Stuxnet

S0603

Malware.View on attack.mitre.org

About this malware

Stuxnet was the first publicly reported malware to specifically target industrial control systems devices. Stuxnet is a large and complex malware that utilized multiple behaviors, including numerous zero-day vulnerabilities, a sophisticated Windows rootkit, and network infection routines. Stuxnet was discovered in 2010, with some components being used as early as November 2008.

Techniques used44

Procedure examples44

TechniqueProcedure example
T1008
Fallback Channels

Stuxnet has the ability to generate new C2 domains.

T1012
Query Registry

Stuxnet searches the Registry for indicators of security programs.

T1014
Rootkit

Stuxnet uses a Windows rootkit to mask its binaries and other relevant files.

T1016
System Network Configuration Discovery

Stuxnet collects the IP address of a compromised system.

T1021
Remote Services

Stuxnet can propagate via peer-to-peer communication and updates using RPC.

T1021.002
SMB/Windows Admin Shares

Stuxnet propagates to available network shares.

T1027.013
Encrypted/Encoded File

Stuxnet uses encrypted configuration blocks and writes encrypted files to disk.

T1041
Exfiltration Over C2 Channel

Stuxnet sends compromised victim information via HTTP.

T1047
Windows Management Instrumentation

Stuxnet used WMI with an explorer.exe token to execute on a remote share.

T1053.005
Scheduled Task

Stuxnet schedules a network job to execute two minutes after host infection.

T1055.001
Dynamic-link Library Injection

Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.

T1068
Exploitation for Privilege Escalation

Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines.

T1070
Indicator Removal

Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads.

T1070.004
File Deletion

Stuxnet uses an RPC server that contains a routine for file deletion and also removes itself from the system through a DLL export by deleting specific files.

T1070.006
Timestomp

Stuxnet extracts and writes driver files that match the times of other legitimate files.

View all 44 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References4

  1. CISA ICS Advisory ICSA-10-272-01 Open source
    CISA. (2010, September 10). ICS Advisory (ICSA-10-272-01). Retrieved December 7, 2020.
  2. ESET Stuxnet Under the Microscope Open source
    Matrosov, A., Rodionov, E., Harley, D., Malcho, J.. (n.d.). Stuxnet Under the Microscope. Retrieved December 7, 2020.
  3. Langer Stuxnet Open source
    Ralph Langner. (2013, November). To Kill a Centrifuge: A Technical Analysis of What Stuxnet's Creators Tried to Achieve. Retrieved December 7, 2020.
  4. Nicolas Falliere, Liam O Murchu, Eric Chien February 2011 Open source
    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.