The call reached Sergey Ulasen of VirusBlokAda, a small Belarusian antivirus company, at a friend's wedding reception. It was a Saturday, a working day in Iran, where a customer had computers crashing to the blue screen and rebooting — even machines with Windows freshly installed. He spent the reception on the telephone. On the Monday afternoon, once he had remote access to an infected machine, he and his colleagues found the malware; closer analysis showed how it spread, and that its drivers carried a genuine digital signature, which they concluded had been stolen. The company's records put its first detection at 17 June 2010. It tried to reach Realtek, whose signature it was, and Microsoft; neither, Ulasen said later, gave a proper response.
It travelled on USB drives and needed no click. Windows read a shortcut file in order to draw its icon, and a shortcut built the right way made it run code as it did so: opening an infected stick in Explorer was enough. The stick carried four shortcuts named along the lines of "Copy of Shortcut to.lnk" and two files dressed as temporary files, which vanished from view once the machine was infected. Of the two drivers, mrxnet.sys hid the files and mrxcls.sys started the malware at boot; both described themselves as Microsoft's and bore a valid signature from Realtek Semiconductor of Taiwan; one had been signed on 25 January 2010. In mid-July Ulasen and Oleg Kupreev published their findings on the company's website and a security forum as Rootkit.TmpHider.
Brian Krebs's post of 15 July was the first widely read account; he quoted Ulasen and the researcher Frank Boldewin, who said the code appeared to be looking for Siemens WinCC SCADA systems. On 16 July Microsoft published Security Advisory 2286198 for every supported version of Windows; its stopgap was to switch shortcut icons off altogether and live with blank white ones. Its malware researchers blogged the same day under the name that stuck, Stuxnet, spliced from ".stub" and "mrxnet.sys"; Symantec adopted it on 19 July. Within a day of the advisory VeriSign had revoked Realtek's certificate. On 17 July ESET's Pierre-Marc Bureau reported a new driver, compiled on 14 July and signed with a certificate belonging to JMicron, another company in Taiwan's Hsinchu Science Park. VeriSign revoked that one on 22 July.
Siemens, told on 14 July, said on 19 July that it was investigating; its spokesman Michael Krampe urged customers to check their computers running WinCC. The worm looked for WinCC and for Step 7, the software that programs Siemens controllers, and opened WinCC's database with a password Siemens had hard-coded, one revealed on forums back in 2008. Siemens advised customers not to change it, since that could disrupt the whole system, and on 22 July offered a tool to find and remove the worm. July's reading was espionage: code that searched project files and tried to copy them out. It did not last. What the worm was built to do is September's story, and the first reported accounts of who built it came in January 2011 and June 2012.
The Logs and the Names
At five in the afternoon, Eastern time, on 25 July 2010 WikiLeaks published what it called the Afghan War Diary: more than 91,000 reports from January 2004 to December 2009 by its count, less some 15,000 held back for what it called harm minimisation, at its source's demand. The Guardian, the New York Times and Der Spiegel had the files in advance and published the same day. The reports sat in army databases to which, Chelsea Manning told a military court in 2013, an intelligence analyst had unlimited access; Manning, then an analyst at a base east of Baghdad, had copied them to a rewritable disc in early January 2010, carried it out in a uniform pocket and uploaded them on 3 February. Not every informant's name was kept out of the published files. The Times of London found dozens of Afghans named, and on 29 July Admiral Mike Mullen said Julian Assange and his source might already have blood on their hands. At Manning's sentencing in 2013 the general who led the Pentagon's review of the leaks testified to the damage it had assessed, but named no one killed because of the release.
Jackpot on Stage
On 28 July 2010, at Black Hat in Las Vegas, Barnaby Jack of IOActive stood between two cash machines he had bought himself, a Tranax and a Triton, the generic kind found in bars and convenience stores, and made both pay out. The unpatched Tranax he never touched. He connected to it remotely, got past its authentication and installed a homemade rootkit he called Scrooge; the machine played a tune, put the word Jackpot on its screen and spat out notes, while an online tool he called Dillinger tracked compromised machines and stored stolen card data. The older Triton he opened with a key obtained online and loaded with his own firmware through a USB port. Triton's vice-president of engineering, Bob Douglas, attended and said the flaw had been patched in November 2009; Tranax could not be reached. The talk was a year late: in 2009 Juniper Networks, then his employer, had postponed it at the request of the ATM maker concerned, which neither named, until vendors had fixed the flaws. "Every ATM I've looked at, I've found a game-over vulnerability," Jack said. His death is recorded in July 2013.
The Code in Escrow
For months, orders for telecom equipment in India had been waiting on security clearance. In April an executive at a large mobile operator told AFP it had been told it could not buy from UTStarcom; the telecom ministry's spokesman, Satyendra Prakash, said nothing was banned, only that operators needed Home Ministry clearance before placing orders. The worry, as Indian papers reported it, was that Chinese products could carry embedded elements that would let China attack networks or shut equipment down, and orders for Huawei and ZTE gear waited. A 26-page draft reported in June would have made vendors lodge their source code with the government and let operators modify it in an emergency; on 26 July Ericsson was reported to object to the escrow and to unlimited liability.
On 28 July 2010 the Department of Telecommunications, in consultation with the Ministry of Home Affairs, wrote its answer into the operators' licences. Operators were to file a network security policy and needed Home Ministry clearance and third-party audits before importing core equipment. Vendors were to deposit source code and designs, encrypted, in an escrow account agencies could open in an emergency, hand maintenance to Indian engineers within two years, and face penalties of up to a contract's full value if spyware or malware turned up. By late August Huawei and ZTE were reported to have been cleared to supply. The escrow was gone by May 2011. And the month's worm, carried on USB sticks rather than inside anyone's switches, was already in India: ESET's detections to the end of September put the country third, after Iran and Indonesia.
Google buys the keeper of Freebase
On 16 July 2010 Google said it had bought Metaweb Technologies, a San Francisco company whose co-founders included Danny Hillis and John Giannandrea; the price was not disclosed. Metaweb ran Freebase, a collaboratively edited database of what Google counted as more than 12 million things, among them films, books, places and companies, and the links between them. Search could already answer a query for Barack Obama's birthday; Google's Jack Menzel wanted it to handle colleges on the west coast with tuition under $30,000, or actors over 40 who had won an Oscar. Google said it planned to keep Freebase "a free and open database for the world" and to add to it. On 20 July electric vans from the University of Parma's VisLab set off for the Shanghai Expo: a lead van, partly driven by a person, found the way, and one behind followed it unaided. Freebase fed the Knowledge Graph of 2012 and closed in 2016, Google helping move its data to Wikidata; Giannandrea ran Google's search and AI before leaving for Apple in 2018.
IBM buys BigFix, Commtouch buys Command
On 1 July 2010 IBM agreed to buy BigFix, a private company in Emeryville, California, founded in 1997, whose software kept watch over an organisation's laptops, desktops and servers, picked out those breaking its policies and sent them fixes and updates; IBM said it could reach 500,000 machines in minutes. The price was not disclosed; the deal closed on 20 July. On 27 July Commtouch, a Netanya firm that licensed spam and web filtering to other vendors and service providers, agreed to pay $4.6 million in cash, and up to about $8 million in all if revenue targets were met through 2011, for the Command antivirus division of Florida's Authentium, whose technology, it said, went to Google, McAfee and Microsoft. Two days later McAfee agreed to buy tenCube of Singapore, whose WaveSecure let the owner of a lost phone locate, lock, back up or wipe it; that price was not disclosed either. In December 2018 IBM agreed to sell BigFix to India's HCL, one of seven products in a $1.8 billion deal.
⏳ Time capsule — July 2010
- On 11 July Spain beat the Netherlands 1–0 after extra time at Soccer City in Johannesburg to win the World Cup for the first time, Andrés Iniesta scoring in the 116th minute; the fourteen bookings were a record for a final.
- On 15 July the Union Cabinet approved ₹, a sign for the rupee designed by D. Udaya Kumar of IIT Bombay's Industrial Design Centre, joining the Devanagari ra to the Latin R; it was chosen from some 3,300 entries.
- On 16 July Christopher Nolan's Inception, a heist film set inside dreams with Leonardo DiCaprio, opened in American cinemas after a London premiere on 8 July; it went on to win four Academy Awards.
- On 22 July at Galle, with the last ball he bowled in Test cricket, Muttiah Muralitharan had India's Pragyan Ojha caught by Mahela Jayawardene for his 800th Test wicket; Sri Lanka won by ten wickets.
Everything had permission
Each of July's stories turned on something that was allowed. The worm's drivers loaded because Windows trusted a signature, and its shortcuts ran because Windows was built to draw icons; the field reports left because an analyst's job gave access to all of them; Jack's Tranax answered because remote management was a feature. The repairs came piecemeal. Microsoft's shortcut patch, shipped on 2 August, left working attack paths open until March 2015; stolen signing keys became so ordinary that by February 2013 a security vendor's own was signing malware; and Stuxnet's frame was reused for Duqu. Sixteen years on, no government has acknowledged building the worm.
The rest ended on the record. What the Pentagon changed after the war logs, and how the analyst's case closed, are carried in November. What Jack did on a stage, criminals were doing to bank machines by October 2014, when a backdoor loaded from a bootable disc turned up on more than fifty ATMs in eastern Europe. Industrial controls became a target in their own right, and in December 2015 intruders switched off substations in western Ukraine. India's argument over whose equipment may sit inside its networks, first written into licences that July, has not closed. The archive runs on behind this edition, back through June to January 2010.