Expert: U.S. 'Leading Force' Behind Stuxnet One year ago, German cybersecurity expert Ralph Langner announced he had found a computer worm designed to sabotage a nuclear facility in Iran. The Stuxnet worm is now recognized as a cyber-superweapon, and it could end up harming those who created it.
NPR logo

Security Expert: U.S. 'Leading Force' Behind Stuxnet

  • Download
  • <iframe src="https://www.npr.org/player/embed/140789306/140799000" width="100%" height="290" frameborder="0" scrolling="no" title="NPR embedded audio player">
  • Transcript
Security Expert: U.S. 'Leading Force' Behind Stuxnet

Security Expert: U.S. 'Leading Force' Behind Stuxnet

  • Download
  • <iframe src="https://www.npr.org/player/embed/140789306/140799000" width="100%" height="290" frameborder="0" scrolling="no" title="NPR embedded audio player">
  • Transcript

DAVID GREENE, Host:

Last week, Ralph Langner sat down with NPR's Tom Gjelten to discuss his discovery.

TOM GJELTEN: Langner Communications is a little firm in Hamburg, Germany. But Ralph Langner and the two engineers with whom he works know a lot about industrial control systems. And in the summer of 2010, they went to work analyzing a malicious software program that was turning up in some equipment. Someone had dubbed the worm Stuxnet. Langner was flabbergasted.

RALPH LANGNER: I'm in this business for 20 years and what we saw in the lab when analyzing Stuxnet was far beyond everything we had ever imagined.

GJELTEN: Langner was in Washington recently for a cyber security conference. In an interview on the sidelines, he told me the more his team analyzed the Stuxnet worm, they more they knew they were onto something big.

LANGNER: We were all pretty much working around the clock. Because after we had the first impression of the magnitude of this, we were just like on speed or something like that. It was just impossible to go back to sleep.

GJELTEN: Was it exciting?

LANGNER: Well, absolutely.

GJELTEN: Langner couldn't imagine who could have created it. Each day he was more impressed.

LANGNER: First time, well, this is a banger. Wow. That's fantastic. That's huge. And then, a couple of days later, the next experience like this, we were thinking, well, what's coming next? What are these guys? At what level are they? Are they aliens or what?

GJELTEN: But that would be science fiction. This was reality.

LANGNER: Thinking about it for another minute, well, if it's not aliens, it's got to be the United States.

(SOUNDBITE OF LAUGHTER)

GJELTEN: Another realization: by analyzing the Stuxnet code, Langner concluded it was designed to disable a particular nuclear facility in Iran. That's serious business, he figured. Some Iranian nuclear scientists, he remembered, had been mysteriously killed. But he published his findings anyway.

LANGNER: I wasn't actually scared, but this was just something I was thinking about. When you know this stuff must involved with intelligence services, who do some dirty work every now and then, and you can't just block that away from your personal situation when you are the guy who is the first to publish - yeah, this is a directed attack against the Iranian nuclear program. So there have been some frightening moments.

GJELTEN: Langner isn't shy about naming the U.S. as the Stuxnet culprit. Here he is, speaking recently at the Brookings Institution.

LANGNER: I'm absolutely convinced that the United States is the leading force behind Stuxnet.

GJELTEN: In that Brookings speech, he also made a bigger point, that having developed Stuxnet as a computer weapon, the United States may in effect have introduced it into the world's cyber arsenal.

LANGNER: Cyber weapons proliferate by use, as we see in the case of Stuxnet. Several months or weeks or a year later, the code is available on the Internet for dissection by anybody who has the motivation and time to do so.

GJELTEN: Tom Gjelten NPR News, Washington.

Copyright © 2011 NPR. All rights reserved. Visit our website terms of use and permissions pages at www.npr.org for further information.

NPR transcripts are created on a rush deadline by Verb8tm, Inc., an NPR contractor, and produced using a proprietary transcription process developed with NPR. This text may not be in its final form and may be updated or revised in the future. Accuracy and availability may vary. The authoritative record of NPR’s programming is the audio record.