Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0603
MITRE ATT&CK Malware

Stuxnet (S0603)

W32.Stuxnet
ShareXLinkedInRedditHN

[Stuxnet](https://attack.mitre.org/software/S0603) was the first publicly reported malware to specifically target industrial control systems devices. [Stuxnet](https://attack.mitre.org/software/S0603) is a large and complex malware that utilized multiple behaviors, including numerous zero-day vulnerabilities, a sophisticated Windows rootkit, and network infection routines.(Citation: Nicolas Falliere, Liam O Murchu, Eric Chien February 2011)(Citation: CISA ICS Advisory ICSA-10-272-01)(Citation: ESET Stuxnet Under the Microscope)(Citation: Langer Stuxnet) [Stuxnet](https://attack.mitre.org/software/S0603) was discovered in 2010, with some components being used as early as November 2008.(Citation: Nicolas Falliere, Liam O Murchu, Eric Chien February 2011)

Platforms: Windows

▪Techniques implemented (69)

T1016System Network Configuration DiscoveryT1082System Information DiscoveryT1132.001Standard EncodingT1560.003Archive via Custom MethodT1070.006TimestompT1129Shared ModulesT1047Windows Management InstrumentationT1112Modify RegistryT1543.003Windows ServiceT1140Deobfuscate/Decode Files or InformationT1070.004File DeletionT1134.001Token Impersonation/TheftT1210Exploitation of Remote ServicesT1027.013Encrypted/Encoded FileT1091Replication Through Removable MediaT1480Execution GuardrailsT1041Exfiltration Over C2 ChannelT1070Indicator RemovalT1055.001Dynamic-link Library InjectionT1573.001Symmetric CryptographyT1014RootkitT1071.001Web ProtocolsT1083File and Directory DiscoveryT1008Fallback ChannelsT1087.002Domain AccountT1120Peripheral Device DiscoveryT1685Disable or Modify ToolsT1068Exploitation for Privilege EscalationT1078.001Default AccountsT1518.001Security Software DiscoveryT1087.001Local AccountT1021.002SMB/Windows Admin SharesT1012Query RegistryT1124System Time DiscoveryT1553.002Code SigningT1135Network Share DiscoveryT1078.002Domain AccountsT1106Native APIT1570Lateral Tool TransferT1053.005Scheduled TaskT1021Remote ServicesT1090.001Internal ProxyT1080Taint Shared ContentT1505.001SQL Stored ProceduresT0849MasqueradingT0888Remote System Information DiscoveryT1694.002Hardcoded CredentialsT0877I/O ImageT0801Monitor Process StateT0867Lateral Tool TransferT0834Native APIT0836Modify ParameterT0874HookingT0807Command-Line InterfaceT0843Program DownloadT0847Replication Through Removable MediaT0863User ExecutionT0873.001Siemens Project File FormatT0869Standard Application Layer ProtocolT0885Commonly Used PortT0866Exploitation of Remote ServicesT0831Manipulation of ControlT0889Modify ProgramT0821Modify Controller TaskingT0832Manipulation of ViewT0886Remote ServicesT0835Manipulate I/O ImageT0851RootkitT0842Network Sniffing
S0603on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.