Open technical sources describe Stuxnet as a chain from Windows infection to Siemens engineering software, then to PLC code that changed centrifuge-related behavior while trying to hide the change from operators. The evidence is strongest at the component and process level: propagation, Step7/WinCC compromise, S7 controller manipulation, and Natanz impact assessments.
Entry layerWindows hosts, removable media, network shares, RPC updating, and Step7 project files carried the malware toward engineering systems.
Supported by CISA, MITRE ATT&CK, and Symantec/Broadcom.
Controller layerThe technical literature identifies Siemens S7 controller payloads, including S7-315 drive manipulation and S7-417 cascade-protection manipulation.
Supported by Langner's technical analysis and ISIS Natanz assessments.
Effect limitOpen-source assessments connect the malware to damaged Natanz IR-1 centrifuges, but public sources still leave uncertainty about exact effect size and official state responsibility.
Supported by ISIS and attribution reporting.