How a secret Dutch mole aided the U.S.-Israeli Stuxnet cyberattack on Iran
news.yahoo.com
news.yahoo.com
I hope that whoever this mole was that he/she has good life insurance and no kids. Based on this info it should be trivial to figure out who it was and even if the journalist got it wrong there will likely be repercussions against the people implicated here.
He's clearly got a bone to pick and it isn't a truth bone.
They reported Iran executed some number of people who were believed to be moles or otherwise guilty of harming the program. According to the sources, Iran doesn't seem to know with certainty if they got the right people, or if the executed individuals were merely unwitting carriers who got infected.
It's also possible they didn't care so much and considered this sort of incompetence/negligence (of course, not such a fair accusation given their adversaries) a capital offense. They may have executed everyone involved, wittingly or not, to serve as a deterrent and increase future OPSEC. Many it's just a bonus for them if a mole also got caught in the net.
This is kind of like a game theory puzzle: if he was executed and you say he was, you give them valuable information. Same if he wasn't and you say he wasn't. You could lie, but Iran's intelligence reading this article may suspect you'll lie. Or they may think it's a double bluff or something.
The safest move to cause the least damage and give Iran as little info as possible may be to say the mole may or may not have been executed. There's also the possibility that the sources fuzzed the story a bit: there may have been more than one mole, or, less likely, zero moles. Intelligence is always cat-and-mouse mind games, with fact and fiction often intermixed carefully.
There was a great article posted the other day on HN suggesting that MI5 had not, in it's entire history during the cold war, unearthed any concrete evidence of, or caught any, Russian spies (save for two instances uncovered incidentally by local police, and one who was a royal and hence never charged).
But none of that mattered. The appearance of subterfuge and counter, is much more important than any actual success. And as you suggested, there needn't have been any mole at all, for the events to play out exactly as they did.
Why?
may be it is all just a smoke screen and parallel construction, and the virus was just included in the next patch update :) Wouldn't be the first time. The parallel construction is obviously needed to make Iranians and the likes to continue hunting for moles (sucks to be executed as a mole for an USB drive that you have no idea about found in your house), tightening security and wasting their money/resources in all the other ways while still continuing to buy Siemens/etc.
While the book is somewhat chronological and story-driven, there's still a ton of interesting info packed into it that I think a lot of HN readers would love.
So Stuxnet just randomly self-assembled on the Internet, to attack very specific air-gapped industrial controllers?
It's not like this highly-targeted Siemens controller worm was a cryptojacker written by a bored teenager.