Back to the case archive

File 2010/008, Documented event

Stuxnet operation

Natanz, Iran, 2009–2010

Case summary

Discovered in 2010, Stuxnet is the first known cyber-physical weapon, built to physically destroy centrifuges at the Natanz uranium enrichment facility. Using four zero-day exploits, the worm targeted Siemens S7 industrial control systems. The public technical analysis is solid; the attribution to a joint US–Israel operation has never been officially acknowledged.

Timeline

  1. 2009-06Compile timestamps of early variants point to this period.
  2. 2010-01IAEA inspectors logged an abnormal rise in centrifuge replacement at Natanz.
  3. 2010-06-17Belarusian firm VirusBlokAda first reported the malware.
  4. 2010-09Symantec and Langner analyses showed the target was centrifuge frequency converters.
  5. 2012-06-01The New York Times published its investigation describing the 'Olympic Games' programme.

People and connections

  • NatanzPlace

    The uranium enrichment facility that was targeted.

  • Symantec (W32.Stuxnet Dossier)Organisation

    Author of the most comprehensive public technical analysis.

  • Ralph LangnerPerson

    The ICS specialist who decoded the PLC payload's purpose.

  • Siemens S7-315/417Object

    The targeted PLC models; cascade and rotor-speed manipulation.

  • Siemens S7-315/417 to NatanzThe payload triggered only on a specific cascade configuration
  • Ralph Langner to Symantec (W32.Stuxnet Dossier)Independent analyses converged on the same target conclusion

Findings

Every finding lists its source and date. Interpretation stays in the researcher's note.

  • That the malware targeted specific centrifuge cascades at Natanz is verified at code level.

    VerifiedSource: Symantec / Langner2010-11
  • Four zero-days and stolen code-signing certificates were used; this implies state-level resources.

    VerifiedSource: Symantec Dossier2011-02
  • Attribution to a joint US–Israel operation ('Olympic Games') is supported by named-source journalism but never officially confirmed.

    ProbableSource: NYT / Sanger2012-06
  • The count of destroyed centrifuges (≈1,000) is an estimate derived from IAEA data; the exact figure is unknown.

    ProbableSource: Institute for Science and International Security report2010-12

Documents

Sources

  1. W32.Stuxnet Dossier

    Symantec, 2011, Technical analysis report

    Open source
  2. Stuxnet

    Wikipedia, 2026, Encyclopedia entry

    Open source
  3. Obama Order Sped Up Wave of Cyberattacks Against Iran

    The New York Times (David Sanger), 2012, Journalistic investigation

    Open source
  4. To Kill a Centrifuge

    Langner Group, 2013, Technical assessment

    Open source

Locations

  • Natanz enrichment facility33.72°, 51.73°

Researcher's note

Interpretation: two distinct confidence levels are interleaved in the Stuxnet file: what the code did (certainty) versus who commissioned it (journalism plus context). Flattening the two into one sentence is the most common reporting error about this case.

Recent checks

  1. 2026-03-15Symantec report link updated after its move to Broadcom.