Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Stuxnet — Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit functionality, and PLC payload injection targeting Siemens Step 7 and S7 PLCs. | Kitploit
도구/GitHubGitHub/sadpainy/stuxnet
Privilege EscalationExploitationLateral MovementReverse EngineeringMalware AnalysisLearning & EducationPayload Development
GitHubsadpainy/stuxnet

Stuxnet

Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit functionality, and PLC payload injection targeting Siemens Step 7 and S7 PLCs.

저장소 보기
548100127일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Stuxnet

Build Tests Siemens Purpose

This repository contains a strictly educational and research-oriented reconstruction of the infamous Stuxnet worm. It is the product of countless hours of reverse engineering work conducted by the global security research community on the original binary samples discovered in 2010.

Disclaimer: This code is provided solely for academic study, malware analysis training, and defensive research. It is not intended to be used for any malicious purposes, nor is it a deployable piece of malware. The authors and contributors do not condone illegal or unethical activities.

Table of Contents

Overview

Core Components

Technical Architecture

Build Instructions

Usage

Legal and License

Acknowledgements

Overview

Stuxnet is widely recognized as the first known cyber-weapon designed to cause physical destruction to industrial control systems (ICS). It specifically targeted Siemens Step 7 software and S7-300/400 PLCs, ultimately manipulating frequency converter drives to damage centrifuge rotors.

This repository is a reconstructed source code derived from the decompiled binaries. It preserves the original logic and attack vectors while structuring the codebase for readability and analysis.

Key Characteristics

Target: Siemens SIMATIC WinCC, Step 7, and S7 PLCs.

Propagation: USB drives (LNK exploits), Network shares (Print Spooler), Peer-to-Peer (P2P).

Payload: Modification of PLC block logic (OB1/OB35) to alter motor frequencies.

Stealth: Advanced Rootkit capabilities (MRxCls.sys, MRxNet.sys) for file, process, and registry hiding.

Core Components

The repository is organized by the primary modules identified during the analysis of the original malware.

Module: Loader/Dropper Filename: winsta.exe, ~WTR4141.tmp Description: Entry point responsible for initial infection, privilege escalation, and deployment of other components.

Module: Privilege Escalation Filename: ~WTR4132.tmp Description: Exploits the Win32k.sys vulnerability to gain system-level privileges.

Module: S7 Hook Library Filename: s7otbxdx.dll Description: Malicious replacement for the original s7otbxsx.dll. It intercepts communication between Step 7 and the PLC.

Module: Step7 Hook Library Filename: s7aaapix.dll Description: Intercepts AUT (Automation Tool) API calls within the Step 7 engineering environment.

Module: Rootkit (File System) Filename: mrxcls.sys Description: Kernel-mode driver used to hide Stuxnet files, processes, and registry keys via SSDT hooking.

Module: Rootkit (Network) Filename: mrxnet.sys Description: Filters file system requests to hide malicious files and enables P2P propagation.

Module: Payload (Attack) Filename: s7plcmain Description: The core logic responsible for the "Frequency Tampering" attack that damages the centrifuges.

Technical Architecture

The following describes the high-level execution flow of the Stuxnet framework.

Stage 1: Initial Infection Vector (USB/Network) Stage 2: Dropper and Escalation Stage 3: Check Environment Stage 4a: Target Found (Siemens Software) -> Install S7 Hooks Stage 4b: Non-target -> Self-Destruct/Idle Stage 5: Monitor PLC Writes Stage 6: Detect OB1/OB35 Write -> Inject Payload Stage 7: Modify Frequency Output Stage 8: Physical Damage to Centrifuges Stage 9: Install Rootkit (MRxCls) Stage 10: Hide Files and Registry Stage 11: Load Network Module (MRxNet) Stage 12: P2P Propagation

Execution Flow

  1. Environment Reconnaissance: The worm checks for the presence of specific Siemens software (WinCC, Step 7) and specific target PLCs (S7-315, S7-417).

  2. DLL Injection: It intercepts the s7blk_write function call.

  3. Code Injection: When a user downloads a project to the PLC, the malicious code is appended to the OB1/OB35 blocks.

  4. Physical Impact: The PLC executes the manipulated code, causing the connected variable frequency drives (VFDs) to spin at abnormal frequencies (high/low), resulting in mechanical damage.

Build Instructions

Important: This codebase is designed for static analysis and debugging in a controlled virtual environment. It is not intended for live deployment on any critical infrastructure.

Requirements

Build Environment: Microsoft Visual Studio 2019/2022 (Windows) or mingw-w64.

Target OS: Windows XP / Windows 7 (for driver compatibility).

Driver Kit:Windows Driver Kit (WDK) 7600 (if compiling kernel drivers).

Building the User-Mode Modules

Clone the repository

root@kitploit:~
git clone https://github.com/Sadpainy/Stuxnet.git
cd Stuxnet

Build the main dropper

root@kitploit:~
cd Main
nmake /f Makefile.win

Build the S7 hook library

root@kitploit:~
cd ../s7otbxdx
cl /LD s7otbxdx.c user32.lib ws2_32.lib

Usage

This code is intended for:

Malware Analysis: Understanding the specific code logic used in advanced persistent threats (APTs).

Defensive Research: Developing detection signatures for ICS security tools (e.g., YARA rules, Snort signatures).

Academic Study: Examining the intersection of cybersecurity and critical infrastructure protection.

Analysis Setup

  1. Isolate Environment: Use a virtual machine (VMWare/VirtualBox) with Host-Only networking enabled. Disable internet connectivity.

  2. Load Modules: Analyze the .dll and .sys files using tools such as IDA Pro, Ghidra, or x64dbg.

  3. Monitor Activity: Use Process Monitor (ProcMon), Process Hacker, and Wireshark to observe the behavior.

Legal and License

License

This project is licensed under the GNU Affero General Public License v3.0, LICENSE.Stuxnet, LICENSE.XOR, LICENSE.Detail, Apache License 2.0 and LICENSE.Desktop. See the LICENSE file for details.

Disclaimer

This repository contains code produced through reverse engineering, provided strictly for educational and security research purposes only.

The original authors of the Stuxnet worm are anonymous. The reconstruction contained herein is the independent work of security researchers and is not affiliated with, endorsed by, or connected to any original author or entity.

The authors do not claim ownership of the original malware or any of its underlying concepts.

This code is provided "AS IS", without warranty of any kind, express or implied, including but not limited to the warranties of merchantability, fitness for a particular purpose, and non-infringement.

The authors are not responsible for any misuse, damage, or legal consequences caused by this code, including but not limited to unauthorized access, data loss, or violation of applicable laws.

By using this repository, you acknowledge that you are solely responsible for ensuring compliance with all applicable laws and regulations in your jurisdiction.

Do not use this code for malicious, unauthorized, or unlawful activities.

Acknowledgements

This research and reconstruction would not have been possible without the extensive analysis and threat intelligence provided by global cybersecurity vendors.

Symantec (W32.Stuxnet dossier)

Kaspersky Lab (The Stuxnet saga)

ESET (Stuxnet under the microscope)

Amr Thabet and Christian Roggia (research-virus/stuxnet)

root@kitploit:~
This is an academic reconstruction. Use it to build stronger defenses, not to cause harm.
도구 다운로드