Categorized | Antivirus

New info on Stuxnet

scada

Stuxnet continues to make headlines. The New York Times published a long story on the latest findings, including these:

President George Bush started an experimental cyber attack program against Iran already in 2008

NY Times claims that Stuxnet was developed jointly by USA and Isreal. They offer no direct proof though.

Israel has built a replica of the Iranian Natanz enrichment facility in their Negev Nuclear Research Center in Dimona. It was used to test drive Stuxnet before it was deployed.

dimona israel negev

Embassy cables leaked by Wikileaks seem to prove that the Iran nuclear program was indeed using Siemens PLC gear.

cable stuxnet

NY Times claims that Idaho National Laboratory at Idaho Falls used their security testing of the Siemens PLC systems to find vulnerabilities to be used in the Stuxnet attack. Apparently Siemens thought this testing was done in order to secure industrial systems. In any case, it is easy to confirm that Siemens and INL did joint security testing in 2008, see this slide:

stuxnet inl
Image copyright Idaho National Laboratory & Siemens

The target of the attack was to modify the operation of high-frequency power drives made by Vacon and Fararo Paya. These drives were controlling the centrifuges that were enriching uranium.

vacon drives

Stuxnet specifically targets a grid of 984 converters

Curiously, when international inspectors visited Natanz encrichment facility in late 2009, they found that the Iranians had taken out of service a total of exactly 984 machines.

Siemens S7-400 PLC

While Stuxnet is doing malicious modifications to the system, it uses a man-in-the-middle attack to fool the operators into thinking everything is normal.

Iranian president Mahmoud Ahmadinejad confirmed in November 2010 that a cyber attack had indeed caused problems with their centrifuges.

centrifuges

Another leaked embassy cable would indicate that there would other, unknown encrichment plants in addition of Natanz. Attacking such unknown targets with cyber sabotage makes much more sense than, say, trying to bomb them. A worm will find even the facilities that you do not know about.

cable stuxnet

There is a real fear that we will eventually see modified copies of Stuxnet.

While modifying Stuxnet is obviously not easy, it is easier than creating the same functionality from scratch.

Finding a copy of Stuxnet is not hard at all as you can see from this forum posting we found:

finding stuxnet

For further background info, see our Stuxnet Q&A and Ralph Langner’s thorough article on Stuxnet for the Control Global magazine

Or, watch our new Stuxnet video which we just published.

On 17/01/11 At 12:13 PM

Full story: F-Secure Antivirus Research Weblog

Related Posts
  • Stars virus: Iran claims to intercept second cyberwarfare attack
    Iranian officials today claimed to have intercepted a cyberwarfare attack, involving malware designed to spy upon government systems. The malware has been dubbed the "Stars" virus by Gholamreza Jalali...
  • Stuxnet, once again
    Stuxnet - the most important malware we've seen in ages - has some interesting features when you look at it from a forensic viewpoint. For example, whenever it infects a new system, it records...
  • From Brain to Stuxnet: 25 Years of Computer Viruses
    We've just published a video going through the last 25 years of PC malware history in 9 minutes.The video contains several demos of what old viruses used to look like.Check it out here. On...
  • Comment on Stuxnet and more Windows 0-days
    Hi folks, Over the last few days, some news organizations have been saying that Stuxnet source code is available on the black market, and that clearly therefor there is an impending Internet armagedd...
  • Another Stuxnet Resources Update
    [Update: The Reuters article flagged on 6th February 2011 refers to a statement by the Russian ambassador to NATO claiming that Stuxnet could have caused "another Chernobyl": more info at...
  • Iran says Stuxnet claims need investigating (Reuters)
    Reuters - Iran should investigate claims that the Stuxnet computer virus has caused major harm to its first nuclear power station, a senior official said Friday after suggestions the plant could becom...
  • Added to Stuxnet resources page…
    …an article by William Gibson (yes, that William Gibson) draws a connection between Brain (a 25-year-old PC virus) and Stuxnet. 25 Years of Digital Vandalism. He doesn't seem to think much ...
  • Important preliminary info on Anti-Malware 5.0: Name change
    Important preliminary information on Anti-Malware 5.0: Name change Emsisoft Anti-Malware - New Freeware mode - a-squared Free becomes the Emsisoft Emergency Kit Full story: a-squared - English...
  • Stuxnet Information and Resources (2)
    [Update 23rd January 2011: volume 3 of this resource has just kicked off at http://blog.eset.com/?p=5945: volume 1 is at http://blog.eset.com/?p=5731.] @imaguid microblogged today about his annoyance...
  • Stuxnet Information and Resources (3)
    This is the 3rd volume of an ongoing Stuxnet resources blog article, supplementing our paper "Stuxnet Under the Microscope". Volume 1 is at http://blog.eset.com/?p=5731, and volume 2 is ...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago