Skip to content
Security Notes

Stuxnet: four zero-days and one centrifuge plant

By Elias Lankinen10 min read

The centrifuges that tore themselves apart

Sometime in late 2009, inside a hardened hall buried eight metres under the desert near the Iranian town of Natanz, aluminium rotors began to fail. These were IR-1 gas centrifuges, roughly two-metre tubes spinning at more than a thousand revolutions per second to separate uranium isotopes. They were finicky machines at the best of times. But this was different. Over a matter of months, Iran decommissioned and replaced roughly 1,000 of them, more than a tenth of the plant's peak installed stock, according to the Institute for Science and International Security, which was watching the site through International Atomic Energy Agency records. The engineers in the control room had no obvious reason why. Their screens showed the cascade humming along inside its normal range. Nothing was flashing red. That was the point.

Source: Wikimedia Commons
Source: Wikimedia Commons

What was killing the centrifuges was a piece of software, later named Stuxnet, that has a fair claim to being the first weapon made entirely of code to cause physical destruction in the real world. It is remembered in headlines for a single arresting fact: it burned through four "zero-day" exploits, previously unknown software flaws for which no patch yet existed. But the four zero-days were the least original thing about it. The real breakthrough was quieter, and more disturbing.

The machine it was built to break

To understand Stuxnet you have to understand what it was attacking. Uranium as it comes out of the ground is overwhelmingly U-238, with less than one percent of the fissile isotope U-235 that a reactor, or a bomb, needs more of. A gas centrifuge enriches it by spinning uranium hexafluoride gas at enormous speed so the very slightly heavier U-238 drifts outward, letting the lighter U-235 be skimmed from the centre. One machine barely moves the needle, so they are plumbed together in long chains called cascades, the output of one feeding the next.

Source: U.S. Department of Energy via Wikimedia Commons
Source: U.S. Department of Energy via Wikimedia Commons

Iran's workhorse was the IR-1, a design descended from 1970s European technology sold on by the Pakistani proliferation network. It was notoriously fragile. Its rotor, spun by a high-frequency electric motor, sits close to its structural limits even when everything is working. The ISIS analysts noted that the IR-1's nominal frequency is around 1,064 hertz, and Iran tended to run it conservatively at about 1,007 Hz to reduce breakage. The rotor's mechanical danger zone begins not far above, somewhere around 1,400 Hz, where the aluminium can no longer hold itself together. The speed of those motors is set by a device called a frequency converter, or variable-frequency drive. And the frequency converter, in turn, takes its orders from a programmable logic controller, or PLC, the small ruggedised computers that run almost every factory, pipeline, and power plant on Earth. At Natanz the PLC was a Siemens S7-315. That machine, and the converters wired to it, were what Stuxnet had come for.

Four zero-days and two stolen identities

Getting there was the first problem. Natanz's control systems were air-gapped, meaning physically disconnected from the internet. No amount of remote hacking reaches a network that has no wire to the outside world. So Stuxnet was built to travel by hand, riding infected USB flash drives carried in by engineers and contractors, then patiently spreading machine to machine once inside. To do that reliably it spent an extraordinary arsenal. Most malware guards its zero-days jealously, because a zero-day is a wasting asset: the moment it is used and spotted, vendors patch it and it dies. Stuxnet used four at once, which was unheard of. Two were for spreading. The first, catalogued as CVE-2010-2568, abused the way Windows drew shortcut icons: simply opening the folder on an infected USB stick in Windows Explorer ran the malware, with no click required. The second exploited a flaw in the Windows print spooler to jump between machines that shared a printer. The other two were escalation-of-privilege bugs, a Windows Task Scheduler flaw and a keyboard-layout flaw in the kernel (CVE-2010-2743), used to seize full administrator rights on a machine once Stuxnet had a foothold. For good measure it also carried the older, already-patched vulnerability (MS08-067) that the Conficker worm had made famous. Then came the detail that told analysts they were looking at a state, not a criminal gang. Stuxnet's drivers were digitally signed with legitimate cryptographic certificates stolen from two Taiwanese hardware companies, Realtek and JMicron, whose offices sat in the same technology park. A signed driver is one Windows trusts and loads without complaint. To obtain those private keys someone had to compromise two separate legitimate companies purely to borrow their reputations. This was not opportunism. It was a supply chain of forgery built to make the weapon invisible.

