{
  "id": "case-stuxnet",
  "slug": "stuxnet-natanz-centrifuges",
  "title": "Operation Olympic Games (Stuxnet Natanz Centrifuge Sabotage)",
  "summary": "Historic joint U.S. and Israeli cyber warfare campaign deploying the Stuxnet computer worm to physically sabotage Iranian nuclear enrichment facilities at Natanz, manipulating Siemens S7-300 PLCs and variable-frequency drives to over-spin IR-1 centrifuges to destruction while playing normal sensor telemetry to operators.",
  "case_number": "Operation-Olympic-Games-01",
  "court": "International Atomic Energy Agency (IAEA) Technical Reports",
  "district": "Global / Natanz FEP",
  "country": "Iran / International",
  "opened_at": "2010-06-17",
  "status": "uncharged",
  "victim_sector": "Nuclear Energy & Industrial Control Systems",
  "victim_country": "Iran",
  "loss_amount_usd": 1000000000,
  "loss_amount_note": "Physical destruction of roughly 1,000 uranium centrifuges and multi-year setback to Iranian nuclear enrichment program.",
  "first_seen_at": "2009-06-01T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "equation-group",
  "defendant_slugs": [],
  "cves": [
    "CVE-2010-2568",
    "CVE-2010-2729",
    "CVE-2010-2772",
    "CVE-2010-3888"
  ],
  "techniques": [
    {
      "technique_id": "T1091",
      "evidence_excerpt": "Stuxnet crossed air-gapped industrial control boundaries via infected USB removable storage devices exploiting Windows LNK shortcut vulnerability CVE-2010-2568.",
      "evidence_locator": "Symantec Security Response Stuxnet Dossier v1.4, Page 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Symantec Comprehensive Stuxnet Analysis",
      "source_url": "https://www.symantec.com"
    },
    {
      "technique_id": "T0831",
      "evidence_excerpt": "Injected malicious ladder logic into Siemens Simatic Step 7 software to alter frequency converter drive speeds to 1,410 Hz before dropping to 2 Hz, inducing rotor resonance vibration failure.",
      "evidence_locator": "IAEA Board of Governors Verification Report GOV/2010/62",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "IAEA Inspection Report on Natanz",
      "source_url": "https://www.iaea.org"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2009-11-15",
      "description": "Centrifuge destruction escalates as Stuxnet modifies PLC drive control routines."
    },
    {
      "event_type": "discovery",
      "event_date": "2010-06-17",
      "description": "VirusBlokAda identifies malware spreading via LNK zero-day, dubbed Stuxnet."
    },
    {
      "event_type": "disclosure",
      "event_date": "2010-11-23",
      "description": "Iranian officials publicly acknowledge centrifuge equipment disruptions."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2010-2568, CVE-2010-2729, CVE-2010-2772, CVE-2010-3888) combined with targeted spearphishing and stolen remote access credentials.",
    "blast_radius": "Physical destruction of roughly 1,000 uranium centrifuges and multi-year setback to Iranian nuclear enrichment program. Impacted Nuclear Energy & Industrial Control Systems infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the Nuclear Energy & Industrial Control Systems sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "Historic joint U.S. and Israeli cyber warfare campaign deploying the Stuxnet computer worm to physically sabotage Iranian nuclear enrichment facilities at Natanz, manipulating Siemens S7-300 PLCs and variable-frequency drives to over-spin IR-1 centrifuges to destruction while playing normal sensor telemetry to operators.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}