The story I read was that the perpetrators had access to the physical centrifuge control center for a while, and used a thumb drive carried by a contract engineer to plant the malware. Then they lost that physical access, and the centrifuge center replaced all its computers or re-installed the OS, and so they tried to use a viral worm (Stuxnet) to get in and deliver the malware to the target system, which somehow escaped onto the web, resulting in Stuxnet getting detected.
Here's a past discussion on HN:
"Unilateral Israeli changes to Stuxnet caused its exposure, angering US" 2016, 132 comments:
The key point is in the Ralph Langer pdf in the top comment there (To Kill a Centrifuge, 2013):
> "Stuxnet’s early version had to be physically installed on a victim machine, most likely a portable engineering system, or it could have been passed on a USB stick carrying an infected configuration file for Siemens controllers. Once that the configuration file was opened by the vendor’s engineering software, the respective computer was infected. But no engineering software to open the malicious file, equals no propagation."
> "That must have seemed to be insufficient or impractical for the new version, as it introduced a method of self-replication that allowed it to spread within trusted networks and via USB sticks even on computers that did not host the engineering software application. The extended dropper suggests that the attackers
had lost the capability to transport the malware to its destination by directly infecting the systems of authorized personnel."
On the positive side, this event led to a lot of job creation in the energy-related cybersecurity sector. This is an informative read from the time:
>Getting the worm into Natanz, however, was no easy trick. The United States and Israel would have to rely on engineers, maintenance workers and others — both spies and unwitting accomplices — with physical access to the plant. “That was our holy grail,” one of the architects of the plan said. “It turns out there is always an idiot around who doesn’t think much about the thumb drive in their hand.”
>In fact, thumb drives turned out to be critical in spreading the first variants of the computer worm; later, more sophisticated methods were developed to deliver the malicious code.
>The first attacks were small, and when the centrifuges began spinning out of control in 2008, the Iranians were mystified about the cause, according to intercepts that the United States later picked up. “The thinking was that the Iranians would blame bad parts, or bad engineering, or just incompetence,” one of the architects of the early attack said.
I have it saved for that quote: "It turns out there is always an idiot around who doesn’t think much about the thumb drive in their hand."
Here's a past discussion on HN:
"Unilateral Israeli changes to Stuxnet caused its exposure, angering US" 2016, 132 comments:
https://news.ycombinator.com/item?id=11108748
The key point is in the Ralph Langer pdf in the top comment there (To Kill a Centrifuge, 2013):
> "Stuxnet’s early version had to be physically installed on a victim machine, most likely a portable engineering system, or it could have been passed on a USB stick carrying an infected configuration file for Siemens controllers. Once that the configuration file was opened by the vendor’s engineering software, the respective computer was infected. But no engineering software to open the malicious file, equals no propagation."
> "That must have seemed to be insufficient or impractical for the new version, as it introduced a method of self-replication that allowed it to spread within trusted networks and via USB sticks even on computers that did not host the engineering software application. The extended dropper suggests that the attackers had lost the capability to transport the malware to its destination by directly infecting the systems of authorized personnel."
On the positive side, this event led to a lot of job creation in the energy-related cybersecurity sector. This is an informative read from the time:
https://nuclear.duke-energy.com/2012/02/07/stuxnet-and-cyber...