Security/ stuxnet · malware · industrial-control-systems · cybersecurity

Stuxnet's Source Code Gets Reverse Engineered, Posted on GitHub

A researcher rebuilt the code behind the malware that sabotaged Iran's nuclear centrifuges and published it on GitHub for anyone to study.

Someone reverse-engineered Stuxnet, the malware that quietly wrecked Iranian nuclear centrifuges more than a decade ago, and published working source code on GitHub.

An anonymous researcher rebuilt Stuxnet's code from scratch and posted it publicly, complete with build instructions. Running it requires a Windows XP or Windows 7 virtual machine, kept off any network, and reproducing the full destructive payload needs the same Siemens industrial software the original targeted. Stuxnet spread three ways: USB drives exploiting a Windows shortcut zero-day, a Print Spooler zero-day for network propagation, and infected Siemens Step 7 project files passed between engineers. It also used stolen digital certificates from Realtek and JMicron to slip past driver signature checks before hijacking the DLL that talked to programmable logic controllers and subtly damaged centrifuge rotors.

Stuxnet was reportedly built by the Pentagon and Israel's Unit 8200 as part of Operation Olympic Games, and it's credited with destroying about 10% of the centrifuges at Iran's Natanz enrichment plant while telling operators everything was fine. That a piece of state-built cyberweapon code engineered to bridge software and physical sabotage is now a public GitHub repo says something about how thoroughly the secret got out over the years, and how little appetite there is left for keeping it locked away.

The original worm escaped into the wild because it couldn't tell when it had left its target network; this rebuilt version comes with the safety instructions the real one never had.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →