Categories: Cyber warfareMalware

Stuxnet infected the network of Russian nuclear facility

Eugene Kaspersky revealed that a staffer at the unnamed nuclear Russian plant informed him of the infection of internal network with Stuxnet.

We have a lot of information on Stuxnet virus, a powerful malware that for the first time has shown to governments the capabilities and efficiency of a cyber weapon.  After its disclosure it’s risen the debate on the use of software and malicious application in Information warfare, every government is investing to improve its cyber capabilities working on both Defense and Offense sides.

The malware Stuxnet is widely considered to have been developed by the US Government in a joint work with Israel cyber units as a means to disrupt Iran’s nuclear enrichment plans.

When we discuss on Stuxnet, and more in general on the risks related to the uncontrolled diffusion of malicious agents in the cyberspace, we mentioned the possibility that a hostile entity, such as foreign government or a cyber criminal gang, could reverse engineer their source code to create more dangerous malware.

If the news is confirmed the news is very concerning, Stuxnet had infected the internal network of a Russian nuclear plant, exactly in the same way it compromised the control system in Iranian nuclear facilities in Natanz.

Eugene Kaspersky, CEO of Kasperky security firm revealed that a staffer at the unnamed nuclear Russian plant informed him of the infection.

“[The staffer said] their nuclear plant network which was disconnected from the internet … was badly infected by Stuxnet,”

“So unfortunately these people who were responsible for offensive technologies, they recognise cyber weapons as an opportunity.” Kaspersky said.

Stuxnet, also in this case, infected the network within a Russian nuclear plant isolated from the Internet, to spread the malware attackers used as attack vector a USB device. Russian Intelligence agencies in the past have already observed this infection mode to cross a physically separated ‘air-gapped’ network, Russian astronauts for example had carried a virus on removable media to the International Space Station infecting machines there, according to Kaspersky.

During a presentation given at the Canberra Press Club Kaspersky provided an excellent overview on the security of cyberspace, in particular highlighting the effect of activities of state-sponsored espionage and cybercrime.

“All the data is stolen,” “At least twice.” is the emblematic statement pronounced by Kaspersky to describe a dramatic situation.

Kaspersky also focused the on the effort necessary to develop a state-sponsored malware such as Gauss, Flame and Red October , the cyber security expert revealed that for the design of a similar malicious code it is necessary at least a $10 million budged.

Kaspersky stated that more than 50% of malware were written in Chinese,  nearly 33% were written in Spanish or Portuguese, followed by Russian-coded malware, this last group is considerably very dangerous because the malicious code it products is the most sophisticated in the world.

Kaspersky also added that Chinese malware appeared to ‘not care’ about operational security because security experts during the investigation have regularly found personal document, photos and social networking accounts on servers used in attack campaigns.

Cyberspace is becoming a dangerous space that we cannot do without!

Pierluigi Paganini

(Security Affairs – cyber weapon, Stuxnet)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Palo Alto Networks fixed multiple privilege escalation flaws

Palo Alto Networks addressed multiple vulnerabilities and included the latest Chrome patches in its solutions.…

19 hours ago

Unusual toolset used in recent Fog Ransomware attack

Fog ransomware operators used in a May 2025 attack unusual pentesting and monitoring tools, Symantec…

22 hours ago

Paraguay Suffered Data Breach: 7.4 Million Citizen Records Leaked on Dark Web

Resecurity researchers found 7.4 million records containing personally identifiable information (PII) of Paraguay citizens on…

1 day ago

Apple confirmed that Messages app flaw was actively exploited in the wild<gwmw style="display: none; background-color: transparent;"></gwmw>

Apple confirmed that a security flaw in its Messages app was actively exploited in the…

2 days ago

Trend Micro fixes critical bugs in Apex Central and TMEE PolicyServer

Trend Micro fixed multiple vulnerabilities that impact its Apex Central and Endpoint Encryption (TMEE) PolicyServer…

2 days ago