{
  "id": "case-olympic-games-stuxnet",
  "slug": "operation-olympic-games-stuxnet",
  "title": "Operation Olympic Games (Stuxnet Industrial SCADA Cyberweapon)",
  "summary": "Joint United States and Israeli covert cyber operation that deployed the Stuxnet computer worm, the first known malware capable of causing physical destruction to industrial hardware. The worm exploited four Windows zero-day vulnerabilities and compromised Siemens Step7 PLC software to spin Natanz nuclear centrifuges out of control.",
  "case_number": "N/A (Covert Operation)",
  "court": "U.S. Federal Executive Attribution",
  "district": "Executive Branch",
  "country": "United States",
  "opened_at": "2010-06-17",
  "status": "uncharged",
  "victim_sector": "Industrial Manufacturing, Critical Infrastructure, Energy",
  "victim_country": "Iran",
  "loss_amount_usd": 1000000000,
  "loss_amount_note": "Physically destroyed approximately 1,000 IR-1 uranium enrichment centrifuges at the Natanz enrichment plant, delaying the Iranian nuclear program by years.",
  "first_seen_at": "2009-11-20T00:00:00Z",
  "last_updated_at": "2026-09-04T12:00:00Z",
  "actor_slug": "tailored-access-operations",
  "defendant_slugs": [],
  "cves": [
    "CVE-2010-2568"
  ],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Stuxnet utilized a Windows zero-day vulnerability in shortcut icon rendering (CVE-2010-2568 LNK vulnerability) allowing automatic binary execution upon viewing a malicious USB drive in Windows Explorer.",
      "evidence_locator": "Symantec Security Response Technical Dossier v1.4, Page 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Symantec Stuxnet Dossier",
      "source_url": "https://www.cisa.gov",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1485",
      "evidence_excerpt": "The worm intercepted Siemens Step7 communications with programmable logic controllers (PLCs), secretly overriding centrifuge rotational frequencies while transmitting recorded normal telemetry back to control room displays.",
      "evidence_locator": "CISA Industrial Control Systems Advisory ICSA-10-272-01",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory ICSA-10-272-01",
      "source_url": "https://www.cisa.gov/news-events/ics-advisories/icsa-10-272-01",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2010-06-17",
      "description": "VirusBlokAda security firm identifies Stuxnet worm propagating in the wild on infected Windows systems."
    },
    {
      "event_type": "advisory",
      "event_date": "2010-09-29",
      "description": "CISA publishes technical advisory on Stuxnet targeting Siemens Simatic Step7 and WinCC industrial control software."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Four zero-day Windows vulnerabilities combined with weaponized Siemens Step7 logic and stolen Realtek and JMicron digital certificates, delivered via infected USB flash drives.",
    "blast_radius": "Physically damaged approximately 1,000 IR-1 uranium enrichment centrifuges at Iran's Natanz enrichment facility, delaying the Iranian nuclear enrichment program by an estimated two years.",
    "kill_chain": [
      {
        "phase": "Air-Gap Ingress",
        "title": "LNK Zero-Day USB Propagation",
        "description": "Operatives deployed Stuxnet via USB thumb drives exploiting a Windows shortcut rendering zero-day (CVE-2010-2568), executing code automatically the moment a user browsed the drive in Windows Explorer.",
        "technical_artifacts": [
          "CVE-2010-2568 (LNK flaw)",
          "USB payload",
          "Stolen Realtek digital certificate"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Industrial Environment Identification",
        "title": "Siemens Simatic WinCC Inspection",
        "description": "The worm verified whether the host was running Siemens Step7 or WinCC software connected to specific frequency converter drives manufactured by Fararo Paya and Vacon.",
        "technical_artifacts": [
          "s7otbxdx.dll hook",
          "WinCC database query"
        ],
        "mitre_technique_id": "T1082"
      },
      {
        "phase": "Physical Sabotage & Sensor Spoofing",
        "title": "Centrifuge Over-Speeding and Sensor Replay",
        "description": "Stuxnet intercepted communications with the Siemens S7-300 PLCs, commanding the centrifuges to spin up to 1,410 Hz (causing physical rotor destruction) while transmitting prerecorded normal sensor readings back to the operators.",
        "technical_artifacts": [
          "PLC block injection (OB35, OB1)",
          "Frequency inverter manipulation"
        ],
        "mitre_technique_id": "T1485"
      }
    ],
    "defensive_takeaways": [
      "Disable USB mass storage access on air-gapped critical infrastructure engineering workstations.",
      "Deploy independent, out-of-band analog vibration and frequency sensors that cannot be overridden by SCADA software.",
      "Enforce cryptographic verification and firmware integrity checks on all Programmable Logic Controllers (PLCs).",
      "Implement physical microsegmentation and strict unidirectional security gateways between IT and OT networks."
    ]
  }
}