Hacker News
Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon
The repository reconstructs Stuxnet’s source code from 2010 binary samples, preserving its logic for academic analysis. It details modules such as winsta.exe dropper, privilege-escalation via Win32k.sys, S7 hook libraries, and rootkits MRxCls.sys and MRxNet.sys that hide files and propagate over USB and network shares. The payload modifies PLC block logic (OB1/OB35) to alter motor frequencies, damaging centrifuge rotors in Siemens S7-300/400 systems.