Thursday, February 17, 2011

Stuxnet Iran Attack Launched From 10 Machines

Symantec Researchers Analyzed The Worm's Timestamps and Found That The 12,000 Infections Identified To Date Originated From A Handful Of Machines.

By Mathew J. Schwartz ,
February 14, 2011 01:23 PM
Courtesy Of "Information Week"

All Stuxnet worm attacks -- which targeted five facilities in Iran -- were launched by infecting a total of just 10 machines. In other words, all 12,000 Stuxnet infections spotted to date can be traced back to these 10 infections, which likely began on machines that weren't connected to the Internet.


 That's the surprise finding from a new Symantec report on Stuxnet, released Friday.

Stuxnet was designed to sabotage the high-frequency convertor drives used in five uranium enrichment facilities in Iran. The malware adjusts the automated control system's user interface to make it appear that the drives are running normally. But in reality, the malware is quickly adjusting the speed of the drives to very high and low frequencies. As a result, not only does the uranium not get enriched, but the drive motors are permanently damaged.


In November, Symantec's researchers discovered that Stuxnet records a timestamp every time it infects a new machine. "However, at the time, this information was largely useless as we did not have enough samples to draw any meaningful conclusions," they said in a blog post.

Since then, however, numerous antivirus firms have been feeding the researchers every Stuxnet variant they capture, enabling them to amass a collection of 3,280 unique samples, which would have generated about 12,000 infections. And they found that every infection could be traced back to just one of 10 machines.

That finding suggests that someone with physical access to the nuclear enrichment control systems may have directly infected the 10 machines. Interestingly, in June 2009, and again in April 2010, the same PC appears to have been infected with different versions of Stuxnet.

Symantec said the last Stuxnet attack appeared to have been launched in May 2010, while the earliest known attack dates from June 2009.

Iran began containing Stuxnet in August 2010. "Looking at newly infected IP addresses per day, on August 22 we observed that Iran was no longer reporting new infections," said Symantec's researchers. "This was most likely due to Iran blocking outward connections to the command and control servers, rather than a drop-off in infections."

But Iran's response came too late. According to news reports, the Stuxnet attacks appear to have been successful.


Cutting-edge attacks like Stuxnet and Zeus will be the everyday exploits of the future. Here's what you need to know. That and more--including five best practices to improve the budgeting process for security spending--in the debut all-digital issue of Dark Reading. Download the issue now (free registration required).

No comments:

Post a Comment