In short
How the US and Israel escalated cyber sabotage of Iran’s uranium enrichment in 2009–2010, moving from earlier Stuxnet-style attacks to a more aggressive “Olympic Games” phase, and how the malware later escaped into the wider world.
Guests
David McCloskey and Gordon Carrera (hosts). Guest referenced: David Sanger (author, The Perfect Weapon) and Kim Zetter (author, Countdown to Zero Day on Stuxnet). Also mentioned: Richard Clark (cybersecurity researcher) and IAEA inspectors (International Atomic Energy Agency) as on-the-ground actors.
Key claims
Obama accelerated the covert operation to buy time for diplomacy; early attacks targeted valves, later updates targeted frequency converters to stress centrifuges; Stuxnet’s code recorded normal operations, used timed attack cycles, and was designed to self-expire (after June 24, 2012). A later “worm” version self-propagated, used fake football sites for command/control, and escaped in summer 2010, triggering a White House Situation Room emergency.
Notable examples
Natanz centrifuge cascades; Fordow’s deep underground facility revealed publicly in September 2009; IAEA inspections in late 2009/2010; the “horse blanket” map briefing; the Situation Room panic after the worm went public.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOThe Cyber Attack on Iran's Nuclear Program
1:17 to 2:22
Exploration of the Obama administration's decisions regarding Iran's nuclear program.
“That's nordvpn.com slash restisclassified.”
The Cyber Attack on Iran's Nuclear Program
2:54 to 3:40
Exploration of the Obama administration's decisions regarding Iran's nuclear program.
“There was no consensus within the Obama administration about how these weapons should be used.”
Stuxnet Unleashed: Background and Consequences
3:40 to 4:55
Discussion on the Stuxnet virus and its impact on Iran's centrifuges.
“This was, he and others noted, exactly the kind of precision-guided weapon that other nations would someday learn to turn on us.”
Transition of Power: Bush to Obama
4:55 to 6:28
Detailing the transition between administrations and the continuity of covert actions.
“These centrifuges had been, of course, used to enrich uranium.”
Diplomacy vs Covert Actions
6:28 to 8:04
The balance between diplomatic efforts and covert sabotage in Iran.
“And very focused on it, the briefers bring out something called the horse blanket, which is a giant folding map of Iran's nuclear program.”
Iran's 2009 Protests and Nuclear Acceleration
8:04 to 10:02
Examining the protests in Iran and their impact on the nuclear program.
“and the Israelis pushing him into action or taking action themselves by buying time for diplomacy through the kind of covert action side.”
Fordow: Discovery and Implications
10:02 to 12:34
Discussion on the revelation of Iran's Fordow facility and its significance.
“And I guess also an acceleration of the nuclear program at the same time, right?”
Escalation of Cyber Attacks
12:34 to 14:00
The strategy behind escalating cyber attacks on Iran's nuclear capabilities.
“and they won't have the intelligence or advance warning that they're doing this breakout that we talked about and making that final push towards a bomb.”
Analyzing the Impact of Cyber Attacks on Centrifuges
14:00 to 17:18
Explore how targeted cyber attacks manipulate centrifuge operations to cause damage.
“So the early attacks that we talked about from 2007, it's thought they target the valves which let the uranium gas in and out of the machine.”
Analyzing the Impact of Cyber Attacks on Centrifuges
18:20 to 18:45
Explore how targeted cyber attacks manipulate centrifuge operations to cause damage.
Show all 12 chapters
The Role of IAEA Inspectors During Stuxnet
19:52 to 28:00
Understand the challenges faced by IAEA inspectors amidst the ongoing cyber attacks in Iran.
“We're going to have inspectors crawling around, looking at Natanz, looking at Fordow, all up in the Iranians' business while Stuxnet is going on in the background.”
The Challenges of Covert Cyber Operations
28:00 to 35:02
Explore the complexities and risks involved in launching covert cyber attacks.
“And he said, it just says lawyers all over it.”
Transcript
Automatic transcript. May contain errors.0:03Gordon Corera:For exclusive interviews, bonus episodes, ad-free listening, early access to series, first look at live show tickets, a weekly newsletter, and discounted books, join the Declassified Club at therestisclassified.com.
0:20This episode is brought to you by NordVPN. Data breaches are rarely singular assaults. Think of a file download as the final step in a multi-stage attack. Whilst waiting for a traditional scan, you could end up exposed to other threats.
0:37Gordon Corera:That's why intercepting threats at the source is key. Neutralising those harmless-looking links, identifying and blocking those scam websites. With NordVPN's digital security app, you won't get ambushed. Much more than a VPN, their built-in next-gen antivirus stands at the forefront of your digital defenses. Anti-scam protection, anti-malware, anti-tracking privacy features, scam call filtering. NordVPN gives you that ongoing layer of protection operating in the background. To get our exclusive discount on your NordVPN plan, go to nordvpn.com slash restisclassified. It's risk-free with Nord's 30-day money-back guarantee.
1:20Gordon Corera:That's nordvpn.com slash restisclassified. The links in the episode description. For adults with Crohn's disease or ulcerative colitis symptoms, every choice matters. Tremphaya offers self-injection or intravenous infusion from the start. Tremphaya is administered as injections under the skin or infusions through a vein every four weeks, followed by injections under the skin every four or eight weeks. If your doctor decides that you can self-inject Tremphaya, proper training is required. Tremphaya is a prescription medicine used to treat adults with moderately to severely active Crohn's disease and adults with moderately to severely active ulcerative colitis.
2:00Gordon Corera:Serious allergic reactions, increased risk of infections or lower ability to fight them and liver problems may occur. Before treatment, get checked for infections and tuberculosis. Tell your doctor if you have an infection, flu-like symptoms or need a vaccine. Explore what's possible. Ask your doctor about Trimphia today. Call 1-800-526-7736 to learn more or visit trimfireradio.com. Hey parents, how do you make smarter choices for your kids' college today? That's where Sally can help. With Sally, you can find scholarships, funding options, tools, and guidance all in one place. And if you need a loan, Sally has options for different families and different situations.
2:44Gordon Corera:College is only worth it if you do it right. So don't just help your kid go, help them go smarter.
2:54A COVID action has been launched against Iran's nuclear programme, but this time on The Rest is Classified, we look at how the Obama administration decides to accelerate the targeting of Iran's centrifuges in a way that ultimately leads it to going out of control.
3:18Gordon Corera:There was no consensus within the Obama administration about how these weapons should be used. Even while Obama was approving new strikes on the Iranian nuclear plant, he harbored his own doubts. In meetings in the Situation Room in the first year of his presidency, Obama had repeatedly questioned whether the United States was setting a precedent using a cyber weapon to cripple a nuclear facility that the country would one day regret. This was, he and others noted, exactly the kind of precision-guided weapon that other nations would someday learn to turn on us. It was the right question, said one senior official who came into the administration after the Stuxnet attacks were over.
3:57Gordon Corera:But no one understood how quickly that day would come. Well, welcome to The Rest is Classified. I am David McCloskey. And I'm Gordon Carrera. And that is David Sanger writing in his book, The Perfect Weapon, about, of course, the Stuxnet virus, this effort by the allegedly, Gordon, I guess, the United States of Israel to disrupt and delay Iran's nuclear program. We have been looking over the last couple of episodes at the story of Iran's nuclear program and really some of the first concerted attempts to sabotage it and take it down, not with bombs, as we've seen recently, but with this cyber weapon.
4:38Gordon Corera:And last time, we looked at how the virus was kind of first unleashed around 2007, caused this massive confusion inside the Iranian program as nobody could really work out what was going on. Centrifuges that you so eloquently talked about, Gordon, sort of the scientific basis of how a centrifuge works. These centrifuges had been, of course, used to enrich uranium. They'd been more or less taken offline for periods of time by this cyber attack. And this program is about to take a turn as the Iranians speed headlong toward a bomb and the United States and Israel desperately try to stop them. The cyber weapon had first been unleashed in 2007 under the Bush administration.
5:21But by the time you get to 2009, President Obama is taking office and there is a handover, which I'd love to sit in on, by the way, one day, of all the secret operations that are underway. The really secret stuff that only one president can brief another president about. And I think at this time, one of those secret operations that are underway is this one called Olympic Games. That's the code name for it. The virus itself will become known as Stuxnet. And it's interesting because President Bush explains the program and personally recommends to President Obama that he should keep it going because it's working, because these Iranian centrifuges are blowing up.
