Electronic Warfare

Stuxnet

Also known as
  • W32.Stuxnet
  • Operation Olympic Games malware
  • Stuxnet worm
  • Win32/Stuxnet

Stuxnet was a specialized cyber-physical weapon built around Windows propagation, Siemens Step7/WinCC engineering environments, and malicious programmable-logic-controller code. Public U.S. reporting attributed the Olympic Games program to U.S.-Israeli intelligence, while CISA, MITRE, Symantec/Broadcom, Langner, and Institute for Science and International Security material trace how the malware moved through engineering systems, manipulated S7 controllers, and was linked to damage at Iran's Natanz centrifuge plant.

Profile / Specs

Profile

Origin
United States / Israel (attributed)
Type
Industrial-control-system malware
Service note
Discovered in 2010; development and effects reported in the late 2000s
Designer
NSA, CIA and Israeli intelligence (reported attribution)
Designed
Mid-to-late 2000s (reported)
Unit cost
Not publicly disclosed
Produced
Not publicly disclosed
Number built
Software tool; number of copies not publicly established

Specifications

Target environment
Microsoft Windows engineering systems associated with Siemens Step7/WinCC software, Siemens S7 programmable logic controllers, and industrial-control workflows
Exploitation
CISA described four zero-day exploits; MITRE maps Stuxnet to Windows privilege escalation, print-spooler and server-service propagation, removable-media replication, project-file infection, and hardcoded WinCC credentials
Propagation
Removable media, network shares, peer-to-peer RPC updating, and Step7 project infection enabled spread through trusted engineering and contractor pathways rather than simple internet scanning
PLC interception
Symantec/Broadcom and MITRE describe Step7 communication interception through replacement or masquerading of the s7otbxdx.dll PLC communication library
Industrial payload
Technical analyses separate the PLC effects into a rotor-speed manipulation path for S7-315 centrifuge-drive systems and a more complex S7-417 overpressure path for cascade-protection equipment
Operator deception
The S7-417 analysis describes recorded input values replayed to human-machine-interface displays while malicious controller logic manipulated process conditions
Known impact assessment
Institute for Science and International Security assessed that Stuxnet likely destroyed about 1,000 IR-1 centrifuges at Natanz in late 2009 or early 2010, while also cautioning that the overall enrichment effect was limited
Cyber-Physical Attack Path

Open technical sources describe Stuxnet as a chain from Windows infection to Siemens engineering software, then to PLC code that changed centrifuge-related behavior while trying to hide the change from operators. The evidence is strongest at the component and process level: propagation, Step7/WinCC compromise, S7 controller manipulation, and Natanz impact assessments.

Entry layer

Windows hosts, removable media, network shares, RPC updating, and Step7 project files carried the malware toward engineering systems.

Supported by CISA, MITRE ATT&CK, and Symantec/Broadcom.

Controller layer

The technical literature identifies Siemens S7 controller payloads, including S7-315 drive manipulation and S7-417 cascade-protection manipulation.

Supported by Langner's technical analysis and ISIS Natanz assessments.

Effect limit

Open-source assessments connect the malware to damaged Natanz IR-1 centrifuges, but public sources still leave uncertainty about exact effect size and official state responsibility.

Supported by ISIS and attribution reporting.

Variants

Public technical sources separate Stuxnet by function and observed development phase rather than by an official family of fielded variants.

VariantConfigurationDesignation notes
Stuxnet dropper and Windows propagation layerWindows infection and spread component

CISA, MITRE, and Symantec/Broadcom describe the Windows-side malware using removable media, network propagation, rootkit techniques, command-and-control reporting, and Step7 project infection before a matching industrial-control environment was reached.

Sources: CISA Primary Stuxnet Advisory, MITRE ATT&CK Stuxnet, W32.Stuxnet Dossier

S7-315 rotor-speed attackCentrifuge drive manipulation payload

Langner's technical analysis identifies an S7-315 branch aimed at centrifuge drive systems by manipulating rotor speeds through frequency-converter control logic.

Sources: Langner To Kill a Centrifuge

S7-417 overpressure attackCascade protection manipulation payload

Langner describes an earlier, more complex S7-417 payload that targeted the Cascade Protection System, replayed recorded process values, and manipulated valves and pressure readings in a Natanz cascade context.

Sources: Langner To Kill a Centrifuge

Timeline

Stuxnet Key Events

  1. Early Stuxnet components in use

    MITRE records Stuxnet as discovered in 2010 but notes that some components were in use as early as November 2008.

    Sources: MITRE ATT&CK Stuxnet

  2. Natanz damage window assessed

    Institute for Science and International Security assessed that Stuxnet may have destroyed about 1,000 IR-1 centrifuges at Natanz in late 2009 or early 2010.

