How the mighty have fallen - the notorious Stuxnet malware source code has been replicated and posted on GitHub for all to see
The GitHub Repository
A pseudonymous GitHub account has published what it describes as a faithful reconstruction of Stuxnet, the worm that sabotaged Iranian uranium-enrichment centrifuges. The repository surfaced via a Show HN submission, which mainstream media outlets then picked up.
The README explicitly states that it is a reconstruction assembled from decompiled binaries. Those binaries have been in public circulation since Belarusian firm VirusBlokAda pulled samples from an Iranian customer's machines in June 2010. Everything that followed, including Symantec's W32.Stuxnet Dossier and Ralph Langner's To Kill a Centrifuge, was built on those samples and how they reacted in test environments. The about page states it was reproduced for educational purposes and is designed to only work on Windows XP and Windows 7.
Background
Stuxnet purportedly took out a fifth of Iran's centrifuges before being discovered. It became the first piece of software widely accepted as having caused physical destruction in the real world.
Previous Reconstructions
This is not the first time readable C-language code aiming to replicate Stuxnet has been published online:
- Malware researcher Amr Thabet published a decompilation of the
MRxNetrootkit carrying a 2010 to 2011 copyright notice. - Christian Roggia followed with a dropper decompilation called
open-myrtus, copyrighted 2012 to 2014, which has since been forked into a long chain of repositories.
The original Stuxnet source, written by whoever built it, has never been leaked.
Naming and Verification
The code remains unverified and untested, with some users indicating that it is likely an AI-generated replication of the original binaries' behavior. The thread where it was first brought to attention by a user called Sadpainy has mixed views, with many developers branding it "AI slop" or a "fake" that relies on a mixture of already existing repositories.
The irony is that if such code were a faithful replication, it would not have mentioned "Stuxnet" in multiple places, including registry keys. The moniker was not used by the developers but was coined by Symantec weeks after discovery, switching from the original W32.Temphid identifier.
Safety and Implications
For those looking to test it, a virtual machine might be their best bet, especially given Stuxnet's ability to physically damage hardware. It is also a stark reminder of what a rogue AI agent could do if left unchecked without specific instructions or safeguards.
Author
Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer's guides, hardware reviews, and sponsored content and features related to tech. Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.
Comments
No comments yet. Start the discussion.