6:00Gordon Corera:You bring up a good point, though, which is that the program itself, this virus, this weapon, has come to be known as Stuxnet. But nobody inside the United States government at this time would have called it that. This would all have been done under this Olympic Games sort of covert action program. Like literally nobody would have called it Stuxnet. It's a name that will be given later by the people who research it out in the wild, rather than the actual kind of teams behind it. But it's interesting because President Obama is going to be very interested in this program when he takes office in 2009.
6:32And very focused on it, the briefers bring out something called the horse blanket, which is a giant folding map of Iran's nuclear program. So he could see, you know, what was being done to different centrifuge cascades in the towns and decide on next steps. And it's compared to President LBJ looking at maps of bombing targets in Vietnam. You know, then it's about where do you want to bomb, Mr. President? Here it's which centrifuge cascade, you know, should we go for and how should we go for it using a cyber weapon? But it's the same kind of thing with a briefer showing this map to the president.
7:08What's on the map? Is it just pictures of the facilities or like? I'm imagining it. It's, you know, we talked in the very first episode of the enrichment facility beneath the ground in Natanz, the one they're building, which got room for 50 ,000 centrifuges. I'm guessing it's almost a map of that, maybe of other facilities as well. But saying these are where these different cascades of centrifuges are. And these are the ones we've already damaged and the Iranians are worried about. And these are the ones we think we can take out with a new update to the cyber weapon. I'm guessing that's what it is.
7:42But he's also worried. He understands, as we heard from that opening quote, that this is, you know, it's something new. And we'll come back to how new it is. But he understands there are risks to unleashing this kind of cyber weapon, but he is going to accelerate it. I mean, one of the reasons is that he actually wants to focus on diplomacy. And so back to that idea of buying time, avoiding a military strike, and the Israelis pushing him into action or taking action themselves by buying time for diplomacy through the kind of covert action side.
8:13Gordon Corera:Well, that's interesting, right? I mean, you look at the sort of campaign Obama, and then compare that to what he did. There obviously was a sort of faith that developed in the administration about covert action, right? And honestly, I guess that is some of the allure of it is, well, it's pretty hard to conduct diplomacy if you're openly bombing a country. But if you're clandestinely, covertly sabotaging its nuclear program and they don't even quite know what's going on, that doesn't exactly rule out diplomacy. You can sort of walk and chew gum at the same time. So I can see why it would be alluring.
8:52Gordon Corera:Although 2009, of course, it's a pretty big year inside Iran. Yeah, it is. I mean, President Obama's tried to send a message, I think, in March 2009, just a really unusual message to the Iranian people kind of holding out the hand of friendship and sends private letters. And he kind of, they get rejected. Nothing happens. But I think he knows that. But he feels he's got to try and open this diplomatic front. But you're right, you know, 2009, big year inside Iran because you have the protests against an election which Iranian people believe is rigged. and they come out on the streets famously in this big movement.
9:26The Green Movement. Yeah, which is a big moment for Iran when people thought, could this topple a regime? And it's interesting because President Obama doesn't support them. He doesn't come out and give a statement of support. He doesn't say the elections are rigged. And I think some of the people around him will later say this is a regret for them, that they didn't side with the protesters a bit more. But I guess it's always that problem that if you side with them, then it allows the regime to say, well, you're all just, all the protesters are basically CIA puppets and being manipulated. So yeah, it's a difficult balancing act.
10:00But yeah, there's a lot of change going on, I think, within Iran at that moment and challenge.
10:05Gordon Corera:And I guess also an acceleration of the nuclear program at the same time, right? Because there's more and more centrifuge installation, which you need to get to the quantities of enriched uranium for a bomb. And then also, and I remember, I wasn't covering Iran at the agency at this time, but I remember in September of 2009, Fordow, a site that had just been bombed, was found and I think publicly revealed for the first time. Yeah, and that was a really big deal. I remember it as well, because you had a lot of Western leaders stand up together and say, we are going to reveal to the world that Iran has another secret site at Fordow.
