Normale Ansicht

Received before yesterdayTom's Hardware

Researcher reverse-engineers infamous Stuxnet malware source code, publishes it on Github for all — attack targeted Iranian nuclear facilities and was the first software of its type to cause physical damage

Anyone keeping track of world news in the early 2010s, and reports on tech in particular, has probably heard about Stuxnet. That malware spawned a large number of conspiracy theories — with the kicker that some of them were actually true. The malware targeted Iranian nuclear facilities and is believed to be the first digital worm to cause direct physical damage in meatspace. An unknown security researcher has now published a source code reverse-engineering of Stuxnet in all its glory.

The worm's ultimate target, allegedly a successful one, were industrial controllers from Siemens that were reportedly used in Iranian's Natanz nuclear enrichment plant. Once it reached the target, Stuxnet's payload manipulated the frequency converters in industrial centrifuges, in a bid to subtly damage the rotors — all while keeping the plant staff in the dark by reporting normal operation.

The repository contains build instructions so interested techies can try it out for themselves and learn all about its inner workings. You'll need a Windows XP or Windows 7 virtual machine, and for obvious reasons, you shouldn't configure any network connectivity for it. To witness the full effects of the payload rather than just the spreading mechanisms, you'll need the appropriate Siemens software, and ideally hardware — though we figure that industrial-scale centrifuges aren't exactly common in techies' cable drawers.

In its heyday, Stuxnet spread via three mechanisms. The primary infection vector was USB sticks with Windows shortcuts and autorun.inf files. Upon plugging one of those sticks in, just viewing the drive's contents would immediately trigger infection thanks to a zero-day vulnerability.

Infected systems then autonomously tried to spread the worm further via the network using a zero-day Windows Print Spooler vulnerability that would let an attacker write system files into any machine sharing a printer. It would also copy itself into accessible network shares. To evade Windows driver signature checks, Stuxnet used two digital certificates stolen from Realtek and JMicron.

The worm also had code to inject itself into Siemens software, by way of the WinCC SQL Server database, and embedding its code in Step 7 project files that automatically ran when engineers opened them. Since those files were almost guaranteed to be shared among more than one engineer, it made for an excellent internal infection vector that didn't depend on having network share control.

The final step was taking charge of the DLL that communicated with the actual centrifuges and injecting malicious code into the PLCs (Programmable Logic Controllers) of those machines to stealthily mess with the rotors.

Stuxnet was part of Operation Olympic Games, an alleged coordinated effort between the U.S. and Israel to try and curb Iran's purported progress in creating nuclear weapons at its Natanz facility. The initiative seemingly ran under both the Bush and Obama administrations, and was supposedly a way to dissuade Israel from launching its own preemptive strike against Iran. The software was allegedly developed by both the Pentagon and Israel's Unit 8200, and was reportedly successful in bringing down about 10% of Natanz' centrifuges by ultimately seriously damaging their rotors.

However, the worm had a nasty bug: it didn't have sufficient checks about which environment it was in, and failed to notice it was no longer in a local network environment. When engineers took their laptops home, it escaped out to the internet at large, at which point security researchers worldwide let out a collective "huh, that's odd" and proceeded to investigate. Mercifully, the worm contained a hard-coded self-destruct date set for June 24, 2012.

Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole victims' data via remote access

02. September 2026 um 16:22

A federal grand jury in California has indicted Russian citizen Searzhudin Tamirlanovich Aktulaev for allegedly conducting phishing attacks that stole data from over 80,000 computers between June 2016 and November 2017, using TVRAT and DarkVNC remote-control malware. Detailed in a Department of Justice press release on September 1st, the indictment — filed in June 2021 and released September 2026 — lists charges of “Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses.”

Aktulaev was extradited to the U.S. in August 2026, five years after his arrest in Cyprus in May 2021. He made his first appearance in federal court in San Francisco — after which he was remanded to federal custody — and is scheduled to appear in district court on October 5, 2026. The arrest was made after an FBI investigation, and the case is being prosecuted by the National Security, Cyber, and Special Prosecutions Section.

According to the indictment, Aktulaev “conspired to exploit the online message platform of a well-known freelance employment technology company, located in the Northern District of California, to spread malware to approximately 80,000 freelancers”. He sent messages containing malicious Microsoft Excel attachments, using approximately 255 fake user accounts. Once opened, the attachments prompted users to run a macro that then downloaded malware from the Internet, mirroring a hack earlier this year in which an unofficial 7-zip.com website served malware-laden downloads for over a week.

The attack used TVRAT (TeamViewer Remote Access Trojan) and DarkVNC malware, both of which grant the attacker remote control of the infected system. TVRAT exploits TeamViewer, while DarkVNC exploits VNC Viewer, popular remote administration tools. The malware stole and uploaded data from the victims' computers to a command-and-control server, from which Aktulaev and his co-conspirators extracted the stolen data to “commit fraud and other criminal activities”.

The indictment says thousands of computers infected by the TVRAT malware were “calling back” to a command-and-control domain hosted in the United States, which was paid for using virtual currency. Roughly half of the victims were in the United States, many of whom were Northern District of California residents, according to the indictment.

“A database found on the command-and-control domain revealed thousands of victims. Additionally, a shared document on the email account used in the criminal activities contained information to include e-commerce login credentials, as well as personally identifiable information (“PII”) for hundreds of victims,” the press release said.

If convicted, Aktulaev could spend up to 20 years behind bars and pay a $250,000 fine or twice the total illicit gains for the conspiracy to commit wire fraud charge alone. The other charges carry terms ranging from two to twenty years in prison, in addition to fines. Meanwhile, the FBI is currently investigating another hack in which 153 million US and Canadian drivers’ licenses were leaked on a Russian cybercrime forum.

FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

More than 153 million US and Canadian driver’s licenses, as well as other identity documents, have reportedly become available for purchase on the dark web for a limited time. According to cybersecurity journalist Brian Krebs, the service was called Nexus, and although it’s no longer available at the time of writing, it claimed to have possessed 153 million driver’s licenses, 10 million ID cards, 1.9 million travel documents, 1.3 million international driver’s licenses, 579k medical cards, 429k common access cards, 91k residence cards, 77k employment authorization records, and 5 million other documents, allegedly sourced from an ID-authentication service based in Louisiana.

The service was advertised on the Russian cybercrime forum Exploit, where whoever was promoting it posted the driver’s license of Krebs as a free sample, which caught the journalist’s attention. He was also able to see a preview of U.S. Secretary of Defense Pete Hegseth’s information on the database — a concerning breach of security for someone with such a sensitive position in the government. After further investigation, they concluded that the service seemed to have possessed legitimate data, especially after searching for the data of several of his friends and family members with their consent. One thing that all the people he found in the database had in common was that they all used Hertz to rent a vehicle.

Krebs also talked with security and privacy researcher Zach Edwards, who said that their information was also found on Nexus. Edwards said that they did not rent a car recently but used their ID at a Planet13 marijuana dispensary. The time stamps found on the scanned images of the driver’s licenses and other identity documents coincide with the time that the victims used their IDs at the said companies, confirming that they were the sources of the leaks. However, Planet13 and Hertz do not do their own authentication; instead, they contract a service provider for the service. Now, it turns out that both Planet13 and Hertz used the company for identity verification and ID-authentication — IDScan.

Based on the evidence gathered by Krebs, it seems that the leak is centered around the company. He has already contacted the company about the issue, and they said they were investigating the matter. “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” Jillian Kossman, a marketing and operations leader at idscan.net, told the journalist. The FBI has also started looking into the leak, with its New Orleans field office opening an official investigation into the breach.

The massive amount of data that was briefly available on the dark web is certainly concerning. A similar data breach hit Discord after its third-party service provider was hit and resulted in the exposure of 70,000 government IDs. Incidents like these have got privacy experts concerned with the push for online age verification requirements, which is why the EFF is asking the California governor to veto the law requiring this.

Aside from privacy-invasive checks and stepping on First Amendment rights, the leakage of sensitive data like this could increase incidents of stolen identity and more. Driver’s licenses are often widely accepted for opening credit lines and bank accounts, with both photographic, UV, and IR scans available on many of the leaked licenses. Aside from that, it could also potentially compromise the privacy and security of vulnerable people, like those fleeing domestic violence and those who are under the witness protection program.

BlindLock hides your password manager and secure vault in a PNG image — also offers secure notes, 2FA, and a crypto address book, with optional hardware security keys

01. September 2026 um 13:45

A new local‑only password manager, notes app, and secure vault that hides your secrets in an ordinary-looking .PNG image file is now available. BlindLock does all this and more with an option to bind to your hardware using TPM2.0, Secure Enclave, or StrongBox. No cloud storage or central vault account is required, and the dev is selling lifetime licenses at $49 (for now). There is an interactive online demo, with nothing uploaded or downloaded, as well as a downloadable full 7-day demo available.

BlindLock’s solo developer David Domingo indicates that one of the main drivers behind his efforts to create this application was the theft of customer vault backups from LastPass in late 2022. What happened to LastPass could have also happened to 1Password, Dashlane, even Proton Pass, reckons Domingo. “When your vault sits on someone else's server, you inherit every risk that server carries: employee access, infrastructure vulnerabilities, government subpoenas, supply chain attacks, and the simple mathematical reality that a server holding tens of millions of vaults is a far more attractive target than your laptop,” says the BlindLock dev on his blog.

BlindLock

(Image credit: BlindLock)

So, three independent layers of security apply to your BlindLock vault. It is invisible in its ordinary-looking PNG carrier, not just encrypted. BlindLock doesn’t run a central vault database, so there is nothing for attackers to steal from BlindLock servers and crack later. Your resting vault file uses 256-bit authenticated encryption and already includes NIST post-quantum components. It is also bound to your device. “The vault opens only when three things match: the carrier file, your master password and your authorized device,” asserts the BlindLock app page. “A copied file alone is not enough to gain access.”

BlindLock’s feature set is pretty broad for a new offering. Fully encrypted inside your chosen .PNG holiday snap or cat photo is a password manager, Markdown-supporting secure notes, a built-in 2FA authenticator, and an encrypted file vault (for any type of file), and there is support for an optional fourth-factor security key like a YubiKey or Google Titan, etc.

Accessing your BlindLock data requires three things at once: the carrier file, your master password, and the authorized device - the vault key is sealed to that device's security chip, which is TPM 2.0, Secure Enclave, or StrongBox depending on the platform. You can avoid overly bloating your central .PNG file by squirreling larger files separately in their own encrypted containers. BlindLock employs a hidden volumes system not unlike VeraCrypt for these containers. Domingo admits these are “not magically unfindable,” but are Argon2id-hardened, 256-bit authentication-encrypted and stored inconspicuously. For device loss or migration, users must create an encrypted BlindLock backup and keep its recovery phrase separately.

BlindLock

Online demo screenshot (Image credit: BlindLock)

As per the intro, BlindLock is being introduced as a one-time $49 purchase. This perpetual pricing plan only applies to the first 1,000 licenses. There will be three waves: “the first 100 at $49, the next 350 at $89, and the final 550 at $109. After that, BlindLock is subscription-only,” says Domingo. The independent dev wants to lay a solid financial foundation, so development of BlindLock can continue.

This article is merely sharing the news about BlindLock and shouldn't be taken as a recommendation. Please check out the online and downloadable demos and judge whether it works for you and offers the features you want for the price.

❌