Stuxnet is a highly sophisticated Windows worm and cyber-sabotage platform targeting Siemens SIMATIC WinCC and STEP 7 industrial-control environments and associated programmable logic controllers. Its payload was narrowly tailored to industrial processes, while its propagation mechanisms spread broadly through removable media and Windows networks. Stuxnet is associated with the disruption of Iran’s nuclear-enrichment program at Natanz. Its state sponsorship is widely alleged publicly, but is not established by the available evidence. Stuxnet exploited multiple Windows vulnerabilities for propagation and privilege escalation, including CVE-2010-2568, MS10-061, MS08-067, MS10-073, and MS10-092, and abused the Siemens WinCC hard-coded-password issue tracked as CVE-2010-2772. It used signed kernel drivers, process injection, file-system filtering to conceal propagation artifacts, peer-to-peer updates between infected systems, and encrypted HTTP-based command-and-control. The operation also used stolen code-signing certificates to make malicious drivers appear trusted. Its modular design supported remote delivery and execution of additional components. Stuxnet is regarded as a landmark example of precision malware designed to manipulate or damage industrial processes rather than conduct conventional data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a sabotage operation that targeted Iran’s enrichment capacity by over-pressuring centrifuges and falsifying telemetry to mislead operators.
Referenced as a separate operator group that reportedly shared/received exploits with/from Equation Group; used zero-days that appeared earlier in Equation Group tooling (per Kaspersky’s linkage discussion).
A named activity cluster referred to as the Stuxnet team, assessed as still active and linked to follow-on espionage and targeted attacks against Certificate Authorities, small CAs, and industrial systems via code closely related to the original Stuxnet.
The operators behind Stuxnet are known for conducting highly sophisticated cyber sabotage operations targeting critical infrastructure, specifically the Iranian nuclear enrichment program at Natanz.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.