The NY Times has a theory
This worm is purported to allow remote control of devices using Siemans controllers, like nuclear power plants, oil pipelines, and other industrial controllers… It is far too sophisticated to have been the work of some 13 year old in his mom’s basement.
(San Bruno pipeline explosion… Hmmm….)
Although China openly expresses interest in cyberwarfare and therefor ranks among the suspects, I doubt the Hoi Poloi ever shall know. My computer is scanned by Chinese servers a dozen times a day, according to Norton Vulnerability Protection. Why are they doing that? But my suspicions lead me to think that if this critter was set loose by a state entity, then we are seeing a mere test run of something much sinister that is still in a corked bottle. Pleasant thought, isn’t it?
Since China and Russia are helping Iran, if Iran is the target of the malware, they’re not likely suspects. One of the reasons a lot of probes come from China is the high number of pirated copies of Windows that don’t get security patches installed. Most of the purpose of attacking residential PCs is building botnets – those groups of 1000s of remotely controlled PCs on fast connections are then used to extort money from banks and bug companies using denial of service attacks.