10:46It's really interesting, the backstory to this, because I think they'd known about it for some time. This had been a revolutionary core guards kind of base. And Fordow, we should say, people might know about it because they've seen it in the news recently. It's a mountain, you know, it's a mountain which has been tunnelled into. And I'm pretty sure that it was a walk-in. Maybe even on the British as well as American side, it's all very secretive, but at first kind kind of tip them off about Iran building another secret nuclear facility. And this is absolutely crucial to the story and obviously to what's happened recently, because we've been talking about Natanz, this place the inspectors had first visited in 2003, where they're building the centrifuges.
11:27But now suddenly it's being revealed that Iran had secretly also been building another enrichment facility, covertly, without telling anybody again, and doing it in a mountain. It's a bad look. And the point is, that's a bad look. For your peaceful nuclear program, yeah. Because Natanz is like 30 feet below ground or something like that. This is hundreds of feet below kind of rock and concrete. So it's a completely different target. It's interesting. There was, in some of the books about this, there's references that the end of the Bush presidency, where they'd first learned of it, there'd been some discussion about whether they could actually send a special forces team onto Iranian territory to try and sabotage it before it developed too much.
12:10But they obviously decide against that and have a hugely risky operation to try and do. So instead, they reveal it to the world in September 2009 that this new enrichment facility is being built. And that then creates another big debate about the nuclear programme because the Israelis fear that Fordow gives them a kind of zone of immunity where free from inspections, deep underground, Iran can quickly move towards a bomb and they won't have the intelligence or advance warning that they're doing this breakout that we talked about and making that final push towards a bomb. So as you get to 2009, there's lots going on.
12:48And Israel is also upping the pressure on the US as a result. And it looks like they're kind of thinking, what else can we do to delay the Iranian program? Assassinations will come back onto the agenda. So 2009, 2010 is a big period of pressure. And that's why it looks like there is this decision to accelerate Olympic Games, to push it, to take it up a level, even from what it's been doing before. And so taking it up a level in this context looks like targeting more of the cascades more
13:22Gordon Corera:frequently. I mean, there's this balance, right? Now that you've got this, I mean, access, right? You don't want to lose it. And so you have to be careful how frequently you mess with them, because if you just are constantly doing it, eventually they might find the code, they might discover that this is actually foreign actors doing this. So you run a great risk, I guess, if you up the frequency or you start to target other pieces of these sites. And I guess that's the decision making and the debate which must be going on at the highest level. The horse blanket. That's why you're pouring over the horse blanket.
13:56I guess that is the point of the horse blanket, isn't it? It's going, okay, if we could take down these centrifuges by upping our game, but there is a risk that it will get discovered or that something will happen which will blow the program. But they're going to up the game. So the early attacks that we talked about from 2007, it's thought they target the valves which let the uranium gas in and out of the machine. So this new set of attacks from around 2009 is instead going to target the frequency converters, which supply power to the centrifuges. back to our centrifuge lesson very delicate have to spin at the right speed the power has to be maintained precisely to get them to spin at this supersonic speed so if you mess with that power supply and with the power being delivered into the centrifuges you can slow them down you can speed them up you can mess with them and you can put kind of strains and stresses on on the systems by making them spin faster and slower.
14:58So that's what the new code looks like. The best account, by the way, of all the detail of how the code worked is in Kim Zetter's book, Countdown to Zero Day on Stuxnet, which is a brilliant book, which really gets deep into this, and I'd really recommend that. But again, what they do with this new set of code is they record what normal operations look like and feed it back in when the attack's underway so no one would spot anything. So for 13 days, there's a recon stage. where the code sits on the programmable logic controller, the thing that controls the power supply, recording the normal operations.
15:33When it's got enough data, it moves to an attack phase, two-hour countdown. Then it targets the frequency converters, which deliver the power for 15 minutes, slows down, speeds up the centrifuges, does it for just 15 minutes, and then goes back to normal. I mean, it's wildest. And then it waits for 26 days while recording normal processes again, and then goes back into another attack cycle, this time for 50 minutes rather than 15, and then alternates this 15-50 minute attack cycle over 26 days. So it's really interesting because, again, it's so precise because what they're trying to do is introduce stresses on the materials inside the centrifuges.
