Stuxnet emerged as a landmark cyberweapon that proved malware could move beyond data theft and disrupt physical industrial processes. Analysis of the worm showed it was built to target Siemens SCADA and PLC environments, with payload logic that reached past infected Windows hosts into industrial control systems, including the uranium enrichment facility at Natanz. Researchers described the malware as unprecedented for its time because its sabotage routines operated largely autonomously, showing that cyberattacks against critical infrastructure were practical and highly engineered rather than theoretical.
Technical reviews found that Stuxnet combined broad propagation with precise targeting, exploiting multiple Windows flaws including MS10-046/CVE-2010-2568, MS10-061, MS08-067, MS10-073, MS10-092, and the Siemens WinCC hard-coded password issue CVE-2010-2772. The worm used modular user- and kernel-mode components, signed malicious drivers with stolen Realtek and JMicron certificates, injected into processes, updated peers over RPC, and communicated over HTTP with command-and-control servers. Infection telemetry cited in the technical analysis showed the heaviest spread in Iran, accounting for 52.2% of observed infections, underscoring the operation’s apparent focus despite its wider self-propagation.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The report states that the Stuxnet file ~wtr4141.tmp had a compilation timestamp of 2010-03-02 and was digitally signed.
The analysis states that the MRXNET.sys driver had a compilation timestamp of 2010-01-25 and shared the same linker version as MRXCLS.sys.
The report says the MRXCLS.sys driver was signed on 2010-01-25, reflecting preparation of a trusted kernel component for the malware platform.
According to Ralph Langner, he and two colleagues decoded Stuxnet's payload in 2010 and found code that operated beyond Windows PCs against Siemens industrial control systems at Natanz.
The technical analysis states that the MRXCLS.sys kernel-mode driver used by Stuxnet carried a compilation timestamp of 2009-01-01.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.