How did a computer worm wreck uranium centrifuges?
Stuxnet crossed an air gap on a USB stick and told the operators everything was normal while it wrecked machines.
▶ Start the storyStuxnet was a computer worm that sabotaged machines by changing how fast they spun. It was first uncovered in June 2010 and targeted industrial control systems, the small computers that run factory equipment. It is believed to have caused substantial damage to Iran's nuclear program after being first installed on a computer at the Natanz Nuclear Facility in 2009. Neither the United States nor Israel has openly admitted responsibility, but multiple news organizations have said it was a joint cyberweapon, known as Operation Olympic Games.
The worm typically travelled on infected USB flash drives, crossing any air gap. On a Windows computer it looked for Siemens Step7 software controlling a programmable logic controller; with neither in place, it became dormant. When it found its target, it changed the speed of the connected motors. It only attacked systems whose motors spun between 807 and 1,210 hertz, much faster than most industrial motors, with the notable exception of gas centrifuges.
Step 1: Infected USB drive
Crosses the air gap
Step 2: Windows computer
Looks for Siemens Step7 software
Step 3: Controller check
Dormant unless the target matches
Step 4: Motor speeds changed
Normal readings shown to operators
The damage worked in two steps: first speeding an infected centrifuge up from its normal 1,064 hertz to 1,410 hertz for 15 minutes, then 27 days later slowing it to a few hundred hertz for 50 minutes. The stress made aluminium tubes expand, often forcing parts into contact and destroying the machine. Meanwhile a rootkit masked the speed changes from monitoring systems and fed the users a loop of normal values.
It was found because it escaped. The timing of discovery has been attributed to a programming error that let the virus spread beyond its intended target. By August 2010, 60 percent of infected computers were in Iran. Sergey Ulasen of the antivirus company VirusBlokAda discovered it, and it became the first discovered malware to spy on and subvert industrial systems.
Quiz me
0/3
Recap
Even a network cut off from the internet can be reached by a USB drive, and the damage can be physical.
💡 A trick to remember it · USB in, dormant until the target fits, then the wrong speed and a calm screen: a worm with a sniper's patience.
Surprising fact · Stuxnet used four zero-day flaws, unusually many for one worm.
Connects to
- 💔 How did one bug put much of the internet at risk, from Heartbleed to Log4Shell?
- 🪱 How did one student's experiment slow down the early internet?
- ⚖️ Should governments tell vendors about the flaws they find, or keep them for spying?
- 🕳️ What is a zero-day, and why do companies pay hackers to find bugs?
- ✍️ How can a message prove who really sent it?
Sources (1)
No source, no claim. Every fact in this lesson (15 claims) cites at least one of these.