Who Created Stuxnet? The Answer Everyone Knows and Nobody Has Confirmed

The United States has never said it built Stuxnet. It has prosecuted a four-star general for talking about it, and then pardoned him on the day he was due to be sentenced.

Ask who created Stuxnet and you get one answer, delivered without hesitation: a joint American and Israeli operation, reported under the codename Olympic Games. That answer is probably correct. It has also never been confirmed by anyone in a position to confirm it, and most of what gets offered as evidence for it is not evidence.

The two clues everybody quotes come from a report whose authors told readers, in the same document, not to draw attribution conclusions from them. The hardest forensic finding about who wrote Stuxnet says nothing about nationality at all. And the one government document that exists on the subject refuses to name either the program or the country.

Who created Stuxnet?

Stuxnet has been widely reported as a joint operation of the United States and Israel. No government has acknowledged it. There has been no indictment, no declassification, and no statement of responsibility from anyone, at any point since the worm was pulled apart and documented.

What exists instead is three separate bodies of material, routinely compressed into that one confident sentence: forensic analysis of the code, a federal leak prosecution, and investigative journalism. They support very different claims, and they are not equally checkable.

The two clues everybody cites

Both come from the same place: Falliere, O Murchu and Chien's W32.Stuxnet Dossier, version 1.4, February 2011.

  • The path string. Whoever compiled the driver left b:\myrtus\src\objfre_w2k_x86\i386\guava.pdb in the binary. Symantec noted that guavas belong to the myrtle family, and offered a flat reading of the rest: "Myrtus could be 'MyRTUs'" — remote terminal units. The Book of Esther interpretation, in which myrtus is Hadassah, came from readers afterwards. It is not in the report.
  • The infection marker. Stuxnet skipped any machine carrying a registry value NTVDM TRACE set to 19790509. Symantec suggested this may be 9 May 1979, and noted that Habib Elghanian was executed by firing squad in Tehran on that date.

Then, in the same document, the sentence nobody quotes:

Symantec cautions readers on drawing any attribution conclusions. Attackers would have the natural desire to implicate another party.

A hardcoded integer and a directory name are the two cheapest things in a binary to plant. The analysts who found them said so at the time, in writing. They are still being presented as fingerprints.

What the code actually proves

There is one piece of hard evidence about Stuxnet's authorship, and it arrived on 11 June 2012, from Kaspersky.

The 2009 build of Stuxnet contained a component called Resource 207 — 520,192 bytes, dropped entirely from the 2010 version, and largely unexamined until then. Inside it was an encrypted DLL wrapping a further PE file of 351,768 bytes. That file was atmpsvcn.ocx: a module of the Flame platform. It handled spread via removable drives and privilege escalation through a win32k.sys flaw reached via NtUserRegisterClassExWOW() — which Kaspersky notes may be the issue Microsoft closed as MS09-025 in June 2009.

The dates are the point. Kaspersky places the Flame platform at no later than summer 2008, and Resource 207 at February 2009. Two codebases, developed separately, sharing a module in 2009 and never again after it.

That finding establishes something specific and verifiable: Stuxnet and Flame came out of an organisation running more than one development team, and those teams had access to each other's work. It does not name a country. The strongest technical evidence about who made Stuxnet is evidence about an org chart.

What Langner actually argued

Ralph Langner's To Kill a Centrifuge, November 2013, is the analysis that separated the overpressure attack from the rotor-speed attack, and established that the famous 21 seconds of recorded sensor readings played back in a loop belonged only to the first of the two.

On authorship he does not point at a flag. He points at a job description:

It is not even difficult to identify potential suspects for such an operation; nuclear counter-proliferation is the responsibility of the US Department of Energy and since 1994 also of the Central Intelligence Agency.

His case runs on capability rather than on strings: the attackers knew the plant's design, and somebody had access to enrichment hardware to develop against. That is an argument about who could have, not about who did, and he keeps the distinction — which is more than most of the write-ups citing him manage.

He is also unflattering about the outcome. He calls it a low-yield weapon, a setback of roughly two years, against rotors Iran could replace out of stock.

