Kaspersky Lab, the Russian cybersecurity company, has released new details about the controversial Stuxnet malware incident in Iran, claiming that the history of the infection of computer facilities related to Iran's uranium enrichment program is longer than previously thought. Kaspersky experts believe that the company "Kala Electric," which played a role in producing centrifuges for the Natanz nuclear facility, was the primary target of the initial attack, and the company "Behpouh" was the entry point for the virus into the global network. Anna Ryskaya, a reporter for Radio Farda in Ukraine, interviewed Alexander Gostev, a senior antivirus expert at Kaspersky, about this matter. The investigation into Stuxnet has never stopped. Since we recognized this malware in 2010, research on it has begun and continues to this day. Within the framework of this research, earlier this year, the first version of Stuxnet, produced in 2007, was discovered, which takes us back long before the main attack of this malware. The Stuxnet saga is not over, and we are researching alongside various companies in this field, including Symantec, which is our main partner in exploring this subject. The information we published yesterday, revealing which companies were the first victims of Stuxnet, is related to the release of a book by American journalist Kim Zetter about the history and investigation of Stuxnet. We actively participated as experts in the writing of this book, and it can even be said that the book was based on conversations with us. In fact, the identification of which companies and organizations were the first victims of this malware is not new information; we have known this for a year and a half, and Symantec reported it in February 2011, although without naming these organizations. During this time, we were working on issues related to this virus that had more urgency. However, now that a new book about Stuxnet has been published, we remembered that we had information on this topic that is worth presenting to the audience, and for this reason, we published this information in collaboration with Symantec. Before we continue our discussion about the recently published information from your company, I wanted to ask if I understood correctly that Stuxnet has not disappeared from the virtual network and is still active? Fortunately, Stuxnet is no longer replicating. In fact, a command to prevent automatic dissemination was embedded in the coding of this virus, which was activated in the summer of 2012. It has been over two years since this malware has rendered itself unproducible and does not infect new computers. However, Stuxnet continues to operate in systems that have been infected and not treated. When I say the Stuxnet saga is not over, I mean that research on it continues. We are now trying to gather as much information as possible about the past of this virus to understand where this saga began. Recently, a writing related to Stuxnet was discovered from 2007. Some clues even reach back to 2003. We are going back in reverse to see if we can discover an even earlier version. Very well, tell us what information you have recently made available to the public about this malware? We published the names of five organizations and companies in Iran that were the first targets and victims of Stuxnet, indicating that these companies were targeted in 2009 and some in both 2009 and 2010. Identifying the target organizations clarifies many issues for those who want to understand the depth and roots of this attack. By piecing together this information, one can understand how the attackers attempted to reach their goal. The victim companies of this attack are all active in uranium enrichment or provide services for this sector, and all are on the U.S. sanctions list. These companies have been blacklisted by the U.S. due to the import of goods that could potentially be used in the construction of nuclear weapons. The creators of Stuxnet used these companies to attack their ultimate target. It is unanimously agreed that this ultimate target was the Natanz uranium enrichment plant, and Stuxnet was supposed to disable the centrifuges at this site after infiltrating the Natanz nuclear facility. Directly attacking these facilities was impossible because this site is not connected to the internet, and the only way to infiltrate the malicious codes was to infect partner companies, hoping that sooner or later an infected USB drive from these companies would find its way to Natanz. Your published information states that the transfer of Stuxnet to Iran was not through a USB drive. Could you elaborate on this? One previous theory was that Stuxnet entered Natanz via a USB carrier and began its global journey from there. However, our new discoveries completely dismiss this theory. According to new information, Stuxnet arrived in Iran just hours after its coding was completed, and it is highly unlikely that its creators could have transferred an infected USB drive to Iran within a few hours and infected a computer in Natanz. It is more likely that we are dealing with an attack of a different kind. One possibility is that Stuxnet was sent via email, but in this case, part of our information about this virus remains incomplete because we do not have the email containing it that was sent to users. The second way is the infection of a server remotely through a security flaw in the Windows operating system, and again, here we have new avenues for research. We have often heard that Stuxnet delayed Iran's nuclear program for several years. Can you explain how this virus accomplished that? In fact, we do not have precise information about whether Stuxnet penetrated Natanz or not, and we make this inference based on indirect evidence. Reports from the International Atomic Energy Agency indicate that in the fall of 2009, when the first version of Stuxnet existed, the number of active centrifuges in Natanz decreased. At least a thousand centrifuges became inactive, and the enrichment capacity decreased by a third. Returning to pre-incident production levels took several years. However, we do not know whether this drop in enrichment volume was a result of Stuxnet's actions or had another cause. Can your investigations open a window to identify those behind the creation of Stuxnet? Our goal is not to find suspects. We are looking for the technical specifications of this attack and the technological features used in the creation of this malware. With the technical information we have, we cannot confirm or deny the theory that has been proposed since 2010, which suspects the U.S. or Israel of being behind Stuxnet. In 2012, American journalist David Sanger reported that in 2008, President Obama signed off on a plan codenamed "Olympic Games," aimed at sabotaging Iran's nuclear program, and many believe that Stuxnet was created as part of this plan. We do not know whether these claims are true or not, but today, this theory is dominant in the Stuxnet saga. After the Stuxnet attack, other malware has also attempted to target Iran's nuclear program. Are Flame or Red October created by the same group, or are they unrelated? When we identified the Flame malware in 2012, we noticed that some components of Flame were used in the 2009 version of Stuxnet, but these components disappeared in the 2010 version of Stuxnet. This means that the creators of Flame collaborated with the creators of Stuxnet in 2008-2009. In 2010, this collaboration ceased, and since then, we are dealing with two separate groups. The first group was responsible for producing Stuxnet and Duqu, another malware targeting Iranian companies. The second group consists of the creators of Flame and its sibling, Gauss, which was spying on Lebanese banks. In other words, Stuxnet and Duqu, on one side, and Flame and Gauss on the other, are two parallel projects, and two separate groups were working on them. Stuxnet clarified for us that these two groups collaborated at one point. Other well-known malware such as Red October is not related to either Stuxnet or Flame, and we are almost certain that the creators of Red October are Russian-speaking.
The Main Target of Stuxnet Was the Producer of Centrifuges in Natanz
Kaspersky Lab has revealed that the Stuxnet malware targeted Iranian companies involved in uranium enrichment, particularly focusing on Kala Electric and Behpouh. The findings suggest that Stuxnet's infiltration methods were more complex than previously thought, and its impact on Iran's nuclear program was significant, delaying operations for years.
👥 Key Players
⚡ Actions
📰 What Happened
Kaspersky Lab revealed Stuxnet targeted Iranian centrifuge producer Kala Electric.
- Unknown attackers attack Kala Electric, Behpouh
- Kaspersky Lab research Stuxnet malware
- Kaspersky Lab publish public
💡 Why It Matters
📚 Background
The Stuxnet malware incident continues to have significant implications for Iran's nuclear capabilities.
📝 Key Evidence
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%