American Innovations · Audible

The Mystery of Stuxnet | Cracking the Code

December 16, 2021·41 min·2 clips
To confirm Stuxnet was destroying Iran's nuclear centrifuges, two cybersecurity researchers attached a balloon to an air pump and watched it burst.
July 16, 2010 opens in Culver City. Liam O'Murku arrives at Symantec's Threat Analysis Lab, a plain cubicle office doing much stranger work than the room suggests. His morning starts with checks on research computers kept offline so the viruses under study cannot escape into the wild. Then Stuxnet ruins the routine. As the analysts work through it, the list of possible builders gets very short: the United States, Israel, China, and Russia. Espionage is no longer a dramatic theory. O'Murku realizes they may have rerouted messages meant for unknown agents straight back to Symantec's office. That is the moment the investigation stops feeling like ordinary malware analysis. Now it is brushing against secret operations and another country's infrastructure, with very little legal comfort around the edges. The question is not just how the virus works. It is whether private researchers can keep studying it without stepping into something much bigger than their job titles. Chen gives the escape route out loud. They could stop, walk away, and let whoever built Stuxnet keep their mission. They do not take it. The malware has touched Symantec customers' computers, and protecting those machines is still the work in front of them. The nerves leak out as dry humor. Chen jokes about hitmen while O'Murku shuts down his computer, pulling back for a beat from an investigation that has barely started. The closing note returns to the record: scenes are dramatized from historical research, with Kim Zetter's Countdown to Zero Day pointed out for more on Stuxnet.

As heard by us

A measured, tense look at Stuxnet that moves from malware analysis into espionage-adjacent uncertainty.

The episode follows Stuxnet out of Symantec's Threat Analysis Lab and into territory that starts to feel like espionage. What works best is the way it treats detection as a slow, uneasy process: routine malware work gives way to the sense that the code may point to a nation…

Read the full review in PlayNext →

Why you'd press play

When malware turns into nation-state espionage, the office morning gets dangerous fast and stays that way for everyone.

Read the full recommendation in PlayNext →
Listen to the show on