Stuxnet
MITRE ATT&CK: S0603 View on attack.mitre.org
Aliases: W32.Stuxnet, Stuxnet
- First seen
- 2008-11-01 00:00:00
- Malware type
- worm, rootkit, exploit-kit
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 3 (2 malicious)
- Last IoC activity
- 2026-09-01 23:56:54
- Profile updated
- 2026-07-07 12:54:10
Targeted industries: energy-and-utilities manufacturing government-and-public-sector
Targeted regions: country_code:ir country_code:us country_code:ru country_code:il
Context
Stuxnet was the first publicly reported malware to specifically target industrial control systems devices. Stuxnet is a large and complex malware that utilized multiple behaviors, including numerous zero-day vulnerabilities, a sophisticated Windows rootkit, and network infection routines. Stuxnet was discovered in 2010, with some components being used as early as November 2008.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Stuxnet (S0603). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 002325.dll | 2026-04-05 | 1 |
| file sample | tmphe739j52 | 2026-03-31 | 1 |
Detection coverage
- 1 YARA rules
- 678 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- Archive via Custom Method (attack-pattern)
- Timestomp (attack-pattern)
- Shared Modules (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Modify Registry (attack-pattern)
- Windows Service (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- File Deletion (attack-pattern)
- Token Impersonation/Theft (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Execution Guardrails (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Indicator Removal (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Rootkit (attack-pattern)
- Web Protocols (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Fallback Channels (attack-pattern)
- Domain Account (attack-pattern)
Detection rules
- MALPEDIA_Win_Stuxnet_Auto (yara-rule)
Reports & references
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- Broadcom/Symantec — Attacks Against Critical Infrastructrure (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- crysys.hu — Ukatemicrysys Territorialdispute (report)
- ESET — Eset Jumping The Air Gap Wp (report)
- web.archive.org — 202304114E0Fa0F4Fd1D408Aaddeef8Be63A4757 20230411161526 0531 (report)
- media.kasperskycontenthub.com — Bartholomew Guerrerosaade Vb2016 (report)
- atlanticcouncil.org — Breaking Trust Shades Of Crisis Across An Insecure Software Supply Chain (report)
- fmmresearch.files.wordpress.com — Theemeraldconnectionreport Fmmr 2 (report)
- fmmresearch.wordpress.com — The Emerald Connection Equationgroup Collaboration With Stuxnet (report)
- storage.googleapis.com — Stuxshop%20Stuxnet%20Dials%20In%20 (report)
- domaintools.com — Visibility Monitoring And Critical Infrastructure Security (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Stuxnet (report)
- spiegel.de — Die Erste Cyberwaffe Und Ihre Folgen A A0Ed08C9 5080 4Ac2 8518 Ed69347Dc147 (report)
- medium.com — W3 May En Story Of The Week Code Signing Certificate On The Darkweb 94C7Ec437001 (report)
- news.yahoo.com — Revealed How A Secret Dutch Mole Aided The Us Israeli Stuxnet Cyber Attack On Iran 160026018 (report)
- codeproject.com — Stuxnet Malware Analysis Paper (report)
- media.ccc.de — 27C3 4245 En Adventures In Analyzing Stuxnet (report)
- ESET — Stuxnet Under The Microscope (report)
- artemonsecurity.blogspot.de — Stuxnet Drivers Detailed Analysis (report)
- MITRE ATT&CK — S0603 (report)
- Broadcom/Symantec — Security Response W32 Stuxnet Dossier 11 En (report)
- CISA — Icsa 10 272 01 (report)
- web-assets.esetstatic.com — Stuxnet Under The Microscope (report)
- langner.com — To Kill A Centrifuge (report)
External references
- mitre-attack — S0603
- W32.Stuxnet
- CISA ICS Advisory ICSA-10-272-01
- ESET Stuxnet Under the Microscope
- Nicolas Falliere, Liam O Murchu, Eric Chien February 2011
- Langer Stuxnet
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy