stuxnet – effort and payout
Tuesday, October 5th, 2010There’s been a ton of speculation on stuxnet so far, much of it seeming to indicate that this was created by a state actor. Most people have pointed at the incredible levels of effort that went into creating it. However people are forgetting that many recent malware attacks – including Zeus and Conficker, have had the title of “most complex ever” bestowed upon them as well. It seems natural that malware and computer attacks will only continue to get more complex. Complexity alone does not indicate a state actor.
What people aren’t saying (but I have a feeling many people sense it intuitively without stating it), is that the lack of monetization combines with the effort is indicative of a state actor being behind the stuxnet worm. Zeus and Conficker were easily monetized, which explains the effort involved – people (perhaps many people), worked hard to create something to make them money. If they needed an exploit, one could be purchased with the hope that they’d recoup the costs later. The fact that Stuxnet seems to do something (but we don’t know what), and doesn’t seem to be easy to monetize, certainly seems to indicate a non-criminal motive. Since we haven’t seen many other players in this space with significant resources other that criminals and governments, government because the natural suspect.
As for the target of Stuxnet, Iran has the most infections, but that could very easily be coincidence. So far there’s no evidence at all that Iran, or anyone else, was a specific target, and we’ve had a simple case of the media continuing to report on each other’s reporting. There are so many reasons that Iran could have more infections I can’t even count them all. Perhaps Iran doesn’t have great antivirus adoption rates. Perhaps the first few infections simply happened to be there. Perhaps, this was made by Iranians. Viruses are inherently untargetted, so trying to guess at a target based on the geographical location of infections is speculative at best. However, since no one has any better theories, the media echo chamber will continue to promote this until people assume it’s true, whether or not it really is.