The closest thing to an official answer is a felony conviction

On 17 October 2016 the Justice Department announced that retired General James E. Cartwright, 67, of Gainesville, Virginia, had pleaded guilty to making false statements. Cartwright had been Vice Chairman of the Joint Chiefs of Staff from 31 August 2007 to 3 August 2011, and Commander of US Strategic Command from 2004 to 2007. He had signed more than 36 non-disclosure agreements.

Between January and June 2012 he disclosed classified information to two reporters, some of it at the top secret level, which appeared in published articles and in a book. FBI agents interviewed him on 2 November 2012. He told them he had not provided or confirmed classified information to the first reporter and was not the source of the quotes in that reporter's book. He told them he had never discussed a particular country with the second reporter. Both statements were false.

Read the release looking for the word Stuxnet and it is not there. Iran is not there either. The document convicting a former Vice Chairman of the Joint Chiefs over this program declines to name the program, and calls Iran "a particular country."

He faced five years. Sentencing was set for 17 January 2017 before Judge Richard J. Leon, with prosecutors seeking two. On 17 January 2017, Obama pardoned him.

The full official record, then: an investigation the US Attorney said collected tens of thousands of documents and interviewed scores of current and former government employees, a felony conviction, a refusal to name what was leaked, and a pardon issued before sentence was passed.

The Dutch engineer, and why the delivery is still disputed

In January 2024, after a two-year investigation, de Volkskrant named the man it says carried Stuxnet in: Erik van Sabben, a Dutch national recruited by the AIVD in 2005, at the age of 36, working for a heavy transport company in Dubai. In that account the malware was planted on a water pump he installed at Natanz.

Michael Hayden, who ran the CIA, put the development cost at between $1 billion and $2 billion, and would not confirm the water pump on the grounds that it remains classified.

Langner's response was shorter. A water pump cannot carry a copy of Stuxnet.

The man who reverse-engineered the payload and the man who ran the agency still disagree about how it got through the door, and neither of them is guessing.

What is actually settled

Three things, and they are narrower than the consensus.

Stuxnet was aimed, not scattered. Symantec traced it to five organisations, hit in three waves: a build compiled on 22 June 2009 that reached four of them between 23 June and 19 July 2009; a build compiled 1 March 2010; and a build compiled 14 April 2010 that was inside a target network by 26 April. In one case the interval between compiling the binary and infecting the target was twelve hours. Nobody gets a twelve-hour turnaround by accident.

It escaped anyway. Roughly 100,000 hosts, about 60% of them in Iran, as of 29 September 2010.

It shared a codebase with Flame in 2009, and never again.

Everything beyond those three is reporting. Good reporting, corroborated from several countries — but reporting, not a document anyone signed.

Governments do name names. Just not their own.

Attribution is not inherently unspeakable. Several governments jointly named the state behind NotPetya on the record, in public, in a coordinated statement.

Naming your own operation is a different act, and there is no mechanism for it short of being forced. Stuxnet was never forced. What the alternative looks like is the prosecution of the man who talked to reporters about it.

So the honest answer to the question is the unsatisfying one. Stuxnet was built by an organisation running multiple development teams, with detailed knowledge of the Natanz plant and access to enrichment hardware to test against. Every open-source indicator points at the United States and Israel. None of it is confirmation, and the two details most often waved as proof were flagged as unreliable by the people who found them, in the paragraph that reported them.

The only thing the United States has ever put in writing about Stuxnet is that a general lied about discussing a country it would not name.

Written and fact-checked by a practicing senior security engineer. Published under UNHACKED, which is accountable for it. How the Archive is written.

Further reading


EXHIBIT 0001 — STUXNET

We put it on a shirt. The first entry in the archive, because it had to be.

Most people who see it will read a word they half-recognise from a documentary. A smaller number will clock the details and know exactly what they are looking at — including the part where nobody has ever admitted to any of it.

That's the whole idea.

View the Stuxnet shirt — EXHIBIT 0001

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.