71. Israel Attacks Iran: The Dawn of Cyber Warfare (Ep 4)

5 Aug 2025 · 44 min · 17 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Episode topic: The Stuxnet worm’s exposure in 2010 and what it meant for the US-Israel “shadow war” against Iran’s nuclear program—cyber sabotage crossing into physical destruction, plus subsequent Iranian retaliation and later escalation in cyber/critical-infrastructure attacks.

Guest backgrounds

No separate guests appear in this episode; hosts David McCloskey and Gordon Corera discuss prior interviews and cite experts/researchers including General Michael Hayden (ex-NSA/CIA), Eugene Kaspersky (Kaspersky founder), and Symantec researchers Liam Amurcu and Eric Chen; industrial-control expert Ralph Langer; UK NCSC head Kieran Martin (mentioned).

Key claims

Stuxnet was covert US-Israel sabotage that affected centrifuges at Natanz; its release into the wild enabled global analysis and forced Iran to clean/defend. The code’s sophistication (including multiple zero-days and stolen certificates) suggests state-level capability. Timing links Stuxnet’s exposure to renewed Israeli assassinations. Cyber attacks can “buy time” but don’t end nuclear programs.

Notable examples

Natanz centrifuge slowdown/possible ~1,000 centrifuges hit; 2012 Aramco wiper with burning American flag; attacks on banks/websites; 2015 Russia turning off Ukraine’s power grid; 2017 WannaCry (NSA-derived tools repurposed) and the NHS impact.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

The Evolution of Cyber Warfare

1:46 to 2:49

Discussion on the historical significance and implications of Stuxnet as a cyber weapon.

“And that, Gordon, is an interview that you did.”

Discovery and Reaction to Stuxnet

2:50 to 4:00

Exploration of how cybersecurity experts discovered Stuxnet and its global impact.

“And where we left last time was that this code, this worm has broken out into the wild.”

Zero-Day Vulnerabilities Explained

4:01 to 6:04

An in-depth explanation of zero-day vulnerabilities and their importance in cyber attacks.

“He says he decided not to speak out in case it gave attackers the idea.”

The Sophistication of Stuxnet

6:05 to 8:03

Discussion on the unprecedented sophistication of Stuxnet and its unique features.

“Normally, attackers build on existing tools and code, but this is different.”

Implications for Cybersecurity Researchers

8:04 to 9:30

Insights into the challenges and paranoia faced by researchers analyzing Stuxnet.

“And then, you know, they're not experts on industrial control systems, but you get experts like Ralph Langer, who is an expert, who suddenly goes, okay, this could be used to attack centrifuges.”

The Blame Game Post-Discovery

9:31 to 11:02

Analysis of the political fallout and blame shifting that occurred after Stuxnet's exposure.

“All that kind of stuff is happening to these cybersecurity researchers as they're publishing it.”

International Involvement in Stuxnet

11:03 to 14:00

Discussion on the potential involvement of other nations in the Stuxnet operation.

“And it's starting to become obvious who was behind it.”

The Role of Countries in Cyber Warfare

14:00 to 18:42

Explore the involvement of various nations in the cyber conflict with Iran.

“because this is the kind of stuff we'd expect the Americans and the Israelis to do.”

Assassinations and Cyber Warfare

18:42 to 19:05

Discuss the implications of Israel's assassination strategy in relation to cyber operations.

“And when we come back, we'll look at all of this and what it means for the Iranian nuclear program, what it means for cyber war, and I think what it tells us about the most recent batch of strikes.”

Iran's Cyber Response and Attacks

19:05 to 22:49

Learn about Iran's retaliation through cybersecurity measures and attacks.

“And I guess the question now, Gordon, is what in the world are the Iranians going to do about all this?”
Show all 17 chapters

The Complexity of Cyber Attacks

22:49 to 28:00

Understand the challenges and complexities behind executing successful cyber attacks.

“You know, this idea of cyber sabotage below the threshold of war, gray zone attacks make cyber tempting.”

Stuxnet's Complexity and Impact

28:00 to 29:29

Explore the intricate planning and challenges behind cyber weapons like Stuxnet.

“The amount of recon and intelligence work which went into Stuxnet, I think, is enormous.”

The Ongoing Iranian Nuclear Program

29:30 to 31:06

Discuss the resilience of Iran's nuclear program despite Stuxnet's impact.

“And it is interesting because when you look at the damage inflicted by the virus, you can't really measure it.”

The Shift in Approach Towards Iran

31:07 to 33:10

Analyze the changing strategies in dealing with Iran's nuclear ambitions over the years.

“He doesn't want either an Iranian bomb or a war.”

Recent Covert Operations Against Iran

33:11 to 34:51

Examine recent covert actions and their implications for Iran's nuclear program.

“I got an email in my inbox from a group calling itself the Homeland Tigers.”

Israel's Current Strategy and Calculations

34:52 to 37:35

Understand Israel's military strategy concerning Iran's nuclear capabilities.

“And up to the point of these most recent strikes.”

Consequences of Attacks on Natanz

37:36 to 39:27

Discuss the implications of attacks on Iran's Natanz facility and future prospects.

“it starts to look like a much better option for the Israelis, right?”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:03Gordon Corera:For exclusive interviews, bonus episodes, ad-free listening, early access to series, first look at live show tickets, a weekly newsletter, and discounted books, join the Declassified Club at therestisclassified.com. Hey parents, how do you make smarter choices for your kids' college today? That's where Sally can help. With Sally, you can find scholarships, funding options, tools, and guidance all in one place. And if you need a loan, Sally has options for different families and different situations. College is only worth it if you do it right. So don't just help your kid go. Help them go smarter.

0:42Gordon Corera:sally.com slash go parents.

0:53Gordon Corera:It would be irresponsible for someone of my background to even speculate. But it's not speculation to know that someone just used a cyber weapon to affect damage, not in the cyber domain, but in the physical domain. That's the first significant crossover that we've seen. Now look, I tell audiences that crashing a thousand centrifuges at a time is almost an unalloyed good. But when you describe what just happened there in a slightly different way, someone just used a cyber weapon during a time of peace to affect physical destruction in what another nation would only describe as critical infrastructure, well, you've got to realize that although that was a good deal, it was also a really big deal.

1:31Gordon Corera:And it does have second and third order effects. A new class of weapons has been used. Go deeper into history and say somebody's crossed the Rubicon. We've got a legion on the different side of the river now. Well, welcome to The Rest is Classified. I am David McCloskey. And I'm Gordon Carrera. And that, Gordon, is an interview that you did. Those are not your words, but those of General Michael Hayden, former director of the NSA and the CIA, in an interview with you back in 2013, not taking responsibility for Stuxnet, but commenting on the sort of world-changing implications of this cyber weapon.

2:12Gordon Corera:And we are now, dear friends, in the final episode of our series on this really first attack on Iran's nuclear program. And the US and Israel have unleashed this code, which has come to be known as Stuxnet, which has targeted Iran's very precious centrifuges with this kind of remarkable precision and sophistication. And the Iranians, now it's been three plus years at this point of this code working its way through largely this facility, this enrichment facility at Natanz. And things have been breaking. Machinery has been slowing down. And where we left last time was that this code, this worm has broken out into the wild.

3:03Gordon Corera:And cybersecurity researchers in Europe and the States are starting to see really all over the world are starting to see this code appear on their computers. and at the same time the US and Israel allegedly are stepping up the game to try to bring even more pain to Iran's nuclear program. That's right the secret is out by the summer of 2010 and this code which was designed to be covert is now being found on machines around the world. It's not shutting them down because then it's not designed to but it is visible and people can start to look at it. I remember talking to an interesting chap called Eugene Kaspersky soon after.

3:44He's the flamboyant Russian founder of the antivirus company Kaspersky. It's named after him. And he remembers his team coming into his office and saying, we've been waiting for something like this to happen. Well, it's happened. Kaspersky says he'd been worried about an attack on physical infrastructure using code since 2002. He says he decided not to speak out in case it gave attackers the idea. That was until he realized the cat was out of the bag. when he saw the film Die Hard 4, Live Free or Die Hard, in which Bruce Willis battled cyber terrorists, which I should say is one of our producer Callum's favourite films, he was saying earlier, and suggesting that we should basically have just kind of talked about that film for the whole of this series.

4:26Could be a bonus episode. Could be a bonus episode. Thank you, Hollywood, Kaspersky says, when that film comes out in 2007. Because, you know, it's not entirely realistic, but it is the idea. Oh, it's not? Yeah, I think the cybersecurity aspects of it may not be perfect. But there's a concept. It's a good example where Hollywood does get things right. Because as a concept that hackers could take down physical infrastructure, it is right. But now it's for real. You know, now in 2010, it's for real. Because Kaspersky, other cybersecurity researchers have basically got a cyber missile in their hands.

5:04and they have never seen anything so sophisticated. And it's so interesting what happens in the next few months because you see this kind of hive mind of cybersecurity researchers go into action. And I've watched it lots of times since then where it's often done on social media platforms. It used to be mainly on Twitter and X where people are saying, I found this, I found that. And they're starting to publish, talk about what they're finding. Often, you know, one person's an expert on one bit of code, one's on another, but they're starting to piece it together collectively this group of cyber security researchers sometimes just work for tiny companies sometimes they work for the big big companies best book on this mentioned it before kim zetta's countdown to zero day because that goes through the process of discovery as people are trying to look at the delivery system the missile as well as the payload of the code that was in it.

6:00And they can see that this is completely different from anything they've seen before in sophistication. Normally, attackers build on existing tools and code, but this is different. It's completely original. Two particular individuals, Liam Amurcu and Eric Chen of Sementech, see a kind of series of really unusual elements to this. I mean, one of them is that it's going to use this attack for what are called zero days, bit of jargon, but a zero day gets its name because it's an undiscovered vulnerability in a piece of code. So normally you say it's four days since this has been patched. A zero day, there's zero days since it's been patched because it's not been patched.

6:40There's not a solution to the vulnerability. And therefore it's incredibly valuable, a zero day, because it is a way that's not yet been discovered to get into a system.

6:49Gordon Corera:Well, and it's actually a product, right? I mean, And it's something that, if discovered, can be sold effectively. Yeah, a zero day is really valuable. There's a market for zero days where people who find them, who look for vulnerabilities, then sell them. You can sell them back to the company, to Apple or Google or whoever, and they'll pay for them. Or you could sell it on the black-gray market to people who want to use the vulnerability maliciously. And the fact that they've got four zero days in this, that is unprecedented. Because why would you need four in one system? It's because this virus is getting into different systems.

7:26And someone could have sold those for money. So immediately you're like, this is not criminals. No criminal hacker would be investing this much time and using this much code. It's stolen legitimate digital security certificates from a company, I think, in Taiwan. It wasn't faked. It was real. Again, that is high end. But they can also see these researchers from Symantec. When they map the location of where the infections have happened, of the 38 ,000 machines they tracked, more than 22 ,000 were in Iran. So you can already see, like, this is a very sophisticated code, and it's really interested in Iran.

8:05It loves Iran. It loves Iran. And then, you know, they're not experts on industrial control systems, but you get experts like Ralph Langer, who is an expert, who suddenly goes, okay, this could be used to attack centrifuges. Centrifuges are in Iran. People start publishing online in research papers. Some of the details of this takes a while because people can't quite grasp what it is. So it's taking months really for people to piece it together. And this is, by the way, where it gets the name Stuxnet. What is that a reference to? I think it's just a tiny reference in some of the drivers and the code to Stuxnet.

8:42And that often happens. People just will pick out something and they'll just call it that because it looks like a unique name. I always find it interesting with these cyber researchers because they are, at this point, exposing what they must realize is a nation-state espionage program. And you're a private cybersecurity researcher and you are making public or publishing details of a covert action program. And I think you can sense some of them are, it's not that they're nervous about doing it because they think they have a duty to do it because there's a risk to systems from this and from all these vulnerabilities which have been found.

9:21But they're worried, you know, are they going to get spied on? Is this going to have some implications for them? It's kind of interesting. And they get a bit paranoid. You know, they're starting to check under their cars for bombs. You know, they're worried about being tailed. I mean, they really are. They're hearing clicks on phones. All that kind of stuff is happening to these cybersecurity researchers as they're publishing it. They think the CIA are onto them. They're in a Jason Bourne film, basically.

9:43Gordon Corera:I understand why you would be paranoid, but I find it highly implausible that cars were beaconed or that anyone was followed or anything like that. I just don't. I don't see it. If you were a cybersecurity researcher, you probably would get a lot of other international spy agencies hacking into your systems to see what you're discovering and what you know, though. So I could imagine Cybris being... Oh, yeah, that would be fair game of like, Like if you're running a cybersecurity firm somewhere in Europe or in Russia or something, yeah, I mean, there could be an interest in learning what you know about it.

10:18Gordon Corera:Although the reality is, from an American standpoint, hypothetically, you already know what this thing is. So you have to assume, I think, once it's out in the wild. I mean, this is why we set up that wonderful cliffhanger, Gordon, at the end of the last episode, where, I mean, once it's out, you have to assume, I think, that you're running on sort of borrowed time and that you just have to use this thing inside Iran as much as possible before it comes out. Collecting on the cybersecurity research actually doesn't seem particularly valuable to me, to be honest, because you're like, well, it's out.

10:50Gordon Corera:We know what this is. They'll piece it together. They'll discover eventually that the target is the Iranian nuclear program. So we just got to work with the time we've got and do as much damage as possible before this thing comes to light. And it's starting to become obvious who was behind it. And there are interesting clues in the code. One has a string of numbers that look like a date. I think it's 1979-0509. And it was the day the researchers realised that a prominent Iranian Jewish businessman was executed by firing squad in Tehran shortly after the Islamic Revolution for allegedly being a spy.

11:25Now, it's interesting, isn't it? Because you find a date like that in the code and you go, well, that's an interesting date. Is it a clue that the Israelis are behind it? Is it a false trail someone else has left? I always find it interesting because people do leave these Easter eggs and these little clues in code and code writers love doing that. I always find it interesting. It's like a game that they're just showing off or leaving a trail for people to follow. There's another word, Murtas, appears in a file name, which in Hebrew was a link to the name Hadassah, which was the name of a biblical figure, Esther, who married a Persian king and saved the lives of Jews when she pleaded for their lives after learning of a plot to kill them all.

12:02Again, you know, all of that is starting to point perhaps towards Israel, as well as perhaps towards the US. And in the US, meanwhile, there is a blame game, unsurprisingly, about the fact that it's getting exposed. I find that maybe unsurprising in Washington. That seems unsurprising, yeah. But yeah, the briefing afterwards will all be, it was the Israelis' fault. It's kind of interesting.

12:26Gordon Corera:What's the logic there, that it was the Israelis' fault? The logic is that they had rushed and that the code was somehow sloppy, and that sloppy code had been put in, which had allowed it to escape and therefore get discovered, and that the Israelis had done some modification to the code, maybe to speed up the propagation of the worm or make it more likely to spread. And there's some questions about whether the US were part of that, were cognizant of it, whether the Israelis did it themselves. But of course, that's the briefing from Washington, much easier to blame someone else. But by the point of November 2010, it's out there.

13:03And a few months after its first in the wild, the finger is pointing pretty clearly because of some of the back history of some of the code and some of the things they can find in it, that it's the US and Israel.

13:15Gordon Corera:What about the Brits, Gordon? I feel like most of our series, you throw the Brits in, even when they're not invited to the party. You think about who might have been involved in pieces of this. It would seem reasonable to assume that GCHQ or SIS would have played some role somewhere, just thinking about the closeness of the relationship in particular with the Americans. How would I put it? I find it plausible. I remember talking to one very senior British intelligence official at the time, and they said they were not surprised when Stuxnet happened and was revealed. And that's a wonderfully ambiguous statement, isn't it?

13:55Because you can be not surprised because you were part of it. Or you can be not surprised. You can be not surprised because this is the kind of stuff we'd expect the Americans and the Israelis to do. I get the sense that they were at the very least aware of it. And there are some indications from some of the early espionage code, there might have been some British involvement in that. There's actually some really interesting suggestions from our friend Edward Snowden's documents that there have been perhaps some British role in the espionage bit. So what I, I don't know what you think, David. My instinct is that other countries may have been involved in this, but definitely US-Israel at the core.

14:31I think the other countries may have been involved in kind of modular bits of Stuxnet. So we talked a bit about whether the Dutch had been involved in getting an engineer to plant one of the USBs, whether he knew what he was doing, whether the Dutch knew it was sabotage rather than espionage, question mark. But I definitely feel like others might have been involved, but maybe not at the absolute core of this.

14:55Gordon Corera:It also seems plausible to me. I mean, you look at two pieces of this shadow war, right? The assassination of scientists, and then the sort of cyber program to degrade and affect Natanz. And it's very easy for me to understand why on the assassination front, the Israelis are going it alone, right? There would be a lot of other countries that would say, nope, not going to do that, not going to have any part in killing civilian scientists. But then on the other side, on the cyber piece, I can see why there'd be a whole host of countries with real interest in getting involved in that program, right?

15:37Gordon Corera:Because it's not going to kill anybody. It's going to slow Iran's progress toward a bomb. And so I can see why, as that develops, there would be logical bits for other friendly intelligence services to sort of plug into to get access to reporting that they otherwise might not have and to take part in kind of slowing this down. So I think it seems likely to me that there's probably a whole bunch of countries outside of, allegedly, the US and Israel that are involved in different pieces of this. I mean, I don't know how big the group was, but I think it's probably not just the CIA and NSA and Mossad.

16:16Yeah, there might have been a few more people playing at the Olympic Games. But by the time you get to November 2010, cybersecurity searches have published material. And at that point, November 2010, technicians at Natanz bring the spinning centrifuges basically to a halt because they're aware of something's going on. and it does look like though and we'll come back to the kind of overall damage but it does look at that point the kind of swing for the fences has hit and maybe taken down about a thousand of those centrifuges but fascinatingly you know you mentioned assassinations there so november 2010 Stuxnet now exposed so it looks like that covert action is over that same month Israel assassinates a nuclear scientist in Tehran using a bomb planted by a motorcyclist to me that that confluence of timing is fascinating, isn't it?

17:06Because it does suggest that Israel, perhaps, assuming it's Israel, we all think it is, Mossad doing the assassinations, has basically gone, okay, that covert action is done. We may now need to up our game with going back to the assassinations and push that to kind of degrade the nuclear program. Because there had been a bit of a pause, hadn't there, in the assassinations. And that pause kind of tracks when Stuxnet is doing the most damage. To me, that feels a plausible argument. It's hard to know for sure.

17:37Gordon Corera:I think that would be just more evidence for the kind of hypothesis I laid out where the Israelis are doing the assassination stuff alone. There's a broader group that's doing Stuxnet. If Stuxnet is basically rolled up, the Israelis figure, well, okay, back to this blunter instrument, right, of trying to degrade the program. And it's really interesting because some of those cybersecurity researchers, you know, out in the private sector who'd been exposing Stuxnet actually say they feel physically sick when they hear about the assassination, because they are wondering, did their exposure of the computer code lead Israel to switch from using code to killing people?

18:15And I guess they, for them, suddenly realize, you know, they're computer researchers, cyber researchers, and they're dealing in matters of life and death, effectively.

18:24Gordon Corera:Sure. I mean, they can't possibly be held responsible for that. I think it is true, right? I mean, there's pretty solid arguments we've made based on the timing that the Israelis, precisely because the code got out, decided to go back to killing. And I guess maybe there, Gordon, let's take a break. And when we come back, we'll look at all of this and what it means for the Iranian nuclear program, what it means for cyber war, and I think what it tells us about the most recent batch of strikes. See you after the break.

19:04Gordon Corera:Well, welcome back. The Stuxnet worm is out in the wild. The Iranians know about it. And I guess the question now, Gordon, is what in the world are the Iranians going to do about all this? Yeah. So part of it is they start to clean their centrifuge program of the virus. unsurprisingly. Wipe it down. Get out the wipes and protect it even more, which is going to make it harder. But it's also Iran's going to hit back in cyberspace. They'd already built some cyber capacity, particularly actually to target that green movement, the protest movement around 2009, 2010. They built up cyber militias to do surveillance on their own population, because they were worried that social media was being used to organise them.

19:49But now they start to use some of their cyber capacity to go on the attack. Very interesting, 2012, so still a couple of years later, that summer, there's an attack on the Saudi oil giant Aramco, and 30 ,000 computers belonging to Aramco are crippled. They're wiped by something called a wiper. The code hadn't been executed quite properly, but a burning American flag appears as an image on some of those machines. Hmm, bit of a message. It didn't actually stop oil and gas production though i think that's one of the interesting things about it it damages the corporate network but it doesn't get to the controllers doesn't move into the physical the physical world exactly which is the key to stuxnet success and what makes stuxnet so unique is it moves from the corporate network or from a you know regular network onto the controllers so it's a show of force but it doesn't have the impact that stuxnet is going to have although it does freak out i think a lot of companies and i remember that at the time because they're all suddenly realising Iran is retaliating against companies rather than against Western states.

20:55And they then attack a whole load of banks and American banking websites. But again, it's not super sophisticated. They just take their websites offline for a couple of days by flooding them with traffic. So it's Iran hitting back. Everyone assumes it's Iran. They're not going to hit back by launching missiles. They're not going to block the Straits of Hormuz at this point, but they're going to fire a warning shot against companies, probably oil companies and financial companies, because they're imposing sanctions on Iran's financial and oil industry. So it makes sense. And it is a bit of a surprise, I think, in the West, because it shows Iran is capable of hitting back.

21:33There's going to be more of these back and forth between Israel and Iran. There's one attack on the Iranian oil and gas ministry computers, in which the song Thunderstruck by ACDC, which is a particular favorite of mine, is blared out at full volume on computers in the middle of the night, which that's a cyber attack I like. I've got sympathy with that. You know, a bit of ACDC. Maybe that could be our podcast theme song, Gordon.

21:57Gordon Corera:That could be one of our... Thunderstruck. Exactly. We'll have to see. I don't think Callum and Becky, our producers, are going to like changing the theme music. I don't think they're ACDC. It's too late. Yeah, exactly. Getting into all kinds of copyright issues. But I guess the point is that we're now moving into this era in which cyber attacks are picking up. Things are going to escalate in cyberspace. End of 2015, Russia turns off a Ukrainian power grid. So again, it's the using a cyber attack, but to turn off a power grid only for a few hours. But you're getting this movement of cyber into the real world in a limited way.

22:35And it's interesting. China, when it's accused of spying in cyberspace, they go, yeah, but you, the US, are the ones who militarized cyberspace first and introduced destructive cyber attacks. Not in one sense. They're right. You know, this idea of cyber sabotage below the threshold of war, gray zone attacks make cyber tempting. States start to move into it. And so there is this who crossed the Rubicon, who put the troops on the other side of the river first. It is the United States. Allegedly. Now, I think you can also say it would have happened anyway. Absolutely. You could see the vulnerability of these systems.

23:11And I find it hard to believe that the Russians would have gone, oh, we're not going to attack Ukraine. Exactly.

Read the full transcript

23:17Gordon Corera:We found a way we just won't, we won't be the first to do it. Yeah. Right. I think the conversation around the should here, to me, I don't know, isn't particularly interesting because it just seems inevitable that it would have happened at some point. But it is fascinating that when you think about what is the kind of modern day analog to the Manhattan Project, right? Or to the atomic bomb, I think there is a great argument to be made that it is Stuxnet. It is the first connection point, between cyber conflict and the physical world. Such as the Iranians taking down a Saudi computer network and putting up pictures of a burning American flag on the monitors, right?

24:07Gordon Corera:It's affecting outcomes in a world of atoms through, you know, bytes and zeros and ones, which is incredible. Yeah, I agree. I mean, it is that when Michael Hayden talks about having the whiff of August 1945, you know, in Hiroshima as being a good example, I think it is an interesting analogy. It's not quite the same. As he says, it's got a whiff of it. It's not a direct analogy. But it is interesting, isn't it? Because it is a bit like Hiroshima. The US is the first to use the atomic bomb. It's the first to develop it. It is different, I guess, because it's stealthier. It's more deniable than an overt use of military force.

24:46So in that sense, it isn't quite the same. And I always think cyber nuclear analogies are a bit of a mistake. But it is a big moment. I think it is the kind of crossing of a threshold, which is to say you can take down a piece of critical infrastructure outside of war with a cyber attack. I guess the only thing that I think is that it's really hard to do. You know, I think that is the key thing about Stuxnet, which I think is often misunderstood, is that this is not easy. And I think if there's one message from is that this took years and a bit like the Manhattan Project, it takes millions of dollars, years of effort and the best offensive hackers that the US and Israeli government and perhaps other governments have at their disposal in order to be able to do this one covert act and one act of sabotage.

25:37I find that fascinating.

25:38Gordon Corera:Yeah, it's not a bunch of people in a suburban basement eating Pop-Tarts, right? And figuring this out. This is a state level effort that's got a whole bunch of infrastructure and funding behind it. Although you have to figure the comparison to the Manhattan Project breaks down a little bit here, because I would figure that even though there are real barriers to entry, it's not as high as developing a nuclear weapon. It is more dangerous in that way because the marginal cost of chaos in this world is lower than in nuclear, I would think. No, that's true. And actually, one of the problems is some of that code can get out into the wild, and then people can repurpose it and use it.

26:19And that's one of the worries about Stuxnet is people are going to do that. Luckily, that hasn't happened, though, right, Gordon? No, no. But, well, there is another moment where listeners might be interested in that 2017, the UK NHS gets taken down by something called WannaCry, which is a really interesting story. And we should definitely do it at some point. Yeah, it's a good one. Because it's a North Korean hack, which gets out of control. But here's the interesting bit. The North Koreans are using cyber weapons stolen from the NSA. They end up in the wild and then they get repurposed by the North Koreans and take down Britain's NHS.

26:51I mean, you know, that is a wild story which shows that there is something about cyber which is it can be repurposed and get out into the wild. But I think there's a there's a good quote from Kieran Martin, who's the former head of the UK National Cyber Security Centre. His analogy is Stuxnet is like the moon landing, you know. So it's fake. Is it? Is it, Dave? You know what you mean, the wind blowing. We're back to tinfoil hats, David.

27:20Gordon Corera:I should say, if you're watching, I'm not wearing the tinfoil hat today. You're in your astronaut suit. Exactly. With the wind blowing on the moon. I think Kieran's point, and Kieran, I'll talk to you about this separately, paper. I think his point is not that Stuxnet was faked, but that it was really hard to do. And it takes a superpower like the US to be able to do it. And that you can't just repeat it whenever you want. And other countries can't kind of quickly do it. Because I think it goes back to all that research you had to do. You had to have the centrifuges. You had to build a copy of Natanz.

27:55You had to kind of work out what programmable logic controller would do it. You had to, you know, the amount - Have a horse blanket. You have to have a horse blanket. The amount of recon and intelligence work which went into Stuxnet, I think, is enormous. And maybe it overinflates what cyber weapons can do. Because, again, another story, when Russia invades Ukraine in 2022, everyone is expecting massive cyber attacks as part of it. And there are, but they don't really have as much impact as people had expected. And again, it just suggests doing the kind of targeted physical attack of a Stuxnet is really, really, really, really, really hard.

28:32It's just not straightforward.

28:34Gordon Corera:I mean, I think the perception, to go back to the diehard, the look for your diehard comparison, I think the perception is that the way that these attacks happen is that somebody has like a gonculator that basically... What is a gonculator? Exactly. It's a very powerful tool. It's a technical term. It's a technical term. You've got like, there's, you know, the bad guy or whoever, right? The spy service has like a gonculator that turns off things. Big red button. We can just turn off the electricity. We can just turn off all the water treatment plants. I think there's a sense that it's a little bit more blunt than that.

29:08Gordon Corera:And I think what hopefully we've shown over these four episodes on Stuxnet is that it's actually a really tailored kind of operation. And so it takes a lot of time and it takes a lot of effort and all of that, right? The problem is, of course, now 2010, it's over. And in the meantime, the Iranian program is still a nuclear program. They still have a nuclear program. Natanz is still there. What happened to that nuclear program, Gordon? What happened in the intervening years? And it is interesting because when you look at the damage inflicted by the virus, you can't really measure it. It's quite hard to measure.

29:40But the general view would be that it set it back definitely months, maybe years. It's a stretch. Some people say three years, but some people say three months. It's a wide range. It's a pretty wide range. It wouldn't seem worth it if it was actually three months. I agree. I mean, but the Iranians say, and they would say this, we've incurred some slight damages here and there, but we've been able to manage pretty well. That's what I would say if I were an Iranian.

30:05Gordon Corera:That's what you would do. We've managed through this terrible crisis and there's been no impact. That's what I would say if I were the Iranians. So it clearly had an impact. It took out at least a thousand centrifuges, it looks like. No one is, of course, sure. The IAEA inspectors are friends with the magnifying glasses. They can see that it's slowed them down. They can see where their magnifying glasses broke in centrifuges. So it's definitely had an impact. It has bought time, but not stopped it. It has not stopped it completely. And that was, I guess, always the point was buying time. And when you look at the decision making at the start, it was not, this is going to destroy the Iranian nuclear program.

30:44It was, we're going to buy time and we're going to do this unprecedented thing. We're going to do something which is potentially risky and which could have blowback, but we're going to do it to buy some time. And in a sense, it does buy time. And you can argue crossing the Rubicon is a big deal, but it's less of a big deal at that point than starting a war in the Middle East. It's back to Bush. I want a third option. He doesn't want either an Iranian bomb or a war. This was his third option. And for a while, at least, it buys them that time.

31:15Gordon Corera:First off, I have to say that if Stuxnet is running in some capacity from 27 to 2010, I find it hard to believe that the delay was only a couple months. Yeah, I agree. That seems implausible. I think we're probably talking about years, but you're right, that nobody could know. So that's one point. I think the second point is, it does seem like, and I guess draws it into the world we're in today where the US and Israel have just overtly hit Iran's nuclear program is that it's not actually plausible to think that any of these sort of sabotage operations would eventually convince the Iranians to just sort of pack it up.

31:57Gordon Corera:Yeah. Right? Like that seems like a bit of an out there idea. So you're always dealing with the reality that at some point, either you're going to have to let the Iranians get to a point where they've got a breakout capability, or you've got to hit the program militarily, right? Because you can't fully degrade the program with covert means, or you have to hope that there's some kind of political change in Iran, where, you know, the regime decides to stop the program, Like Gaddafi did. You're right. And Obama, we went back to where we were talking about previously, about him wanting to use diplomacy.

32:39And to some extent, he gets that because they get what's called the JCPOA, the agreement in 2015, in which Iran agrees to restrict its enrichment. So to kind of constrain the enrichment that's taking place. But then President Trump leaves the deal, says it's a bad deal unilaterally. So Iran then is back in business and starts to push forward again. And now it's harder to do another Stuxnet. You could maybe only do it once. And then it's interesting, isn't it? Because you do get some more covert action. You do get more attempts to do it. I mean, I remember getting an email on July 1st, 2020, just before midnight.

33:16I got an email in my inbox from a group calling itself the Homeland Tigers. This came to my work email. It's a good name. They claim to be Iranians. Hmm. And they said they'd started a fire at Natanz. Now, I always I think this was an Israeli thing. And they were basically emailing journalists like me to try and claim responsibility and to try and suggest that it was an Iranian domestic group. I slightly find that implausible. But they sent me details of this and it wasn't yet public. And then the next day it emerges. There has been a fire at Natanz.

33:49Gordon Corera:The Homeland Tigers were on to something. The Homeland Tigers. But there's going to be more of these little explosions. And of course, November 2020, picking up to our previous episode, you get the assassination campaign, claims arguably its biggest target, Mohsen Fakhrizadeh, the man who's been driving a lot of the military side, and he's taken out in 2020. into. Well, and even a couple years before that was when the Israelis, it was 2018, when the Israelis conducted that wild operation to basically go into warehouses, I think a big warehousing facility in Tehran and basically steal all of the hard copy documents about the nuclear program.

34:30Gordon Corera:The themes from the kind of Stuxnet era, I guess you could say, cyber attacks, physical sabotage, an assassination campaign, and then this kind of almost like a public relations trying to shed as much light as possible on the Iranian program. Those, I guess, pillars of the Israeli campaign against Iran's nuclear program are very much alive and well a decade after Stuxnet, right? And up to the point of these most recent strikes. Yeah, because what you then see is that shadow war and some of it public continuing and you have the iranians continuing to enrich continuing to increase the amount of material shorten that breakout time through which they can you know get to the bomb and then of course you know just this year something changes you know which changes the dynamics around this program you know it is interesting to look at it with this long view that we've had.

35:27Because Israel's argument is that they get new intelligence, which suggests Iran is pressing forward on aspects of weaponization, which you'll remember if you go back to the early episode 2003, the US believes the Iranians stopped at that point, the final stage, the weaponizations. Now, the Israelis suggest they have something new on that. Others I've spoken to are more sceptical about that. And they think it's more that Israel's risk calculus has changed, that Israel's risk calculus about tolerating an Iranian bomb after October the 7th changes, and of course, all its proxies. We talked about this on one of our bonus episodes, really interesting interview, where all the proxies that Iran has are taken off the board, off the chessboard.

36:13So Iran has less ability to respond if Israel wants to strike. And so I think Israel just sees that opportunity of a weakened Iran and of a Trump administration, which they are hoping might come in behind them, which of course it does, and then go for it. Now, I'm not saying there wasn't any new intelligence, but I think that calculus is more of what's going on in my head.

36:35Gordon Corera:Oh, it's really important. It's got to be. Yeah, because you think about the sort of Mayor Dagan calculation on wanting to delay Iran's going to push toward a bomb because he's trying to avoid a conflict. And on the conflict side of that has got to be the sense that if we actually militarily strike the Iranians, there's going to be a protracted regional war that's going to lead to thousands of people getting killed, right? And all of a sudden, I think now in the summer of 2025, with Hezbollah basically defanged, and with the Israelis having already taken a big bite out of Iran's air defenses and with Iran really reeling, all of a sudden that calculation shifts and you think, well, the whole point of all of this, the shadow war stuff, is to degrade Iran's nuclear program as much as possible.

37:35Gordon Corera:Well, all of a sudden, if the cost of the over-military strikes goes way down, it starts to look like a much better option for the Israelis, right? And even if there's not really new intelligence on that front, all of a sudden it makes a lot more sense to overly strike. And when you figure that if you're Netanyahu, you might be able to do this and then convince the Americans to join and use those big B2s with the bunker buster bombs that maybe can get you deep enough to create some real damage at 4DAO. It starts to seem like a pretty attractive idea. Even if you're only setting the program back a year or two, you figure, why not if you're Netanyahu, right?

38:19Yeah, totally. So that really does take us to where we are now with those attacks, Natanz, which is where we started, getting bombed multiple times. Fordow getting hit by these massive ordnance penetrators. Damage, setback. Again, hard to know what's happened underground, but also does Iran have more secret sites? Has it got another secret mountain site? What's happened to the 400 kilograms of highly enriched uranium, which they stockpiled already? Will Iran now race for a bomb at a secret site or on the back foot will it go for a deal? I don't think we can know where it goes next. But hopefully, I think by telling this story, we've helped explain how we got here and how to understand the events as they've been unfolding.

39:06Because I think that context is really important, even if we can't really predict where this goes next.

39:13Gordon Corera:And the big loser in this entire series, Natanz. Yeah. The poor site at Natanz is horse-blanketed, bombed, centrifuges ripped apart. I mean, I know we're covering almost 20 years of history here, But it seems like if you're an Iranian nuclear scientist or physicist or engineer, maybe you want to work elsewhere, right? Which I guess is part of the whole point of this. Part of the point, yeah. Right, is let's go work on, you know, designing the next generation of Tupperware instead of nuclear bombs. So, it has been quite the journey, Gordon. And I have to commend you once again for your explanations of nuclear physics.

40:00Gordon Corera:Listeners to the podcast will, of course, understand that I don't enjoy giving you compliments, but I think you navigate science very well. I'll take it. That's right. I'll take it. That's right. We should note that although this series is ending, it's still a wonderful time to sign up for the Declassified Club, Gordon. We've got a great interview, haven't we, with Jim Lawler about Iran, which is talking about specifically the targeting and the sabotage of Iran's nuclear program. So he ran one of the CIA teams, which was dealing with Iran's nuclear program and with the AQ Khan network, which we talked about.

40:34We've heard from him a bit already about other aspects of his career, but it is an absolutely fascinating interview. If you want to understand what sabotage really looks like, how it is done, it is amazing how you run front companies and all that stuff. And that is going to be the bonus episode for our club members, which is coming out on Friday. So do join at the rest is classified dot com. But otherwise, see you next time. See you next time.

41:09Gordon Corera:Hey, guys, it's Anthony Scaramucci for the rest is politics. U.S. Katty Kay and I want to tell you about our North American tour in October. Donald Trump is rewriting the history of the United States from trade wars to immigration crackdowns to global conflicts. We are here to make sense of all of it. You know, we're in an era defined by depolarization and American institutions are breaking under Donald Trump. Cady and I will be live on stage breaking down what's really happening, sharing insider perspectives and answering your questions. This October, we're heading to Toronto, Boston, New York, Washington, D.C., a host of other American cities to get into all of the political action.

41:53We would love to see you there. Come and join us.

41:56Gordon Corera:So head to the rest is politics, U.S. dot com to get your tickets and come see us live.

From the publisher

How did the Stuxnet cyberweapon, designed to be covert, break out into the wild? What were the world-changing implications of this sophisticated attack on Iran's nuclear centrifuges, and what happened when it was exposed?

Listen as David McCloskey and Gordon Corera reach the finale of their series on the Stuxnet cyberweapon, discussing its discovery by cybersecurity researchers and the subsequent shift in tactics against Iran's nuclear ambitions.

-------------------

To sign up to The Declassified Club, go to ⁠www.therestisclassified.com⁠.

To sign up to the free newsletter, go to: ⁠https://mailchi.mp/goalhanger.com/tric-free-newsletter-sign-up⁠

-------------------

Get our exclusive NordVPN deal here ➼ nordvpn.com/restisclassified It's risk-free with Nord's 30 day money back guarantee

-------------------

Order a signed edition of Gordon's latest book, The Spy in the Archive, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠via this link.⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

Order a signed edition of David's latest book, The Seventh Floor, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠via this link.⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠

-------------------

Email: classified@goalhanger.com

Twitter: ⁠⁠⁠⁠⁠⁠⁠@triclassified⁠⁠⁠⁠⁠⁠⁠

Assistant Producer: Becki Hills

Producer: Callum Hill

Senior Producer: Dom Johnson

Exec Producer: Tony Pastor
Learn more about your ad choices. Visit podcastchoices.com/adchoices

More from The Rest Is Classified

All 157 episodes
71. Israel Attacks Iran: The Dawn of Cyber Warfare (Ep 4)The Rest Is Classified · 44 min
Listen in VO