Back to the archive

Stuxnet operation

Natanz, Iran, 2009–2010

Case summary

Discovered in 2010, Stuxnet is the first known cyber-physical weapon, built to physically destroy centrifuges at the Natanz uranium enrichment facility. Using four zero-day exploits, the worm targeted Siemens S7 industrial control systems. The public technical analysis is solid; the attribution to a joint US–Israel operation has never been officially acknowledged.

Timeline

  1. 2009-06Compile timestamps of early variants point to this period.
  2. 2010-01IAEA inspectors logged an abnormal rise in centrifuge replacement at Natanz.
  3. 2010-06-17Belarusian firm VirusBlokAda first reported the malware.
  4. 2010-09Symantec and Langner analyses showed the target was centrifuge frequency converters.
  5. 2012-06-01The New York Times published its investigation describing the 'Olympic Games' programme.

People and connections

  • Natanz

    The uranium enrichment facility that was targeted.

  • Symantec (W32.Stuxnet Dossier)

    Author of a detailed public technical analysis.

  • Ralph Langner

    The ICS specialist who decoded the PLC payload's purpose.

  • Siemens S7-315/417

    The targeted PLC models; cascade and rotor-speed manipulation.

  • Siemens S7-315/417 to NatanzThe payload triggered only on a specific cascade configuration
  • Ralph Langner to Symantec (W32.Stuxnet Dossier)Independent analyses converged on the same target conclusion

Findings

  • That the malware targeted specific centrifuge cascades at Natanz is verified at code level.

    Assessment: VerifiedSource: Symantec / Langner2010-11
  • Four zero-days and stolen code-signing certificates were used; this implies state-level resources.

    Assessment: VerifiedSource: Symantec Dossier2011-02
  • Attribution to a joint US–Israel operation ('Olympic Games') is supported by named-source journalism but never officially confirmed.

    Assessment: ProbableSource: NYT / Sanger2012-06
  • The count of destroyed centrifuges (≈1,000) is an estimate derived from IAEA data; the exact figure is unknown.

    Assessment: ProbableSource: Institute for Science and International Security report2010-12

Documents

Sources

  1. W32.Stuxnet Dossier

    Symantec, 2011, Technical analysis report

    Open
  2. Stuxnet

    Wikipedia, 2026, Encyclopedia entry

    Open
  3. Obama Order Sped Up Wave of Cyberattacks Against Iran

    The New York Times (David Sanger), 2012, Journalistic investigation

    Open
  4. To Kill a Centrifuge

    Langner Group, 2013, Technical assessment

    Open

Locations

  • Natanz enrichment facility33.72°, 51.73°

Researcher's note

Interpretation: two distinct confidence levels are interleaved in the Stuxnet file: what the code did (certainty) versus who commissioned it (journalism plus context). Flattening the two into one sentence is the most common reporting error about this case.

Recent checks

  1. 2026-03-15Symantec report link updated after its move to Broadcom.