Engineer Used Water Pump to Get $1B Stuxnet Malware into Iranian Nuclear Plant
securityweek.com
securityweek.com
>Ralph Langner, a researcher who conducted an in-depth analysis of Stuxnet after the malware’s existence came to light, noted that “a water pump cannot carry a copy of Stuxnet”.
In his Xitter post he also says the infiltration timeline doesn't match his analysis.
https://twitter.com/langnergroup/status/1744389845638635727
who to believe ?
Well, that's all the proof I needed — a twitter post with no further information.
Obviously he may be right as he is a researcher and most likely actually did the research, but an non-sourced definitive statement on social media is not what I consider "proof".
The more hard to believe part is that a lot of electric equipment like water pumps have very simple software running on them, which might only be controlled by some messages on a serial bus that sends certain commands. To use that as a vector you would need the software to have very specific vulnerabilities.
Hence, I doubt they employed people to promote piracy on the PS2.
Anyways, from this perspective, even back then, the analysis was pretty thorough:
If you're not familiar with pinyin, do you still read that X as making an "Sh" sound, as in Xi Jinping?
VFDs are connected to the process control system through a variety of interfaces... simple voltage or current loops, serial buses like BACnet, modbus, or ethernet interfaces like modbus TCP.
The centrifuges that were destroyed are not driven by pumps. Motors, yes, but not pumps.
Maybe that was the point. To throw more mis/disinformation to cause more guessing on how it happened instead of who.
I'm afraid he was not told the truth of the operation...
Have I missed anything?
Here's a past discussion on HN:
"Unilateral Israeli changes to Stuxnet caused its exposure, angering US" 2016, 132 comments:
https://news.ycombinator.com/item?id=11108748
The key point is in the Ralph Langer pdf in the top comment there (To Kill a Centrifuge, 2013):
> "Stuxnet’s early version had to be physically installed on a victim machine, most likely a portable engineering system, or it could have been passed on a USB stick carrying an infected configuration file for Siemens controllers. Once that the configuration file was opened by the vendor’s engineering software, the respective computer was infected. But no engineering software to open the malicious file, equals no propagation."
> "That must have seemed to be insufficient or impractical for the new version, as it introduced a method of self-replication that allowed it to spread within trusted networks and via USB sticks even on computers that did not host the engineering software application. The extended dropper suggests that the attackers had lost the capability to transport the malware to its destination by directly infecting the systems of authorized personnel."
On the positive side, this event led to a lot of job creation in the energy-related cybersecurity sector. This is an informative read from the time:
https://nuclear.duke-energy.com/2012/02/07/stuxnet-and-cyber...
>Getting the worm into Natanz, however, was no easy trick. The United States and Israel would have to rely on engineers, maintenance workers and others — both spies and unwitting accomplices — with physical access to the plant. “That was our holy grail,” one of the architects of the plan said. “It turns out there is always an idiot around who doesn’t think much about the thumb drive in their hand.”
>In fact, thumb drives turned out to be critical in spreading the first variants of the computer worm; later, more sophisticated methods were developed to deliver the malicious code.
>The first attacks were small, and when the centrifuges began spinning out of control in 2008, the Iranians were mystified about the cause, according to intercepts that the United States later picked up. “The thinking was that the Iranians would blame bad parts, or bad engineering, or just incompetence,” one of the architects of the early attack said.
I have it saved for that quote: "It turns out there is always an idiot around who doesn’t think much about the thumb drive in their hand."
Well, what an unfortunate coincidence.
I’ve seen firsthand that security engineers tend to be paid less than mainstream dev roles, but pocket money for the best talent in the world seems unlikely. The IDF needs them more than they need the IDF. Even with religious beliefs in play, wouldn’t market forces still have an effect?
Well, this of course only applies to the conscripts who are serving their mandatory (almost) 3 years in the IDF. It's not like you can leave and if you're planning to build your career in this field it obviously preferable than serving in combat or logistics units.
I would assume they are more like interns/apprentices though (how useful can most 18-20 year olds be anyway?) and most real work is done by people who are actually being paid a salary.
Basically a signal intelligence/hacking unit just like any other military outfit in their forces.
It is mostly 18 to 21 year olds. And I would think it looks really good in your CV if you want to work on the sector later.
I wonder which unit is the elite one.
For instance the attack path isnt immediately clear and there needs to be a period of developing proof of concept exploits that are then tested in a variety of environments, there needs to be persistence techniques developed, there needs to be a C2 system, there needs to be a methods to avoid detection. Stuxnet was probably a collection of many 0days that were used in conjunction. Each 0day probably takes months of "dev time" at minimum to develop.
Him dying in a motorcycle accident is awfully convenient for whoever hired him if he was, indeed, involved in the operation.
Wow. Arguably worth it but that is a staggering figure.
But it's hard to imagine it being worth it to the American taxpayer. Remember it's arguable whether Iran would have bothered pursuing this at all, except Israel itself is a nuclear power, which the United States allowed (see Taiwan in the 1980s for what the US does when other allies try and start their own programs).
Dr Jeffrey Lewis (an American expert in nuclear nonproliferation) answers this with a no. Not on monetary grounds, but on the grounds that the setback is only momentary. (While as he proposes diplomacy can bring lasting change.)
I recommend his podcast "The Deal": https://www.middlebury.edu/deal-podcast
Season 1 and season 2 are entirely about the promise and the collapse of the nuclear deal with Iran. Season 2 episode 4 talks about Stuxnet.
The focus on a guy with a USB stick and access to shitty SIEMENS/SCADA systems makes a nice james bond story but I don't see the actual relevance.
Here you go! ( Tweedekamer is Dutch parliament )
The news article resulting in the questions: https://www.volkskrant.nl/kijkverder/v/2024/sabotage-in-iran...
Looks like NL is going to do a "wir haben ess nicht gewusst" in order to not be liable for collateral damage. "The Americans did it".
I suspect they don't understand that intelligence and the military function by pouring money on a problem until it gets solved despite profound, systemic failures.
I’m not that gullible (even though the word ’gullible’ was removed from the English dictionary in 2021, I am still fond of it).
But, seriously. No chance on earth. It’s just PR. And the pump thing is probably just psychological warfare… ‘if they can put it into a water pump, they can put it into anything…’.
It was more likely just a mundane USB stick. Every computer has a usb port.
I wonder if he ain't dead and they faked his death incase his name ever got out (like this)
Well, that’s not suspicious at all. Any of the parties involved could conceivably benefit from his accident.
Either one can cause what looks like a typical accident.
Plane crashes have a pretty high death rate too, but plane crashs are rare.
What is the probability of having a motorcycle accident in Saudi Arabia.
The odds of dying in a traffic accident in that country are considerably higher than in the United States, and much higher than in other developed countries (sorry USA, you suck at road safety, but not as much as the UAE does)[1].
While I don't have country-specific statistics to hand, the odds of dying riding a motorcycle are much, much higher than in a car. One estimate is that you are around 27 times more likely to die per distance driven/ridden [2].
Even so, in an absolute sense, the odds of dying on a typical motorcycle commute are low. My guess is that your odds of meeting foul play shortly after screwing with the Iranian nuclear program are likely higher than dying in a random traffic accident. But coincidences do occur.
[1]https://en.wikipedia.org/wiki/List_of_countries_by_traffic-r...
[2] https://www.autoinsurance.org/motorcycle-vs-car-accidents/
The US is right in the middle -- doing better than the Czech Republic and South Korea -- on the metric that matters on the page you linked, but really, more data is needed because the metric you want to look at is mostly missing from the table.
But to be serious, I meant it mostly that it's certainly one case that would warrant extra investigations. Even if it was a random accident, someone like the Iranians could have claimed that their super advanced spy hunting team got him.
This is not the number that really matters in this context.
Falling out of a 8 story window has an incredibly high injury/death rate. Yet those we often assume ARE the result of foul-play.
What we're really comparing here is the probability of a party either lying, or contributing (causing) the motor cycle accident. The lethality rates aren't super interesting in this case. The main difference between this and falling out of windows, is that window-falls are much more rare then motor cycle accidents.
Who is 'we'? Falls out of buildings are overwhelmingly due to accidents by tradespeople or suicide.
Most homicides by being pushed from a height occur in remote areas, not from buildings. Most windows on high buildings are limited in how far they open during normal operation for safety reasons. And most older buildings that lack these features have smaller windows with higher sills. Statistics aren't tracked to this level by most crime reports because it is so overwhelmingly rare for someone to be killed this way.
While homicidal defenestration makes for a good fictional story line, I don't think it is useful for murderers.
> Statistics aren't tracked to this level by most crime reports because it is so overwhelmingly rare for someone to be killed this way.
The real issue here is we aren't comparing the statistics of the "average joe". For random-person we can predict the reason for their fall was unlikely to be state-level foul play - in fact near zero chance of it.
The likely hood of state-level foul play is substantially higher for spies, rich oligarchs with unpopular opinions, journalists, etc. How much higher I have no idea.
---
Anyway my point was the lethality of the cause of death is really not what anyone is interested in. When spies, rich oligarchs with unpopular opinions, journalists, etc die shortly after they did something particularly provoking I don't think people care about the lethality of the incident as much as the cause.
However, it's also easy to fall into the fallacious trap of defining people solely by their profession. People who have sensitive jobs and also do other risky activities in their spare time incur those risks in addition to the risks they have due to their profession.
In fact, some successful people with enemies engage in more risky activities because they can afford to do so. Rich people dying in general aviation accidents is a pretty frequent pattern, for example.
Plenty of weirdly coincidental falls from windows:
> Ravil Maganov, September 1 2022, reportedly hospitalised for heart problems and depression, then "fell out of a window"
> Grigory Kochenov, December 7 2022, reportedly fell to his death from his balcony while officials from the Investigative Committee executed a search warrant for his apartment
> Dmitriy Zelenov, December 9 2022, reportedly felt ill and fell over a railing and hit his head, later died in hospital without regaining consciousness
> Pavel Antov, December 24 2022, fell out of window from Hotel Sai International
> Marina Yankina, February 16 2023, found dead after falling from a window on the 16th-floor of a high-rise building.
