CASE DOSSIER uncharged

Operation Olympic Games (Stuxnet Industrial SCADA Cyberweapon)

Docket: N/A (Covert Operation) Court: U.S. Federal Executive Attribution Opened: 2010-06-17 Sector: Industrial Manufacturing, Critical Infrastructure, Energy

Key Facts

Status
UNCHARGED
Legal disposition
Loss Amount
$1.0 billion
Physically destroyed approximately 1,000 IR-1 uranium enrichment centrifuges at the Natanz enrichment plant, delaying the Iranian nuclear program by years.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: UNCHARGED in U.S. Federal Executive Attribution.
  • Primary Target Sector: Industrial Manufacturing, Critical Infrastructure, Energy.
  • Documented Financial Loss: $1.0 billion.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Joint United States and Israeli covert cyber operation that deployed the Stuxnet computer worm, the first known malware capable of causing physical destruction to industrial hardware. The worm exploited four Windows zero-day vulnerabilities and compromised Siemens Step7 PLC software to spin Natanz nuclear centrifuges out of control.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Four zero-day Windows vulnerabilities combined with weaponized Siemens Step7 logic and stolen Realtek and JMicron digital certificates, delivered via infected USB flash drives.

Operational & Financial Fallout

Physically damaged approximately 1,000 IR-1 uranium enrichment centrifuges at Iran's Natanz enrichment facility, delaying the Iranian nuclear enrichment program by an estimated two years.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: UNCHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Four zero-day Windows vulnerabilities combined with weaponized Siemens Step7 logic and stolen Realtek and JMicron digital certificates, delivered via infected USB flash drives.

Adversary Kill Chain Flow

3 Documented Phases
1
Air-Gap Ingress LNK Zero-Day USB Propagation
MITRE ATT&CK T1190 →

Operatives deployed Stuxnet via USB thumb drives exploiting a Windows shortcut rendering zero-day (CVE-2010-2568), executing code automatically the moment a user browsed the drive in Windows Explorer.

Artifacts & Tooling: CVE-2010-2568 (LNK flaw) USB payload Stolen Realtek digital certificate
2
Industrial Environment Identification Siemens Simatic WinCC Inspection
MITRE ATT&CK T1082 →

The worm verified whether the host was running Siemens Step7 or WinCC software connected to specific frequency converter drives manufactured by Fararo Paya and Vacon.

Artifacts & Tooling: s7otbxdx.dll hook WinCC database query
3
Physical Sabotage & Sensor Spoofing Centrifuge Over-Speeding and Sensor Replay
MITRE ATT&CK T1485 →

Stuxnet intercepted communications with the Siemens S7-300 PLCs, commanding the centrifuges to spin up to 1,410 Hz (causing physical rotor destruction) while transmitting prerecorded normal sensor readings back to the operators.

Artifacts & Tooling: PLC block injection (OB35, OB1) Frequency inverter manipulation
Real-World Blast Radius & Operational Fallout

Physically damaged approximately 1,000 IR-1 uranium enrichment centrifuges at Iran's Natanz enrichment facility, delaying the Iranian nuclear enrichment program by an estimated two years.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Disable USB mass storage access on air-gapped critical infrastructure engineering workstations.
✓ Deploy independent, out-of-band analog vibration and frequency sensors that cannot be overridden by SCADA software.
✓ Enforce cryptographic verification and firmware integrity checks on all Programmable Logic Controllers (PLCs).
✓ Implement physical microsegmentation and strict unidirectional security gateways between IT and OT networks.

Procedural & Incident Timeline

2010-06-17 incident

VirusBlokAda security firm identifies Stuxnet worm propagating in the wild on infected Windows systems.

2010-09-29 advisory

CISA publishes technical advisory on Stuxnet targeting Siemens Simatic Step7 and WinCC industrial control software.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Stuxnet utilized a Windows zero-day vulnerability in shortcut icon rendering (CVE-2010-2568 LNK vulnerability) allowing automatic binary execution upon viewing a malicious USB drive in Windows Explorer." Symantec Security Response Technical Dossier v1.4, Page 14 reviewed
T1485 Data Destruction
Impact
"The worm intercepted Siemens Step7 communications with programmable logic controllers (PLCs), secretly overriding centrifuge rotational frequencies while transmitting recorded normal telemetry back to control room displays." CISA Industrial Control Systems Advisory ICSA-10-272-01 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Operation Olympic Games (Stuxnet Industrial SCADA Cyberweapon), No. N/A (Covert Operation) (U.S. Federal Executive Attribution 2010), https://cybercaselibrary.com/cases/operation-olympic-games-stuxnet/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/operation-olympic-games-stuxnet" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>