Stuxnet
Stuxnet is a computer worm, publicly identified in 2010, that sabotaged industrial processes by reprogramming Siemens PLCs while hiding the changes from operators, and is widely regarded as the first publicly known malware designed to damage physical equipment.
Stuxnet is a computer worm, publicly identified in 2010, that was designed to sabotage industrial processes by reprogramming Siemens PLCs. It targeted systems running Siemens Step 7 engineering software and S7 controllers driving frequency converters, and is widely reported to have damaged uranium enrichment centrifuges at Iran's Natanz facility. It is generally regarded as the first publicly known malware built to cause physical damage through an industrial control system.
Stuxnet spread through infected USB drives and local networks, exploiting several previously unknown Windows vulnerabilities and using drivers signed with stolen digital certificates. On reaching a matching configuration, it modified PLC code to alter motor speeds while replaying recorded normal values to operators, hiding the manipulation. It changed security thinking across the industrial sector, showing that isolated networks could be breached and that control logic itself could be a target.
As a historical case, Stuxnet illustrates the importance of removable media control, engineering workstation security, monitoring of controller program changes and integrity checking of PLC logic. It also showed how highly targeted attacks can rely on detailed knowledge of a specific process and its equipment. Detailed public analyses, including Symantec's W32.Stuxnet Dossier and the work of Ralph Langner, document how the attack operated.
Key points
- Publicly identified in 2010; targeted Siemens Step 7 software and S7 PLCs
- Spread via USB drives and networks using several Windows zero-day vulnerabilities
- Altered motor speeds while replaying normal values to operators
- Showed that air-gapped industrial networks can be breached
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- Removable Media ControlOT & Industrial Cybersecurity
- Engineering Workstation SecurityOT & Industrial Cybersecurity
- Air GapOT & Industrial Cybersecurity
- Controller Write ProtectionOT & Industrial Cybersecurity
- Programmable Logic Controller (PLC)PLC & Industrial Control
- Industroyer (CrashOverride)OT & Industrial Cybersecurity