Stuxnet

MITRE ATT&CK: S0603 View on attack.mitre.org

Aliases: W32.Stuxnet, Stuxnet

First seen
2008-11-01 00:00:00
Malware type
worm, rootkit, exploit-kit
Family
Malware family
Operating systems
windows
Related IoCs
3 (2 malicious)
Last IoC activity
2026-09-01 23:56:54
Profile updated
2026-07-07 12:54:10

Targeted industries: energy-and-utilities manufacturing government-and-public-sector

Targeted regions: country_code:ir country_code:us country_code:ru country_code:il

Context

Stuxnet was the first publicly reported malware to specifically target industrial control systems devices. Stuxnet is a large and complex malware that utilized multiple behaviors, including numerous zero-day vulnerabilities, a sophisticated Windows rootkit, and network infection routines. Stuxnet was discovered in 2010, with some components being used as early as November 2008.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to Stuxnet (S0603). The 2 most recently updated:

TypeIndicatorUpdatedSources
file sample 002325.dll 2026-04-05 1
file sample tmphe739j52 2026-03-31 1

Detection coverage

  • 1 YARA rules
  • 678 Sigma rules

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • Timestomp (attack-pattern)
  • Shared Modules (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Modify Registry (attack-pattern)
  • Windows Service (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • File Deletion (attack-pattern)
  • Token Impersonation/Theft (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Rootkit (attack-pattern)
  • Web Protocols (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Domain Account (attack-pattern)

Detection rules

  • MALPEDIA_Win_Stuxnet_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Broadcom/Symantec — Attacks Against Critical Infrastructrure (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • crysys.hu — Ukatemicrysys Territorialdispute (report)
  • ESET — Eset Jumping The Air Gap Wp (report)
  • web.archive.org — 202304114E0Fa0F4Fd1D408Aaddeef8Be63A4757 20230411161526 0531 (report)
  • media.kasperskycontenthub.com — Bartholomew Guerrerosaade Vb2016 (report)
  • atlanticcouncil.org — Breaking Trust Shades Of Crisis Across An Insecure Software Supply Chain (report)
  • fmmresearch.files.wordpress.com — Theemeraldconnectionreport Fmmr 2 (report)
  • fmmresearch.wordpress.com — The Emerald Connection Equationgroup Collaboration With Stuxnet (report)
  • storage.googleapis.com — Stuxshop%20Stuxnet%20Dials%20In%20 (report)
  • domaintools.com — Visibility Monitoring And Critical Infrastructure Security (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Stuxnet (report)
  • spiegel.de — Die Erste Cyberwaffe Und Ihre Folgen A A0Ed08C9 5080 4Ac2 8518 Ed69347Dc147 (report)
  • medium.com — W3 May En Story Of The Week Code Signing Certificate On The Darkweb 94C7Ec437001 (report)
  • news.yahoo.com — Revealed How A Secret Dutch Mole Aided The Us Israeli Stuxnet Cyber Attack On Iran 160026018 (report)
  • codeproject.com — Stuxnet Malware Analysis Paper (report)
  • media.ccc.de — 27C3 4245 En Adventures In Analyzing Stuxnet (report)
  • ESET — Stuxnet Under The Microscope (report)
  • artemonsecurity.blogspot.de — Stuxnet Drivers Detailed Analysis (report)
  • MITRE ATT&CK — S0603 (report)
  • Broadcom/Symantec — Security Response W32 Stuxnet Dossier 11 En (report)
  • CISA — Icsa 10 272 01 (report)
  • web-assets.esetstatic.com — Stuxnet Under The Microscope (report)
  • langner.com — To Kill A Centrifuge (report)

External references