{
  "id": 6410238,
  "title": "Researcher reverse-engineers infamous Stuxnet malware source code, publishes it on Github for all — attack targeted Iranian nuclear facilities and was the first software of its type to cause physical damage",
  "url": "https://urgent.news/2026/09/09/researcher-reverse-engineers-infamous-stuxnet-malware-source-code",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-09T10:30:00.000Z",
  "source": {
    "name": "Tom's Hardware",
    "slug": "tom-s-hardware",
    "url": "https://www.tomshardware.com/tech-industry/cyber-security/researcher-reconstructs-infamous-stuxnet-malware-source-code-attack-targeted-iranian-nuclear-facilities-and-was-the-first-software-of-its-type-to-cause-physical-damage"
  },
  "original_language": "en",
  "account": "The infamous Stuxnet malware, responsible for causing physical damage to Iranian nuclear facilities, has been reverse-engineered by a researcher and published on GitHub for all to view. This malicious software targeted Siemens industrial controllers used in Iran's Natanz nuclear enrichment plant. The worm infiltrated these controllers, manipulating frequency converters in industrial centrifuges to discreetly damage the rotors, all while appearing to function normally to plant staff. The source code repository includes build instructions for interested individuals to experiment with Stuxnet and better understand its inner workings. However, to observe the malware's full impact and not just its propagation methods, one must possess Siemens software and ideal hardware, such as industrial centrifuges. Stuxnet primarily spread through USB sticks with Windows shortcuts and autorun.inf files, as well as exploiting a zero-day Windows Print Spooler vulnerability. To bypass Windows driver signature checks, the worm utilized stolen digital certificates from Realtek and JMicron. Additionally, Stuxnet injected itself into Siemens software, embedding its code in Step 7 project files that automatically executed when engineers accessed them. The worm's ultimate goal was to control the DLL responsible for communication with the centrifuges and inject malicious code into Programmable Logic Controllers (PLCs) to covertly alter rotor behavior. Stuxnet was a part of Operation Olympic Games, a joint effort between the U.S. and Israel aimed at curbing Iran's nuclear weapons progress at the Natanz facility.",
  "summary": "An anonymous security researcher has reconstructed the source code of the infamous Stuxnet worm, which was built to subtly interfere with Iranian uranium enrichment during the Bush and Obama administrations.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Hacker News",
        "title": "Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon",
        "url": "https://urgent.news/2026/09/07/show-hn-stuxnet-a-reconstructed-source-code-of-the-infamous-cyber",
        "published": "2026-09-07T22:12:38.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}