Stuxnet is a highly sophisticated Windows worm developed for targeted sabotage of industrial control systems, most notably Siemens environments associated with Iran’s Natanz nuclear enrichment facility. It is widely regarded as a landmark cyber-physical weapon because it combined propagation, stealth, Windows privilege and execution tradecraft, and specialized industrial manipulation in a single operation.
Stuxnet spread in Windows environments and is known to have leveraged the Windows Shell shortcut vulnerability CVE-2010-2568. It also abused Windows mechanisms for persistence and execution, including creation of registry entries to load driver components and scheduling of network jobs shortly after infection. The malware performed extensive host and network discovery, including collecting system IP address and time information, enumerating network resources and shares, and identifying running processes associated with security products. It also reduced object integrity levels through Windows API usage to facilitate execution and evasion.
A notable feature of Stuxnet was its use of process injection, including injecting a DLL into trusted processes, as well as decrypting embedded resources in memory for execution. It communicated with command-and-control infrastructure over HTTP, sending encoded victim information and using simple XOR-based obfuscation for outbound data. It also supported resilient communications through generation of new command-and-control domains. In addition, it contained functionality for file deletion through an RPC server routine.
Stuxnet’s significance lies not only in its technical sophistication as a self-propagating malware platform, but also in its role as a precedent-setting offensive cyber operation against operational technology and industrial processes. Its discovery reshaped global understanding of the risks posed by malware capable of bridging conventional Windows compromise and industrial sabotage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems... https://www.geoffchappell.com/notes/security/stuxnet/ctrlfldr.htm
...as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems... https://www.geoffchappell.com/notes/security/stuxnet/ctrlfldr.htm
Stuxnet ... CVE-2010-2743 (Keyboard layout EoP) | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Stuxnet ... CVE-2008-4250 (RPC RCE) | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Stuxnet ... CVE-2010-3338 (Task Scheduler EoP) | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Infected Siemens Simatic Step7 project files using exploit for vulnerability CVE-2012-3015. | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Stuxnet ... CVE-2006-3439 (RPC RCE) | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
Stuxnet was well known for its use of CVE-2010-2729, the Windows Print Spooler RCE exploit. Flame used it as well. | Stuxnet ... was made for a sabotage operation of Iran’s nuclear program ... Even Stuxnet, best known for its sabotage capabilities, collected information about Siemens Simatic Step 7 engineering software projects found in compromised machines.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ultimately, it turned out that the fortuitous discoveries of Stuxnet, Duqu, and Flame were in fact related beyond superficial succession.
The tranquil days of reverse engineering banking trojans were pierced by Stuxnet, Duqu, Flame, Gauss, and MiniFlame.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
Trojan spreads via new Windows hole ... Malware Targets Shortcut Flaw in Windows SCADA ... PoC Exploit Code Available for Windows LNK Vulnerability | The Aurora and Stuxnet attacks used 0-day exploits to install malicious programs onto the system... Stuxnet: MS10-046 (0-day), MS10-061 (0-day), MS10-073 (0-day), MS10-092 (0-day), CVE-2010-2772 (0-day), MS08-067 (patched).
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Propagation to network shares using scheduled jobs and Windows Management Instrumentation.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
When the Win32/Stuxnet worm didn’t have enough privileges to install itself in the system it exploited a recently patched (MS10-73) 0-day vulnerability in the win32k.sys system module to escalate privilege level up to SYSTEM... Yet another vulnerability that Stuxnet exploits in order to elevate privileges concerns the Task Scheduler Service...
The Stuxnet attack constituted a serious threat to trust in software using legal digital signatures... even has digital certificates for installed modules published in the name of reputable companies.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
IoCs include services such as mrxcls service, WinMI32 service, HP003044 service, NetBIOS2010 service, pnppci service, ethio service, ntdos505 service.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
Stuxnet ... was a worm that spread over USB using the 0-day .LNK vulnerability
http://www.microsoft.com/technet/security/bulletin/ms10-061.mspx; ... ms10-061-printer-spooler-vulnerability.aspx | Another way in which the worm replicates itself over the network exploits a vulnerability in Window Spooler (MS10-061)... The worm is also capable of distributing itself over the network through shared folders... Stuxnet’s exploitation of the MS08-67 vulnerability to propagate itself through the network...
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A highly targeted cyber weapon referenced as an example of offensive tooling escaping intended bounds and proliferating techniques.
Referenced as a historical example demonstrating the risks of USB-borne attacks and removable media exploitation.
A worm referenced as a historical example of malware used to target operational technology and PLCs in Iran’s nuclear program.
A destructive worm referenced as having been used to damage systems involved in Iran's nuclear program.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.