    Sources: ISIS Natanz Stuxnet Assessment, ISIS Natanz Stuxnet Update

  3. Stuxnet becomes public

    Security companies began reporting the worm in June 2010, prompting official industrial-control-system mitigation guidance.

    Sources: CISA Stuxnet Malware Mitigation

  4. U.S. industrial-control advisory

    CISA's primary advisory described malware targeting Siemens control software and noted the use of four zero-day exploits.

    Sources: CISA Primary Stuxnet Advisory

  5. Symantec dossier released

    Symantec/Broadcom announced the W32.Stuxnet Dossier after weeks of analysis, covering infection statistics, propagation, command-and-control behavior, and the PLC infector.

    Sources: Symantec Stuxnet Dossier Announcement, W32.Stuxnet Dossier

  6. Updated Natanz assessment

    Institute for Science and International Security said later information increased the likelihood that the S7-315-focused part of Stuxnet caused Natanz centrifuge damage, while noting that the attack did not stop Iran's enrichment program.

    Sources: ISIS Natanz Stuxnet Update

  7. U.S.-Israeli attribution reporting

    The Washington Post reported that current and former officials described Olympic Games as a collaborative NSA, CIA and Israeli effort against Iranian centrifuges at Natanz.

    Sources: Washington Post Stuxnet U.S. Israeli experts

  8. Langner technical analysis published

    Ralph Langner's To Kill a Centrifuge separated the Natanz attack into a complex S7-417 overpressure path and a later S7-315 rotor-speed path.

    Sources: Langner To Kill a Centrifuge

Media
Related Weapon Systems
Gateway Mission Router, Cyber-hardened air-to-ground communications and command-and-control router, Electronic WarfareElectronic WarfareGateway Mission RouterCyber-hardened air-to-ground communications and command-and-control routerGateway Mission Router is a V2X/Vertex battlefield communications router for air-to-ground command-and-control networks. Public sources describe GMR and GMR-1000 as cyber-hardened, platform-independent hardware that routes datalinks, assured communications, situational-awareness data, and command-and-control information across aviation and ground platforms, including U.S. Army Air Warrior and Combined Joint All-Domain Command and Control modernization contexts.
Gulfstream G500 Nachshon Shavit, Signals-intelligence and electronic-reconnaissance aircraft, Aircraft & UAVsAircraft & UAVsGulfstream G500 Nachshon ShavitSignals-intelligence and electronic-reconnaissance aircraftThe Gulfstream G500 Nachshon Shavit is Israel's Gulfstream V/G500-based special electronic missions aircraft, converted for Israeli Air Force 122 Squadron with IAI/ELTA mission systems for signals intelligence, electronic reconnaissance, and long-range ISR support. Official IAI material describes Shavit as the Nachshon fleet's SIGINT aircraft for monitoring the electromagnetic spectrum, while public image and fleet sources identify it as the earlier Gulfstream V/G500 member alongside the G550 Eitam and Oron aircraft.
Stunner interceptor, Missile interceptor, Air DefenseAir DefenseStunner interceptorMissile interceptorThe Stunner interceptor is the two-stage hit-to-kill missile fired by David's Sling, Israel's mid-tier air and missile-defense layer co-developed by Rafael and Raytheon. CSIS describes the missile as using radar datalink updates and onboard terminal seekers, while RTX markets SkyCeptor as a Stunner-family variant for short- to medium-range missile-defense threats. Source-backed operational use is documented in Gaza-related interceptions and the post-October 2023 Israel-Hezbollah fighting.
Skynex, Networked short-range air defense system, Air DefenseAir DefenseSkynexNetworked short-range air defense systemSkynex is Rheinmetall Air Defence's modular short-range air defense architecture built around the Oerlikon Skymaster battle management system, networked X-TAR3D-class sensors, and autonomous 35 mm Revolver Gun Mk3 effectors firing programmable AHEAD ammunition. German-funded Skynex systems in Ukrainian service have been reported in truck-mounted power-plant defense roles, while Italy received the first NATO-member Skynex battery in December 2025.
GBU-57A/B Massive Ordnance Penetrator, Air-delivered deep-penetration guided bomb, MunitionsMunitionsGBU-57A/B Massive Ordnance PenetratorAir-delivered deep-penetration guided bombThe GBU-57A/B Massive Ordnance Penetrator is a Boeing-built U.S. Air Force GPS-guided bunker-buster bomb for hardened and deeply buried facilities. Developed from a Defense Threat Reduction Agency technology demonstration and integrated for B-2 Spirit employment, it became operationally documented in June 2025 when U.S. B-2s used 14 weapons against Iranian nuclear target areas during Operation Midnight Hammer, an event tracked in both the catalog's U.S.-Iran and 2025 Israel-Iran conflict scopes.

Sources