet’s real inheritance shows there.

In December 2015, attackers took down part of Ukraine’s power grid, cutting electricity to hundreds of thousands of people. Operators watched their own controls move on the screen, worked by hands that weren’t theirs, opening the breakers that carried the power. Human attackers were at the keyboard in real time, reaching into a physical system and switching it off. It was widely attributed to a Russian group.

A year later, in December 2016, they did it again to part of Kyiv, and this time the tool was different in a way that matters. The 2015 attack needed people at the keyboard issuing each command. The 2016 attack used a malware framework, later called Industroyer or Crash Override, that could do the work on its own. It understood the protocols that grid equipment speaks, and it could throw the switches automatically once it was set loose. The human moved up and out of the loop, and the code ran the attack.

That shift is the direct line from Stuxnet. Stuxnet carried its own instructions for wrecking centrifuges once it found them, needing no operator at the moment of damage. Industroyer carried its own instructions for opening breakers. The weapon that runs by itself, once delivered, is the model, and it is the same model that makes the modern AI agent attacks I’ve written about so dangerous: not a person doing harm at machine speed, but a machine doing it with the person no longer required.

Triton: aiming at the last line of defense

The most frightening of Stuxnet’s descendants came in 2017, and it went after the one system nobody is supposed to touch.

A petrochemical plant in Saudi Arabia was hit by malware later called Triton. Its target was the safety instrumented system, the controllers whose entire job is to shut a process down before it reaches an explosion or a release of poison gas. Those systems are the last line of defense in a plant that handles dangerous materials. They exist so that when everything else fails, something still stops a disaster that could kill the people working there.

Triton was built to disable that. Reach the safety system, switch off its protection, and you have removed the thing standing between an industrial accident and a catastrophe. The attack was caught before it caused the worst, reportedly because it accidentally tripped a shutdown and drew attention, but the intent was plain. Someone had built a weapon aimed at the safeguards that keep human beings alive.

Stuxnet broke machines. Triton was designed to remove the protections that keep machines from killing people. That is the distance the field traveled in seven years, and it traveled it because Stuxnet showed the first step was possible.

What is Stuxnet’s real legacy?

It normalized the idea that a nation can reach through a computer and break another nation’s physical world, and it proved a wall could not stop that.

Before Stuxnet, attacking infrastructure meant bombs and soldiers, things a country could see coming and answer in kind, under rules built up over centuries.

Stuxnet opened a way to do that damage with code: quietly, deniably, and from anywhere, against targets that thought their isolation protected them. The nuclear powers noticed. Governments that had never spent much on cyber weapons started spending, hard, because a tool had just been demonstrated that could reach the places their tanks and planes could not. The arms race it started is still running, and there are no treaties governing it the way there are for the older weapons.

One point keeps landing on me across this whole series: none of the descendants needed a new idea. They needed the first proof that the idea worked. Stuxnet was that proof. Every attack in this series after it, and every AI incident I’ve covered since, is a variation on the thing Stuxnet established: that the barrier you trust, whether it’s an air gap, a supplier, or the isolation of a test environment, is only a barrier until someone shows it can be crossed. Once crossed, it is a map.

The next articles leave the world of state cyberweapons for a different kind of trust betrayed: a militant group whose low-tech devices were turned into weapons, and the supply chains that let it happen. For the wider view of security and the people who need to understand it, the cybersecurity hub collects the rest of my work.

Frequently Asked Questions

Did Stuxnet stop Iran’s nuclear program?
No. It destroyed roughly a thousand centrifuges and delayed the program by an estimated few months to two years, but Iran replaced the damaged equipment and continued enriching uranium. The lasting effect was strategic, not final. It proved infrastructure could be attacked through code, and it pushed Iran to build its own offensive cyber capabilities.
What was Shamoon and how is it connected to Stuxnet?
Shamoon was malware that struck Saudi Aramco in 2012, wiping the data on about 30,000 computers instead of spying or stealing. It is widely attributed to Iran and came a few years after Stuxnet demonstrated that energy and industrial targets could be hit through code. It is a clear example of the pattern where a country attacked with a new kind of weapon builds its own version and uses it.
What were Duqu and Flame?
Duqu, found in 2011, was a reconnaissance tool that logged keystrokes and gathered system information, and its code shared enough with Stuxnet that researchers linked the two. Flame, uncovered in 2012, was a large spying tool that could record audio, capture screenshots, and steal data, mostly from targets in Iran and the Middle East. Both suggested Stuxnet was part of a wider, sustained program built largely for surveillance.
How did the Ukraine power grid attacks relate to Stuxnet?
They extended Stuxnet’s core idea, attacking physical infrastructure through code, to a civilian power grid. In 2015, attackers cut power to hundreds of thousands of people with operators at the keyboard. In 2016, a malware framework called Industroyer could open breakers automatically, moving the human out of the loop, the same self-directed model Stuxnet used against centrifuges.
What made the Triton attack so dangerous?
Triton, discovered in 2017 at a Saudi petrochemical plant, targeted the safety instrumented system, the controllers whose job is to shut a process down before it reaches an explosion or a toxic release. Disabling that system removes the last line of defense protecting the people in the plant. Where Stuxnet broke machines, Triton was built to remove the safeguards that keep machines from killing people.
What is Stuxnet’s lasting legacy?
It normalized the idea that a nation can reach through a computer and physically damage another nation’s infrastructure, and it proved that isolation alone could not stop that. Governments that had spent little on cyber weapons began investing heavily, launching an arms race in infrastructure attacks that continues today, without the treaties that govern older classes of weapons.
Why do Stuxnet’s techniques still matter for AI security?
Stuxnet established the model of a weapon that runs on its own once delivered, causing harm with no human at the controls at the moment of damage. That is the same property that makes autonomous AI agent attacks dangerous. The deeper lesson also carries over: a trusted barrier, whether an air gap, a supplier, or an isolated test environment, holds only until someone proves it can be crossed, and then it becomes a map for everyone else.

Continue the Series

1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment