How we used to 'bomb' Iran.
- Adam Spencer

- Jun 18
- 5 min read
The claim is that a peace deal has been brokered. Truth is only time will tell. But one thing we do know. 20 years ago the US went about the whole “let’s disrupt Iran’s nuke program” a completely different way.

Don’t just stand there … bust a nuke.
Long before anyone outside the shipping world had heard of the Strait of Hormuz, back before The Apprentice had even spawned its first celebrity edition, the US and Israel went after the Ayatolleh’s arsenal. But they did it without dropping a single bomb. Just code.
This year, the Natanz enrichment plant has been pounded from the air on at least two occasions. Twenty years ago someone tried to wreck the very same site without anyone ever knowing they were there.
This is the story of the OG cyber-weapon, possibly the finest piece of malware ever written, and on the occasion of its rough 20th birthday (exact date unknown, naturally), dear reader, this is Stuxnet.
Dateline 2006.
Pakistan tested a working bomb in 1998, and its chief physicist, A.Q. Khan, turned out to be running a tidy side hustle. Old AQ was flogging enrichment blueprints and kit to North Korea, Libya and Iran.
When Libya came clean in 2003, the West grabbed its centrifuges and shipped them off to a lab in Tennessee. Same model Khan had sold Tehran, the IR-1.
Iran, meanwhile, kept enriching. By 2006 it had cascades spinning at Natanz, a bunkered plant ringed with fences and guns. Bombing it risked another Middle Eastern war which, given how President Bush had recently fared in Iraq and its surrounds was, fair to say, not a wildly popular idea.
So the geeks got a-thinkin', and soon Washington and an Israeli partner reached for something a great deal quieter.
"Oh, we know. It was the US and Israel." — Kim Zetter, Countdown to Zero Day.
So how do I build a bomb? Just asking, for a friend.
Natural uranium is mostly, with the greatest of respect, the useless isotope.
To get yourself a bomb you need to concentrate the rare one. The trick is a centrifuge, a metal tube about two metres tall spinning uranium hexafluoride gas at supersonic speed, flinging the heavier atoms outward so you can skim off the lighter, fissile stuff.
The stuff that splits and packs the real atomic punch.
Chain hundreds together into a cascade and you slowly climb towards weapons-grade gear.
The catch is those rotors are delicate things. Spin them slightly wrong and they wobble, crash into their neighbours and shatter.
Which is exactly the weakness those aforementioned cyber-geeks decided to lean on.
Stuxnet.
The Natanz computers most important to the project were ‘air-gapped’ — sealed off from the internet. So no amount of remote hacking could reach them.
The answer was gloriously low-tech.
The creators of Stuxnet loaded the killer code onto USB sticks and got humans to carry it across the moat.
Contractors who serviced the plant were the mules, most likely with no idea of the digital timebombs they were ferrying.
Built through 2006 and let loose in early 2007, the first version quietly closed the exit valves on the centrifuges.
Gas poured in and couldn't get out. The pressure climbed, and the machines tore themselves apart.
To the Iranians it looked like dodgy hardware. Inspectors logged wasted gas and stalled progress.
These days a cyber threat might be suspect number one after such an event. In the sweet naive days of 2007, nobody suspected the software.
Stux 2: Stux harder.
Then things got properly clever.

A second, far nastier version of Stuxnet arrived around 2009. Looksmaxxed for digital destructiveness, this one toyed with the rotor speed, flooring it and then slowing it to a crawl, setting up harmonic wobbles that destroyed the machines while the control room showed everything ticking along nicely.
Supervisors suspected nothing because the malware had recorded weeks of normal readings and played them back. Exactly like the cliched looped CCTV tape in a heist film.
"This virus is a masterpiece." — Jack Rhysider, Darknet Diaries.
The bit that makes specialists go weak at the knees is the zero-days.
A zero-day is a flaw the software maker doesn't know exists, so there's no patch and no defence.
Most malware is lucky to ride one.
Stuxnet carried four! Plus stolen digital certificates from two Taiwanese firms to make itself look legitimate.
Four unknown flaws stitched into a single weapon was unheard of at the time, and as a feat of engineering it remains a colossal achievement, the sort of thing that took a nation-state's worth of scientists, spies and coders years to assemble.
By the time Iran wiped its systems, around 1,000 centrifuges were gone. It was beastly enough that the head of Iran's atomic agency stepped down in 2009, a resignation many later pinned on the quiet carnage.
So how did we ever find out?
Stuxnet’s downfall was its inherent ambition. To improve its odds of reaching Natanz, the team bolted on an aggressive worm that copied itself onto any Windows machine it touched.
But this feature worked too well.
The thing leapt off the target network, onto contractors' laptops, out into the wider world, and turned up on roughly 100,000 computers across the planet; thankfully non-destructive on machines that did not match its target configuration.
That sloppiness is the only reason we know any of this.
In 2010, after a Belarusian firm first spotted it, the security firm Symantec started pulling it apart and realised they were staring at something almost certainly no criminal outfit of the time could possibly have built. Two of the keywords found in the code .stub and .mrxnet gave us Stuxnet.
"Stuxnet is a tactical nuclear missile in the cyber war arsenal." — ScienceDirect.
What a naive little tike that worm turned out to be, wandering off and getting itself collared.
The US has never formally owned up to Stuxnet, as part of a general policy of being pretty cagey about the who sphere of cyber-espionage. Yet two decades on, sabotaging an enemy's machines with a few keystrokes sits alongside land, sea, air and space as a recognised front of modern war.
And the wheel turns. The same Natanz that Stuxnet stalked in silence is now taking actual ordnance from the sky. The quiet approach has given way to the loud one.
But anyone who knows this field still stops and stares at what a few thousand lines of code managed to pull off twenty-odd years back.
Sleep tight. Somewhere out there, the next one is already sitting on a USB stick, waiting to be plugged into the action.
Further reading and listening;
Darknet Diaries, Episode 29: "Stuxnet". Hosted by Jack Rhysider, featuring journalist Kim Zetter, author of Countdown to Zero Day.
ScienceDirect, "Stuxnet" topic overview: https://www.sciencedirect.com/topics/computer-science/stuxnet




Comments