The payload nobody had seen before

All of that, the whole elaborate delivery machine, existed to get one final component onto the right computer: a machine running Siemens Step 7, the software engineers use to program the S7 PLCs. On the millions of computers Stuxnet eventually reached, this payload did precisely nothing. It was inert unless it found a very specific configuration: a Siemens controller wired to a particular number of frequency converters, made by the Finnish firm Vacon or the Iranian firm Fararo Paya, running the motors at between 807 and 1,210 Hz. Those are not speeds you find in a bottling plant. They are the fingerprint of a uranium enrichment cascade. Stuxnet was checking, before it acted, that it had arrived at Natanz and nowhere else.

Source: Ulli1105 via Wikimedia Commons
Source: Ulli1105 via Wikimedia Commons

When it found its target, it did something no malware had done before. It rewrote the PLC's own control logic, inserting itself between the Windows programming station and the controller. According to Symantec's landmark W32.Stuxnet Dossier, this was the first ever PLC rootkit: code that lived inside an industrial controller and lied to anyone who inspected it. When an engineer opened Step 7 to check what the PLC was running, Stuxnet handed back the original, clean, unmodified logic. The sabotage was hidden underneath. Then it waited. Stuxnet did not attack constantly, which would have been noticed. It sat dormant for periods of days to weeks, and only then triggered one of its sabotage routines. In the sequence Symantec labelled as one of the attacks, it drove the converter output up to 1,410 Hz, past the rotors' safe limit, for about fifteen minutes. Then it returned everything to normal and disappeared back into dormancy. Some time later, roughly 27 days on by the ISIS reconstruction, a different routine slammed the frequency down toward 2 Hz for around fifty minutes before restoring it. Speed the fragile rotors up until they warped; slow them to a crawl; repeat over months.

The lie told to the control room

The most chilling part was the deception layered on top. While a sabotage routine ran, Stuxnet did not simply hide the changed program. It fed the operators' monitoring systems fake data. Before an attack, it recorded normal sensor readings from the plant, then played that recording back on a loop while it manipulated the motors, so the control room saw a placid, healthy cascade the whole time the machines were being wrecked. It also disabled the automatic safety shut-offs that should have cut in when the frequencies went out of bounds. This is a classic man-in-the-middle attack, the same trick a fraudster uses to sit between you and your bank, but pointed at spinning metal. The independent researcher Ralph Langner, whose team did much of the early reverse engineering, argued in his analysis To Kill a Centrifuge that Stuxnet actually contained two distinct weapons written years apart. An earlier, subtler one attacked the Cascade Protection System on a Siemens S7-417 controller, closing isolation valves to raise gas pressure inside the centrifuges. The later, cruder one was the rotor-speed attack. Both shared a goal that Langner emphasised: the damage was engineered to look like ordinary equipment failure. The centrifuges were to seem simply unreliable, so that Iran would chase phantom manufacturing defects, sack suppliers, and lose confidence in its own machines rather than suspect an attacker at all. That is the misconception worth clearing up. Stuxnet was not a digital explosion. It was a whisper campaign against a nation's engineers, designed to make good people doubt their own instruments.

Who builds a thing like this

A weapon this specific cannot be written from a bedroom. To target Natanz, its authors needed the cascade's exact wiring, the model numbers of the converters, the plant's operating frequencies, and enough understanding of centrifuge physics to know which speeds would cause slow, deniable wear rather than an obvious blowout. That is intelligence work, not just coding. In June 2012 the New York Times reporter David Sanger, drawing on interviews with current and former officials, reported that Stuxnet was part of a joint American and Israeli operation code-named Olympic Games. By his account the effort was conceived under President George W. Bush around 2006, as an alternative to an Israeli airstrike on Iran's facilities, and was accelerated under President Barack Obama. The technical work is widely attributed to the U.S. National Security Agency working with Israel's signals-intelligence Unit 8200. Sanger reported that the United States had even built a replica of the Natanz cascade, using centrifuges of the same lineage, to test the code on real machines before deploying it. No government has formally confirmed authorship, and it is worth stating plainly that the attribution rests on journalism and leaks rather than an official admission. It became solid enough, though, that the U.S. government opened a leak investigation into Sanger's sources. That inquiry eventually led to retired Marine General James Cartwright, a former vice chairman of the Joint Chiefs, who pleaded guilty in 2016 to lying to investigators about his contacts with reporters. He was later pardoned. The prosecution never disputed that Olympic Games was real; the fight was over who talked about it.

How the weapon got loose

Stuxnet was supposed to stay inside Natanz. It didn't. In 2010 a more aggressive variant began propagating far beyond the plant, spreading across ordinary computers around the world. By Symantec's count it eventually infected more than 100,000 hosts, with about 60 percent of them in Iran. Sanger's sources described the moment officials realised the code had escaped "like a zoo animal that found the way out of the cage," and an anxious meeting in the White House Situation Room over whether to keep going. The escape is what exposed it. In June 2010, a small antivirus company in Belarus called VirusBlokAda, investigating computers in Iran that were mysteriously rebooting, found the LNK exploit. Its researcher Sergey Ulasen is generally credited with the first identification. Within weeks the security world had a name, coined from strings in the code, and had begun pulling the worm apart. A weapon whose entire value depended on being invisible had been dissected in public because it wandered out of the one facility it was meant to stay inside.

What it actually accomplished

Here the record gets genuinely contested, and it is worth resisting the tidy story. The romantic version says Stuxnet crippled Iran's nuclear programme. The sober version is smaller. ISIS estimated it may have destroyed around 1,000 IR-1 centrifuges, roughly 10 percent of what was installed, during late 2009 and early 2010. But the analysts were careful to hedge: they noted that Iran had spare centrifuges, that overall enrichment output dipped but recovered, and that "questions remain" about how much of the damage Stuxnet actually caused versus the IR-1's ordinary unreliability. Iran kept enriching. Within a few years it was running far more centrifuges than before. So the honest assessment is that Stuxnet bought time, perhaps a year or two of delay and disruption, and sowed lasting paranoia, without stopping anything. If the goal was buying room for diplomacy short of a war, that is not nothing. If the goal was ending Iran's programme, it failed. Its real legacy is not measured in broken rotors. Stuxnet proved that software could reach across the air gap and physically destroy critical machinery, and it showed every intelligence agency and defence ministry on Earth exactly how. The techniques it pioneered, from PLC rootkits to falsified sensor feeds, are now part of the standard vocabulary of attacks on power grids, water systems, and pipelines. The tools built to defend against it, and the ones built to imitate it, both trace back to those months under the Iranian desert. The uncomfortable question it leaves open is one of precedent. A state crossed the line from spying to physical sabotage by code, decided the target was worth it, and set loose something it could not fully control. The next time, the machine on the other end of the frequency converter may not be a centrifuge in an adversary's bunker. It may be a turbine, a dam, or a hospital, in a country that never agreed to be a proving ground. What to watch is not whether that capability spreads. It already has. It is whether anyone ever agrees on rules for using it.

Sources

  1. Institute for Science and International Security, Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant?, 2010
  2. Institute for Science and International Security, Stuxnet Malware and Natanz: Update of ISIS December 22, 2010 Report, 2011
  3. Symantec (Broadcom), W32.Stuxnet Dossier, 2011
  4. Ralph Langner / The Langner Group, To Kill a Centrifuge: A Technical Analysis of What Stuxnet's Creators Tried to Achieve, 2013
  5. U.S. Cybersecurity and Infrastructure Security Agency, ICS Advisory ICSA-10-272-01: Primary Stuxnet Advisory, 2010
  6. Wikipedia, Stuxnet, accessed 2026
  7. Wikipedia, Operation Olympic Games, accessed 2026
  8. Foreign Policy, Obama's General Pleads Guilty to Leaking Stuxnet Operation, 2016