16:15So they're not just like switching off the power or speeding it up to the point where the centrifuges crash. They're stressing the centrifuges so that they break. I mean, again, it is just amazing the amount of research and understanding of how these centrifuges work and what you can do with them in order to develop code to do it that precisely and to know you'll have an impact. I just think it's amazing when you think about it.
16:41Gordon Corera:I love this quote that you put on here, Gordon, which I think really captures it well. It says the attackers were in a position where they could have broken the victim's neck, but they chose continuous periodic choking instead. And I guess at this point, they've been in Natanz for a few years messing with it, right? I mean, which is also incredible is that they've just sort of been slowly sapping this facility's productivity, right? For years at this point. And I guess maybe there's a good chance to take a break. When we come back, we'll see how this choking starts to get even tighter. See you after the break.
17:19Gordon Corera:Hey, this is Michael and Hannah from Goal Hangers. The rest is science. This episode is brought to you by Cancer Research UK. When we talk about beating cancer, we often focus a lot on survival. And that can mean overlooking impacts that last long after treatment ends. Yeah, for example, take cancers in children and young people. The treatments themselves can be incredibly harsh. They can cause lifelong side effects like infertility or hearing loss. And Cancer Research UK is working to change that because young people, they should be able to grow up hearing the voices of the people that they love and living their lives to the fullest.
17:54Gordon Corera:That's right. And one clinical trial led by Cancer Research UK showed that giving another drug alongside chemotherapy nearly halved the number of children losing their hearing. And today, the treatment combination is being used by doctors across the world. For more information about Cancer Research UK, their research and breakthroughs, and how you can support them, Visit cancerresearchuk.org slash rest is science.
18:44the way. WISE keeps things simple. WISE is a smart way to move the currencies you need around the globe. It works in more than 160 countries and with over 40 currencies. Most transfers arrive instantly. WISE uses the mid-market exchange rate, like the one you see on Google, with no markups or hidden fees. So when money needs to move, you can see the rate, know the fee and get on with it. Join millions saving billions on hidden fees by downloading the Wise app today. Be smart. Get wise. T's and C's apply. Evening. Buyer's remorse.
19:21Gordon Corera:Buy a new car? I'll be moving in. Let's get started. Sorry, I think there's been a mistake. I bought it from Carvana. You what? Yeah, great price. I even have seven days to love it or return it. So there's no... No, no buyer's remorse. More like buyer's rejoice. I guess I'll let myself out. Congratulations. I mean it. Buyers rejoice. Buy your car today on Carvana. Limitations and exclusions may apply. See our seven-day return policy at Carvana.com.
19:52Gordon Corera:Well, welcome back. It is December of 2009, early 2010, and Gordon, now we've got the return of our good friends at the IAEA, The International Atomic Energy Agency, who are going to be this dance of inspectors coming into Iran and trying to get access to facilities. We're back to this. We're going to have inspectors crawling around, looking at Natanz, looking at Fordow, all up in the Iranians' business while Stuxnet is going on in the background. I love the idea of inspectors. It makes it sound like, I imagine like kind of Inspector Clouseau with like a magnifying glass. Definitely. They definitely have clipboards, a lot of clipboards and magnifying glasses.
20:32Gordon Corera:I don't think that's what they really like. I think they have like kind of high tech samplers, but I just think this idea of international inspectors. But yeah, they're visiting the site late 2009, 2010. They can see the Iranians are replacing centrifuges at a faster rate than normal, that some of them are getting damaged, that they don't know what's going on. It looks like the Iranians are firing some of their engineers and they're running tests on the motors to find out why the speed's changing. It's this whole confusion they've got, but they're still pressing forward. So in early 2010, it looks like US and Israel, who we assume are behind this, decide, as people say, to swing for the fences, which I guess is a baseball thing.
21:14That is a baseball thing. It's a baseball thing. I was trying to look at that because I read that in Kim's book. I was thinking, swing for the fences, you know, just take a big shot to get the home run. Am I getting the language right? You're going for the home run, trying to clear your base? I don't know. Anyway, I never understand baseball.
21:27Gordon Corera:What you said there isn't technically wrong, but it doesn't sound right. You would not go for the home run as an example. Okay. But the other analogy I like is that they supersized the virus, which is like you're going to your McDonald's and you say, I want the big Mac meal. I supersize it. So it's like a virus to go after. And they're going to supersize it to go after a specific array of a thousand centrifuges. Now, here is the thing. They're going to be more aggressive. They want to move fast. So they're upping their game and they still have this problem, which is getting over the air gap to get into the systems.
22:06So you want to get your new virus into the systems to do the damage. And of course, as we said before, these systems are not connected to the regular Internet. And previously they'd used flash drives, giving them to lots of people, hoping they get in and then they spread. Now they're going to slightly change, it looks like, the delivery mechanism for the virus. And they're going to use what's called a worm. And the point about computer worms is they self-propagate. They spread by themselves. And this has been something that's known about for years, that you can do this with computer worms. And some of the earliest computer worms are fascinating.
22:42There is a great story about, I won't do the whole story here, about the Morris worm, which is the first computer worm, November 1988, where this student wants to test how far he can spread a worm. So he launches it. I think he launched, he goes to MIT to launch it to try and hide his tracks, even though he's not an MIT student. And it spreads and it basically takes down the entire Internet because he's made some of his worms, basically what are called immortal worms, which won't die. And they spread and immortal worms are bad and they spread anyway. And so it takes down the Internet. But here is the bit I love about the Morris worm story is one of the people who gets a phone call to say it's a problem is the chief computer scientist at part of the NSA, America's Signals Intelligence Agency, who works for the National Computer Security Center.
Read the full transcript
23:30And his name is Robert Morris. And it turns out it's his son who's unleashed the worm. And you always think, that's a bad day in the office when your son, when you work at the NSA, and your son has taken down the internet.
23:44Gordon Corera:Like father, like son, though, Gordon, come on. Exactly. He's an expert. But that is the point about worms. Why are they self-propagating though? That's an inherent feature of the code that makes it a worm? Yeah. That is why it's a worm rather than a virus, because it spreads by itself. You don't need to just infect a host like a virus, but the worm, this is the idea of it in computer speak, in cyber speak, is that it will move from machine to machine by itself. So it's got a life of its own, effectively. That's the idea that you get it onto the network somehow, and then it can spread around the Iranian network machine to machine, even in their local network, until it finds a way in to the centrifuges you want to hit.
24:31But the crucial thing is it's still very targeted in terms of what it's trying to actually do and who it actually unleashes its payload on.
24:41Gordon Corera:Is the hope in this kind of new phase that they will reach other facilities? Is it we're trying to get beyond Natanz to get into Fordow or like just different pieces of the cascade at Natanz? I think it's more that pressure to up the game, to get to the centrifuges you want. And knowing that this could take quite a long time to get to them. and it could take quite a long time through the previous methods before the right USB hits the right computer, which is connected to the right computer. So instead you inject it into the system somehow through one person and then you just let it spread until, and this is the crucial bit, until it finds the exact system that it's looking for.
25:24And it's really interesting because it's really precisely engineered. We talked before, you know, these are programmed to look for Siemens logic controllers. But in this case, it is looking for a logic controller connected to a specific array of systems running Iranian centrifuges. And if that very specific combination of different software and hardware packages is not in existence, then the code just sits there and does nothing. It's quite interesting. It's really, again, the complexity of it is amazing because it's got to contact its kind of controller when it infects a new system. And whoever's designed this has set up fake football websites to act as the command and control server.
26:06So when it reports back... American football? No, I think it's proper football, David. Okay. Because the theory is that that will mask, if someone is seen checking football results websites, if that's spotted, it will just look like an engineer who's maybe checking how Real Madrid or someone are doing.
26:24Gordon Corera:Yeah, that would be bad if it was American football because I can't imagine there's too many Iranian nuclear engineers who are like, oh, let's go and check in on the Cleveland Browns scores today. So it's really precisely engineered. And if the exact conditions aren't met, it does nothing. It just, it doesn't release its payload. So it's so interesting because the whole aim of this is to avoid collateral damage to other systems. So to avoid it, hitting a different logic controller, a different industrial facility and activating. There's even, I mean, this is the next bit that's fascinating about it, an expiration date for it.
