Stuxnet is a highly sophisticated Windows worm developed for sabotage of industrial control systems, most notably Iran’s Natanz uranium-enrichment facility. Widely attributed to a U.S.-Israeli operation, it targeted industrial infrastructure and used false-data injection to conceal physical sabotage by presenting normal-looking centrifuge sensor readings to operators. Tailored Access Operations personnel contributed to its development. Stuxnet exploited Windows vulnerabilities, including CVE-2010-2743 for local privilege escalation, established execution through scheduled tasks and driver-loading Registry modifications, and injected DLLs into trusted processes. It performed host and network reconnaissance, enumerated network resources, collected system network information, and transmitted victim information over HTTP. Its use of encrypted in-memory resources, encoded communications, process injection, and deceptive industrial-process reporting supported evasion and concealment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2010-2743 The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." | CVE-2010-2743 ... allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability."
...as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems... https://www.geoffchappell.com/notes/security/stuxnet/ctrlfldr.htm
...as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems... https://www.geoffchappell.com/notes/security/stuxnet/ctrlfldr.htm
Stuxnet ... CVE-2008-4250 (RPC RCE) | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Stuxnet ... CVE-2010-3338 (Task Scheduler EoP) | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Infected Siemens Simatic Step7 project files using exploit for vulnerability CVE-2012-3015. | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Stuxnet ... CVE-2006-3439 (RPC RCE) | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Stuxnet was well known for its use of CVE-2010-2729, the Windows Print Spooler RCE exploit. Flame used it as well. | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“TAO’s coding savants helped craft the digital weapon known as Stuxnet.”
Ultimately, it turned out that the fortuitous discoveries of Stuxnet, Duqu, and Flame were in fact related beyond superficial succession.
The tranquil days of reverse engineering banking trojans were pierced by Stuxnet, Duqu, Flame, Gauss, and MiniFlame.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
Trojan spreads via new Windows hole ... Malware Targets Shortcut Flaw in Windows SCADA ... PoC Exploit Code Available for Windows LNK Vulnerability | The Aurora and Stuxnet attacks used 0-day exploits to install malicious programs onto the system... Stuxnet: MS10-046 (0-day), MS10-061 (0-day), MS10-073 (0-day), MS10-092 (0-day), CVE-2010-2772 (0-day), MS08-067 (patched).
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The Stuxnet attack constituted a serious threat to trust in software using legal digital signatures... even has digital certificates for installed modules published in the name of reputable companies.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
IoCs include services such as mrxcls service, WinMI32 service, HP003044 service, NetBIOS2010 service, pnppci service, ethio service, ntdos505 service.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
Stuxnet ... was a worm that spread over USB using the 0-day .LNK vulnerability
http://www.microsoft.com/technet/security/bulletin/ms10-061.mspx; ... ms10-061-printer-spooler-vulnerability.aspx | Another way in which the worm replicates itself over the network exploits a vulnerability in Window Spooler (MS10-061)... The worm is also capable of distributing itself over the network through shared folders... Stuxnet’s exploitation of the MS08-67 vulnerability to propagate itself through the network...
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cyber weapon used against Iran's nuclear program that reportedly disabled several hundred centrifuges.
ICS-focused sabotage malware cited as a historical example of using false-data injection to replay normal centrifuge sensor readings and hide malicious process changes from HMIs and controllers.
A digital weapon whose development was aided by TAO personnel.
Malware used in a US/Israeli operation targeting Iranian centrifuges in an air-gapped nuclear enrichment environment, notable for sabotaging industrial infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.