Tech●●●●●Difficulty 4 of 5

How did a computer worm wreck uranium centrifuges?

Stuxnet crossed an air gap on a USB stick and told the operators everything was normal while it wrecked machines.

▶ Start the story

Stuxnet was a computer worm that sabotaged machines by changing how fast they spun. It was first uncovered in June 2010 and targeted industrial control systems, the small computers that run factory equipment. It is believed to have caused substantial damage to Iran's nuclear program after being first installed on a computer at the Natanz Nuclear Facility in 2009. Neither the United States nor Israel has openly admitted responsibility, but multiple news organizations have said it was a joint cyberweapon, known as Operation Olympic Games.

The worm typically travelled on infected USB flash drives, crossing any air gap. On a Windows computer it looked for Siemens Step7 software controlling a programmable logic controller; with neither in place, it became dormant. When it found its target, it changed the speed of the connected motors. It only attacked systems whose motors spun between 807 and 1,210 hertz, much faster than most industrial motors, with the notable exception of gas centrifuges.

How Stuxnet reached its target
  1. Step 1: Infected USB drive

    Crosses the air gap

  2. Step 2: Windows computer

    Looks for Siemens Step7 software

  3. Step 3: Controller check

    Dormant unless the target matches

  4. Step 4: Motor speeds changed

    Normal readings shown to operators

The damage worked in two steps: first speeding an infected centrifuge up from its normal 1,064 hertz to 1,410 hertz for 15 minutes, then 27 days later slowing it to a few hundred hertz for 50 minutes. The stress made aluminium tubes expand, often forcing parts into contact and destroying the machine. Meanwhile a rootkit masked the speed changes from monitoring systems and fed the users a loop of normal values.

It was found because it escaped. The timing of discovery has been attributed to a programming error that let the virus spread beyond its intended target. By August 2010, 60 percent of infected computers were in Iran. Sergey Ulasen of the antivirus company VirusBlokAda discovered it, and it became the first discovered malware to spy on and subvert industrial systems.

Quiz me

0/3

  1. 1.How did Stuxnet reach computers that were not connected to the internet?
  2. 2.Why did the worm check a motor's frequency before attacking?
  3. 3.Why did the people monitoring the plant not notice the speed changes?

Recap

Even a network cut off from the internet can be reached by a USB drive, and the damage can be physical.

💡 A trick to remember it · USB in, dormant until the target fits, then the wrong speed and a calm screen: a worm with a sniper's patience.

Surprising fact · Stuxnet used four zero-day flaws, unusually many for one worm.

Sources (1)

No source, no claim. Every fact in this lesson (15 claims) cites at least one of these.

  1. [1]Stuxnet · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