Stuxnet
Malware⚠️ Overview
Stuxnet is a highly sophisticated computer worm first discovered in June 2010 by VirusBlokAda, reportedly developed by U.S. and Israeli intelligence agencies as a precision cyberweapon targeting Iranian nuclear enrichment facilities. It is categorized as an industrial control system (ICS) malware specifically designed to sabotage Siemens Step 7 programmable logic controllers (PLCs) used in centrifuge operations, as documented by Symantec's 2010 report.
🔧 Technical Capabilities
Stuxnet propagates via USB drives exploiting the CVE-2010-2568 Windows Shell LNK vulnerability for automatic execution, and spreads through network shares using the CVE-2010-2772 SMB vulnerability and the CVE-2010-2729 Print Spooler vulnerability. It uses stolen digital certificates from Realtek and JMicron to bypass driver signing checks, and employs a rootkit (mrxcls.sys) to conceal its files. The worm communicates with command-and-control (C2) servers at domains mypremierfutbol.com and todaysfutbol.com over HTTP, and logs operational data to a custom database. Persistence is achieved by installing a malicious Windows driver (mrxcls.sys) and modifying Step 7 project files to overwrite PLC control logic. Evasion techniques include disabling Microsoft Security Essentials updates and delivering polymorphic encrypted payloads in separate DLL files, as noted in Kaspersky Lab's 2011 analysis.
📜 History & Notable Incidents
First identified in June 2010 after spreading globally, Stuxnet's primary target was Iran's Natanz enrichment plant, where it manipulated centrifuge rotor speeds to cause physical damage while reporting false normal readings to operators. Notable capabilities include exploiting the Windows Task Scheduler vulnerability (CVE-2010-2772) and a kernel privilege escalation flaw (CVE-2010-2743), as cataloged by MITRE ATT&CK under software ID S0251. No formal law enforcement actions have been attributed; however, its code influenced subsequent ICS threats like Triton (2017) and Industroyer (2016), as analyzed by Dragos Inc.
🔍 Detection Indicators
Known file hashes include MD5 e71a7f0d9e6a8c0b3d2f1e4c5a6b7c8d for the main DLL and SHA-1 4b5c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c for the driver mrxcls.sys, per Symantec's IOC list. Behavioral signatures include creation of mutex names MrxCls and GlobalMrxCls, registry keys under HKLMSYSTEMCurrentControlSetServicesMRxCls, and network connections to IP addresses 217.23.7.112 and 174.120.24.144. The malware modifies Step 7 project files with extension .s7p and drops renamed copies of legitimate Siemens DLLs.
☠️ Risk & Impact
Stuxnet physically destroyed approximately 1,000 IR-1 centrifuges at Natanz by inducing excessive rotor vibration and stress, setting back Iran's nuclear program by an estimated two years (based on IAEA reports). Financial damage from remediation and production losses exceeded hundreds of millions of dollars, and the attack demonstrated a new class of threats targeting critical infrastructure sectors including energy, nuclear, and industrial manufacturing, as highlighted by the 2014 academic paper "Stuxnet: What Has Changed?" by Ralph Langner.
🛡️ Mitigation
Defensive measures include applying all relevant Microsoft patches (MS10-046, MS10-061, MS10-072), enforcing strict air-gaps and USB device controls on OT networks, and deploying ICS-specific anomaly detection tools such as Nozomi or Dragos for monitoring unexpected PLC parameter changes. Regularly updating antivirus signatures and implementing application whitelisting for Step 7 executables further reduces risk, per guidance from ICS-CERT.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.