Latest
When a Client Thinks the Ghostwriter Used AIThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe One-Hour Call Before I Quote Your BookThe Work You Would Never Have StartedWhen Your Own Memoir Sounds Like BraggingMonthly or Milestone: How Ghostwriting Gets BilledWhat It Costs to Fix an AI-Written ManuscriptThe Quotation Marks That Get Authors SuedThe Hugging Face AI Agent Attack: An Operations ReadingBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreThe Web Got Fenced: What AI Search Costs Small SitesBlack Tuesday: The Web Ring War Nobody Outside It NoticedWhat the AI Visibility Industry Sells, and What the Evidence SaysBlack Tuesday: The Original ring-master.net Page, 2000Behind the Book: Peacekeeper, The Dissolution WarsBehind the Book: Real World SurvivalBehind the Book: Publish Your BookBehind the Book: ReincarnationBehind the Book: Sell Your BooksBehind the Book: Selling on eBay
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

Stuxnet: The Weapon That Rewrote What a Cyberattack Could Be

This entry is part 2 of 13 in the series Nothing Is Isolated
TL;DR: Stuxnet was the first computer attack that reached out of a screen and broke real machines. Built under a secret US and Israeli program called Olympic Games, it destroyed roughly a thousand uranium centrifuges at Iran’s Natanz plant around 2009 and 2010. The plant was air-gapped, cut off from the internet on purpose, and the attack got in anyway. A small Belarusian antivirus firm found it by accident in 2010 after it escaped and spread worldwide. This is the second article in a series on attacks that beat isolation, and Stuxnet is the one that proved code could do the work of a bomb.
Series Navigation  (13 parts)

Every weapon before 2010 obeyed the same rule. To break a machine, you had to touch it. A bomb, a bullet, a saboteur with a wrench, a spy who cut a wire. The damage was always physical, done by something physical, and the wall around a sensitive facility was built to keep physical things out.

Stuxnet broke that rule. It was software, nothing but a pattern of ones and zeros, and it destroyed a thousand precision machines spinning in a hardened plant that no bomb had touched. That is why it matters, and why it earns its own place in this series. Everything before it was a burglar getting through a wall. Stuxnet was the first time the wall didn’t matter, because the weapon was already inside, delivered by people who thought they were just doing their jobs.

What was Stuxnet?

Stuxnet was a computer worm, a self-spreading program in the same family as the Morris worm that opened this series, but built for a single purpose by people with a nation’s resources behind them. Its target was the uranium enrichment plant at Natanz, in Iran, and the centrifuges there: tall, delicate cylinders that spin uranium gas at enormous speed to concentrate the material used in reactors and, if enriched far enough, in weapons.

Iran’s centrifuges ran under the control of industrial computers made by Siemens, the same kind of controllers that run factories, pipelines and power plants all over the world. Stuxnet was written to find those specific controllers, in that specific configuration, and to wreck what they controlled while telling the people watching that everything was fine. It ignored almost every computer it ever touched. It was hunting for one room in one country.

It worked. Between late 2009 and early 2010, roughly a thousand centrifuges at Natanz, about a tenth of the machines in operation, failed or were pulled out and scrapped. The breakage rate ran far past normal wear. Iran’s scientists spent months watching their equipment die and not knowing why, because the computers on their desks kept insisting the machines were running normally.

Where did Stuxnet come from?

Nobody has officially admitted building it, and I’ll be plain about that. The United States has never confirmed its role, and neither has Israel. What follows is the account assembled by journalists, most prominently David Sanger of the New York Times, and by the security researchers who took the code apart. It is widely reported and broadly accepted, and it has never been formally acknowledged by any government that took part. Treat it as the best available reconstruction, not as a signed confession.

The program was reportedly called Olympic Games. It started under President George W. Bush around 2006, at a moment when the United States and Israel wanted to slow Iran’s nuclear progress without dropping bombs, because a physical strike on Natanz risked a wider war. President Obama reportedly continued and expanded the operation after taking office. The goal was sabotage that looked like bad luck: centrifuges failing often enough to set the program back, in a way Iran would blame on its own faulty equipment instead of on an attack.

Reporting since has filled in more of the delivery. A Dutch engineer, recruited by Dutch intelligence at the request of the CIA and Israel’s Mossad, is said to have helped get the infection inside Natanz by installing compromised equipment. He died in a motorcycle accident in Dubai two weeks after the attack, at 36, a detail that has fed speculation ever since and that I’ll leave as what it is, a detail, because I have no way to know more than that.

What the researchers could prove, from the code itself, is that this was not the work of a lone hacker or a criminal crew. The thing was too expensive.

It burned four zero-day exploits at once, previously unknown flaws that sell on the black market for six figures each, and no criminal spends that arsenal on a target that doesn’t pay. It carried drivers signed with certificates stolen from two real hardware companies. It was tailored to one plant’s exact machinery. Reported development cost ran to around a billion dollars across the agencies involved. Everything about it said state, and the states it pointed to were the two with the motive.

How was Stuxnet discovered?

Here is the irony at the center of the whole story. The most carefully targeted cyberweapon ever built was found because it failed to stay where it was put.

Stuxnet was designed to live inside Natanz and die there. It was supposed to spread quietly among the plant’s machines and never leave.

But at some point a programming change let it copy itself onto a laptop that then left the building, and when that laptop connected to the internet, the worm no longer recognized that its environment had changed. It started spreading the way any worm spreads, machine to machine, across the wider world. It infected more than 200,000 computers globally before anyone understood what it was, doing nothing to almost all of them because none of them was the plant it wanted.

In June 2010, a small antivirus company in Belarus called VirusBlokAda got a call about machines in Iran that kept rebooting for no reason. An engineer named Sergey Ulasen, reportedly at a wedding when the call came, spent the evening on the phone trying to work out what was wrong.

His team pulled the malware apart and realized fast that they were looking at something unlike anything in the catalog: code that exploited an unknown Windows flaw just to spread, and drivers signed with certificates that belonged to legitimate Taiwanese hardware makers. That was the moment they knew it was no ordinary virus.

Word moved through the security world, and the big firms took it apart in public. Symantec published a detailed dossier.

A German control-systems expert named Ralph Langner spent weeks on the payload and worked out the part everyone else had missed: this wasn’t spyware and it wasn’t a normal worm. It was aimed at Siemens industrial controllers, and its purpose was to physically damage whatever those controllers ran. By September 2010, with news that Iran’s centrifuges had been failing, the picture came together. The world was looking at the first piece of software built to destroy physical equipment, and it had been running for months before anyone outside Iran knew it existed.

Why was Stuxnet different from every attack before it?

Three things set it apart, and each one opened a door that has stayed open.

It crossed an air gap. Natanz was not connected to the internet. That was the whole defense, the assumption that a plant cut off from the outside world cannot be reached from the outside world. Stuxnet reached it anyway, and the next article in this series is about exactly how, because the method is the lesson.

It caused physical destruction. Before Stuxnet, a computer attack stole data, wiped drives, or knocked a service offline. Damage stayed inside the machines. Stuxnet reached through the controllers and broke steel, spinning centrifuges past what their rotors could survive until they cracked. It proved that code could do what until then had required a bomb or a saboteur, and it did it to one of the most protected facilities on earth.

And it lied to the operators while it worked. A man who spent twenty years in operations cannot read that part calmly. Stuxnet recorded what normal looked like on the plant’s monitoring systems and played that recording back to the control room while it wrecked the machines. The engineers watched their screens, saw ordinary readings, and had no reason to think anything was wrong until the centrifuges started failing in numbers no normal fault could explain. The instruments they trusted had been turned into liars.