27:02So every time it infects a new machine, it checks whether it's after June the 24th, 2012. And if it is after that date, then it stops, doesn't do anything. So the whole thing is timed to self-destruct as well as only actually affect one single target machine. So you've got something which is going to spread across the Iranian network, but look for only one machine to be able to hit its target. And even then only last for a couple of years.
27:31Gordon Corera:which I guess does market as kind of a government program, right? Because you'd figure if this is actually a group of hackers or something like that, that you wouldn't figure an expiration date being built in. I think that, again, is one of the clues that will come out of the discovery of this virus, because everything about the way this is engineered is to be precisely targeted. and people I spoke to said, I remember I spoke to US Cyber Bazaar, a guy called Richard Clark, who'd done it. And he said, it just says lawyers all over it. Oh, I can't even imagine how many lawyers must have been all over this thing.
28:08Gordon Corera:I mean, every covert action program is just covered in lawyers anyway, right? And this seems, with all of the potential risk that this weapon might get out. Because when you put together a covert action finding, it's not a particularly complicated document to draw up. But you're, of course, one of the sections you're going to list is like, what are the risks associated with this, right? And I would think here, you not only have the risk that this thing gets out, right? But you also have a risk when you're if you're messing with an industrial facility, I guess you're taking a risk along the way that there'd be people who get killed in these accidents, Right.
28:48And so you're having to get a more elevated sort of authority to conduct attacks like this, even if the risk isn't particularly high, it still would have to be acknowledged as part of this.
29:01Gordon Corera:So you're going to have lawyers all over this thing, for sure. Yeah. And I think everything that you see about the code and the way it's designed suggests a real rigor and deep kind of oversight, accountability, lawyered process to put together that code. You can see someone going, if you're releasing something which can take down industrial facilities, then it absolutely has to be totally targeted so that it will definitely only affect one place and affect one type of system. And we want an expiration date so this doesn't last forever. You know, it doesn't kind of take down the whole world and, you know, kind of self-propagate in that way.
29:43So you can see, actually, I think it's really interesting with the precision of the delivery system and of the kind of restraints and constraints which are put around it, that this is the result probably of quite a lot of arguing and interagency meetings. And you can imagine, and we don't know the detail of it, but you can imagine President Obama going, I'm only going to sign this off, this more aggressive attack, if I know it's not going to take down Iranian electricity grids or neighbouring countries' electricity grids or come back to our electricity grids and take them down and do these kind of things.
30:18You could imagine that that will be the stipulation which is put on unleashing this new covert action, more aggressive covert action as part of the program.
30:29Gordon Corera:But of course, I guess you can put an expiration date on it and you can write up the legal kind of language, however you'd like. But the reality with a self-propagating computer worm is that you really have no control where it's going to end up. So at some point, presumably, spoiler alert, it's going to escape. Yeah. And I think the idea was it would just remain within this Iranian network of Natanz and look for the configuration it was after and then act. But... Oops. Oops. The problem with the self-propagating worm is that it's a self-propagating worm and you can't control where it goes. So just like, you know, Robert Morris, this kid in the 80s who didn't plan to crash the entire US internet at that time, there are unintended consequences when you release something onto the internet.
31:22And so it looks like, I mean, we can't know exactly what happens, but there must have been a moment where perhaps an Iranian scientist whose laptop had been infected with this worm then plugs into the internet, you know, with maybe the same laptop. And at that point, the worm escapes. I just have this vision of a kind of big, kind of cybery worm. It's a giant sandworm. A giant sandworm. Like in June. Yeah, like in June. Yeah. I just imagine it tunneling through a fiber optic cable going, I'm free. And it's free at last. Yes, free at last. And it's out. And it looks like it is a mistake in the code.
32:02It looks like there wasn't intended to get out onto the general internet. but it is going to escape all around the world. And so in the summer of 2010, suddenly it's appearing and it's appearing on machines, this bit of code everywhere. And it is the most sophisticated piece of malicious software any cybersecurity researcher has ever seen in the history of the world. And it's out there on all these machines. And yet it's not doing stuff to their machines.
32:32Gordon Corera:The one person who had their laptop connected to a Siemens PLC was shocked to see what was happening. And it's going to take them months to understand. But also in the White House as well, as soon as they realize this, which is in the summer of 2010, there is panic. There's an emergency meeting of top US officials in the Situation Room once they realize it's out in the wild. And it's really interesting because they agree that this isn't going to be secret for long. People are going to work out what it is. And so they're actually going to roll the dice again and give it another chance to do as much damage as possible before the Iranians work out what it is.
33:14So it looks like they actually at that point inject two more versions into the system to try and hit the thousand centrifuges they really want to take out. They're going to swing for the fences again as a kind of last swing. They're going for the home run. Before you get caught out. Is that what happens? Before they catch you out and they catch the ball? Is that a good analogy? No, that one doesn't work.
33:39Gordon Corera:But one question that I have is, so this virus, this worm, I mean, sat on computers inside the Iranian nuclear program now at this point for three years and wasn't discovered. Why is it that as soon as it gets out, it's seen right away? It must be something to do with that specific bit of code, because the original code was also really carefully designed to be encrypted, to also not show up when you do a kind of virus scanning system, to be hidden in all those ways. But at this point, it is out. It is a larger bit of code than anything that's ever been seen before. And it is starting to sit on systems.
34:22And on some systems, it does kind of muck around with them a bit. So in a few places, it doesn't quite switch them off. But you can start to see that there's a big block of code sitting on the system and doing something, even if you don't understand what it is. And so now the race is on because you've got the code unleashed, you've got the Iranians, perhaps about to realise that there might be a link between what's happening and the problems in their nuclear programme. and all these researchers in the outside world from the summer of 2010 trying to pick it apart and understand what's happening.
34:57So we are really reaching the final stages now of this COVID action.
35:01Gordon Corera:That sounds like a great cliffhanger, Gordon. To end our third episode on Stuxnet and Olympic Games and look toward the thrilling climax in which the US and Israel allegedly will double down yet again on the power of this cyber weapon and a whole host of cybersecurity researchers are going to start to unpack what exactly is this worm that has escaped and look at this kind of history-changing cyber weapon as it gets out into the wild. But of course, you don't have to wait for that episode. You can join the Declassified Club at therestisclassifiedatgoalhanger.com. get early access to all of these wonderful episodes get bonus content there's so many reasons to do it we hope to see you there and we'll see you next time see you next time
36:05Gordon Corera:hello look what tj max dragged in the devil wears prada 2 is now streaming on disney plus and hulu We are digital. We are downloadable. We are streamable. The fashion event of the year is certified fresh. Pull yourself together. We have work to do. Critics say it's smart and witty and the perfect sequel. That's all. Get runway ready for The Devil Wears Prada 2 on Disney Plus and Hulu. Rated PG-13.
From the publisher
What was the "horse blanket" and how did it guide Obama's decisions on cyber warfare? How did the Stuxnet virus evolve to target Iran's centrifuges more aggressively? And what were the risks and ethical dilemmas involved in unleashing such a powerful and precise cyber weapon?
Listen as David McCloskey and Gordon Corera delve into the Obama administration's acceleration of the Olympic Games program, the sophisticated targeting mechanisms of the Stuxnet virus, and the increasing pressure on Iran's nuclear ambitions.
-------------------
To sign up to The Declassified Club, go to www.therestisclassified.com.
To sign up to the free newsletter, go to: https://mailchi.mp/goalhanger.com/tric-free-newsletter-sign-up
-------------------
Get our exclusive NordVPN deal here ➼ nordvpn.com/restisclassified It's risk-free with Nord's 30 day money back guarantee
-------------------
Order a signed edition of Gordon's latest book, The Spy in the Archive, via this link.
Order a signed edition of David's latest book, The Seventh Floor, via this link.
-------------------
Email: classified@goalhanger.com
Twitter: @triclassified
Assistant Producer: Becki Hills
Producer: Callum Hill
Senior Producer: Dom Johnson
Exec Producer: Tony Pastor
Learn more about your ad choices. Visit podcastchoices.com/adchoices