> Artyom Bartenev, June 8 2023, found dead after falling 12 stories from his apartment window.
> Kristina Baikova, June 23 2023, fell off her apartment at the 11th floor; circumstances of the incident have not yet been clarified.
These stories are all "according to intelligence sources", they can really anonymously brief out anything that serves their needs.
All this requires is to understand who died shortly after Stuxnet who could have feasibly been involved.
It was his family who said that he started panicking, so he was probably involved.
It seems much more likely that he actually did die in a random motorcycle accident (not uncommon), or he was entirely uninvolved and a dead man was chosen to pin blame on in order to hide the real method(or, to make Iranians stop trusting foreign contractors, making them do everything in-house with higher costs and worse quality).
If he panicked after the Stuxnet attack, as his family is reported to have said, then it's likely he has behaving erratically and was fearful for his life.
That could easily translate to circumstances where he rides a motorcycle in a particularly dangerous manner - e.g. fleeing from someone he thought was Iranian/Dutch/US/Israeli intelligence (even if they weren't).
Also, reasonable chance this entire story is fabricated and this was done a different way.
The point of killing someone over some wrong they did you is publicizing it after the fact. If you don't take credit for it, it doesn't have any deterrent power.
Or alternately, he did it and then tried to back out of the deal. Now arranging an apparently accidental death then became the best way to keep security intact.
The one theory that makes no sense is that they intended his death from the beginning.
Like the JFK assassination theories that involve killing off an additional dozens of people. You can't cover up one murder by involving an extra 1000 people.
- Foreigner
- Engineer
- Married to Iranian
- Access to plant (Alleged)
- Died from non-natural causes within 2 weeks at age 36
The various deaths associated with Putin are a counter example here. Russia denies involvement but the method usually makes it pretty obvious. Rare poison, unlikely situation etc.
The asset in this case wasn't known publicly and the method of death makes people assume it was simply an accident. Unless they did some private announcement, no one was deterred. If it was Iran and they wanted to send a message, they would probably have to out the asset publicly and/or make it clear that it was an assassination. e.g. a bomb would send a clear signal that it was more likely to be a nation state assassination and not some accident or a random robbery/act of violence.
It’s a pretty strong signal to others that there are consequences.
"We successfully attacked the nuclear facility!"
"Oh Van, by the way what name did you sign in the log book?"
"...Oh no"
I imagine there are a non-zero amount of readers (but not commenters) who find these stories comments extremely funny.
From the report in Dutch, they raise the point he may not have even known the magnitude of what he was doing. Until it already had been done and he realized what happened.
Even AIVD/MIVD may have not known…or so they say.
But we will probably never know.
Actually his name is Erik, van Sabben is his last name. Perhaps that's how he got away with it.
They were all older gents, but it’s not outside the realm of plausibility that “Van” could be what van Sabben was called. :)
I’m not clear on the timeline. As I understand it, the hack went on for ages before it went malignant and started damaging stuff. Is it 2 weeks from being deployed, or 2 weeks from wrecking equipment?
Do you think he got the villa next to Epstein or Kobe?
It's much easier for a country to retire an engineer with a fat paycheck than to create an incredible amount of distrust killing him.
An assassination only makes sense if somehow he threatened to tell everything to the iranian goverment.
https://english.aawsat.com/features/4778291-stuxnet-mystery-...
He was a well known engineer that had worked in Dubai for 12 years in the transport industry and had an Iranian wife. He was well known as an engineer at the forefront of the rapid development of major projects in the Gulf region.
A regional paper even published his obituary in 2009:
https://www.thenationalnews.com/uae/engineer-who-helped-buil...
Excerpt:
Erik van Sabben, a Dubai-based engineer whose expertise in the heavy lifting and transport industry placed him at the forefront of the rapid development in the Gulf over the past decade, has died. A keen motorcycle rider, he was killed in an accident near Dhaid on Jan 16, just two weeks short of his 37th birthday. Born in Vlissingen, The Netherlands, Mr van Sabben had lived in the Gulf on and off for 12 years. While an undergraduate, he worked as a trainee for Mammoet Gulf in Dubai, a specialist heavy lifting company, which he joined after graduating. He spent the next decade in Dubai, and briefly, Abu Dhabi.
I swear, the latest generation of conspiracy theorists are really pathetic.
USA and Israel think Iran have got a bit close to figuring out Stuxnet culprit, they put out a story and use a poor guy who can’t defend himself against the accusation of being involved, one who happened to have had a tragic accident with a motorbike and who so just happened to do some work in Iran. And boom, the death is suspicious so there must be truth to it all…
That is probably more believable (to me at least).
I don't see how punishing him further accomplishes anything.
source:Floridian
> Van Sabben passed away in the United Arab Emirates two weeks after the Stuxnet attack as a result of a motorcycle accident.