Site navigation

Next Gen Stuxnet Worm Reportedly Attacked Iran

Duncan MacRae

,

worms

Iranian officials claim that the country has been targeted by an upgraded version of the worm used to infect one of its nuclear power plants in 2010.

A more aggressive and sophisticated variant of Stuxnet has allegedly hit Iranian Government networks, officials have claimed.

Iranian General Gholam Reza Jalali said: “Recently we discovered a new generation of Stuxnet, which consisted of several parts…and was trying to enter our systems,” adding that Iran had managed to neutralise the threat.

Israeli news agency Hadashot stated that Iran “has admitted in the past few days that it is again facing a similar attack, from a more violent, more advanced and more sophisticated virus than before, that has hit infrastructure and strategic networks“.

Confronting infiltration

In a televised speech this week, Iranian Supreme Leader Ayatollah Ali Khamenei, said Iran’s “civil defences should confront infiltration through scientific, accurate, and up-to-date action,” although he made no reference to any specific attack.

The original Stuxnet worm, thought to be a joint US-Israel project, was first detected in June 2010.

It was used to infect Iran’s Natanz nuclear facility, having been introduced to its systems via a worker’s USB, and further spread around the globe when a Natanz employee took his laptop home and connected it to the internet.

Although it reportedly destroyed a fifth of Iran’s nuclear centrifuges by causing them to spin out of control, it is not known for certain why it was created. It is suspected that the actual purpose of the worm was to draw the equivalent of an electrical blueprint of the nuclear power plant in order to understand how the computers control the centrifuges used to enrich uranium.

Whether deliberate or due to a mistake in the worm’s coding, Stuxnet subsequently increased the pressure on spinning centrifuges while showing the control room that everything appeared normal by replaying recordings of the plant’s protection system values during the attack.

It has also been theorised that Stuxnet was designed to reduce the lifespan of Iran’s centrifuges and suggest to the world that the state-of-the art Natanz control systems were beyond the plant workers’ understanding.

The original Stuxnet used four zero-day exploits, and was used as a basis for creating other malware strains utilised by cybercriminals in the past eight years.

Broderick Perelli-Harris, senior director of professional services at security specialist Venafi, said: “Now, more than 22 million pieces of malware use that blueprint to attack organisations and states alike across the world.

“It’s easy for organisations and governments to ignore when it’s used against an adversarial state, but the blueprint remains ‘in the wild’ for cybercriminals to exploit. The new Stuxnet reminds us that governments need to think very carefully when they are creating cyber-arms, so that they do not escalate the problem. Cyber weapons are much more prone to proliferation and almost impossible to control. It’s naïve to think we can.”

Duncan MacRae

Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data