I’ve written before, in my reading of the Hugging Face AI agent attack, that the log is the floor every other control stands on, and when the record lies you have lost the ability to know anything at all. Stuxnet is where that lesson starts. Sixteen years before AI agents were caught falsifying their own activity records, a cyberweapon was already feeding a nuclear plant’s operators a recording of a normal day while the machines died in front of them.

What did Stuxnet accomplish in the end?

Less than the headlines suggest, and I’ll state it plainly.

It destroyed around a thousand centrifuges and it set Iran’s program back, by estimates ranging from months to a couple of years. It did that without a single airstrike, without a soldier crossing a border, and without Iran being able to prove for a long time that it had been attacked at all. On its own terms as a sabotage operation, it worked.

But Iran rebuilt. Enrichment continued. And because the worm escaped and was caught, the secret was out: the code was studied by every government and security researcher on earth, and the techniques inside it went into circulation. The operation bought time and lost the element that made it special. Whether the trade was worth it is an argument that people who know far more than I do still have, and I won’t pretend to settle it.

What is not in dispute is what Stuxnet started. It proved a nation could reach across the world through a computer and break another nation’s infrastructure, and it proved a physical wall could no longer stop that. Every attack in the rest of this series lives in the world Stuxnet made.

The next article takes apart the piece that should worry anyone who has ever trusted a wall: how a weapon crossed an air gap that was supposed to be uncrossable. For the wider view of security and the executives and writers who need to understand it, the cybersecurity hub collects the rest of my work on this.

Frequently Asked Questions

What did the Stuxnet worm target at Natanz?
Stuxnet was a computer worm discovered in 2010 that was built to physically damage industrial equipment. Its target was the uranium enrichment plant at Natanz, Iran, and the Siemens industrial controllers that ran the centrifuges there. It destroyed roughly a thousand centrifuges while showing the plant’s operators normal readings, and it is widely regarded as the first cyberweapon to cause physical destruction.
Who created Stuxnet?
No government has officially confirmed responsibility. Based on investigative journalism and technical analysis of the code, it is widely reported to have been built by the United States and Israel under a secret program called Olympic Games, started around 2006 under President Bush and continued under President Obama. The evidence is strong and broadly accepted, but it has never been formally acknowledged.
How was Stuxnet found if it was so well hidden?
It was found by accident in June 2010 after it escaped its intended target. A programming change let it spread beyond Natanz onto internet-connected computers, where it infected more than 200,000 machines worldwide. A small Belarusian antivirus firm, VirusBlokAda, was called about Iranian computers that kept rebooting, took the malware apart, and recognized it as something unlike anything before it. Symantec and researcher Ralph Langner later worked out its true purpose.
How much damage did Stuxnet do to Iran’s nuclear program?
It destroyed roughly a thousand centrifuges at Natanz between late 2009 and early 2010, about a tenth of the operating machines, and set Iran’s enrichment program back by an estimated few months to a couple of years. Iran rebuilt and enrichment continued, so the operation bought time instead of stopping the program.
Why is Stuxnet considered the first cyberweapon?
Because it was the first piece of software proven to cross from the digital world into the physical one and destroy real equipment. Earlier attacks stole data, wiped drives, or knocked services offline. Stuxnet reached through industrial controllers and physically broke centrifuges, doing damage that until then had required a bomb or a saboteur, against a facility cut off from the internet.
Did Stuxnet hide its activity from the plant operators?
Yes. It recorded normal readings from the plant’s monitoring systems and replayed them to the control room while it drove the centrifuges to destruction. The operators saw ordinary values on their screens and had no reason to suspect an attack until machines began failing at a rate no normal fault could explain. The instruments they relied on had been made to lie.
Is Stuxnet still a threat today?
Not directly. It was built for one specific plant configuration and carried an expiry date, and Siemens patched the flaws it used. Its lasting danger is the precedent. Once it was discovered, its techniques were studied worldwide and inspired later attacks on industrial and critical infrastructure. The final articles in this series cover them.

Continue the Series

1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment