Researchers disclosed FAST16, a previously undocumented sabotage malware framework whose core components were compiled around 2005, placing it years before Stuxnet and marking it as one of the earliest known cyber tools built to corrupt high-precision computational workloads. SentinelOne said the framework used a Lua-based carrier, svcmgmt.exe, alongside the boot-start driver fast16.sys to spread across Windows 2000/XP networks, evade monitored environments, and patch targeted applications in memory so they produced subtly altered floating-point results instead of overt failures. References in Shadow Brokers material linked the malware name to leaked deconfliction data, but researchers stopped short of definitive attribution while assessing the tooling as state-grade and likely tied to a covert sabotage campaign.
Analysis of the malware’s rule-based patch engine indicates it targeted specialized software including LS-DYNA 970, PKPM, and MOHID, with Symantec concluding the strongest evidence points to tampering with LS-DYNA and AUTODYN simulations involving high explosives and possible nuclear detonation modeling. The hooks reportedly altered outputs only under narrow conditions, such as uranium-like densities and specific explosive equation-of-state models, suggesting an effort to quietly degrade the fidelity of weapons, engineering, hydrodynamics, and civil-structure simulations rather than trigger immediate disruption. Researchers said the framework’s worm-like lateral movement, credential impersonation, persistence, and long-term maintenance across multiple software builds indicate a sustained operation intended to spread consistent calculation corruption through an entire facility and potentially delay or derail sensitive scientific and engineering programs.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Symantec's Threat Hunter Team published additional analysis concluding FAST16 was designed to tamper with LS-DYNA and AUTODYN simulations involving high explosives, with indicators pointing to nuclear detonation modeling. The company said the malware selectively altered outputs under narrow conditions and appeared maintained across multiple software builds over time.
SentinelLABS released a detailed report describing FAST16's Lua-powered carrier, boot-start driver, worm-like propagation, rule-based patching engine, and likely target classes in engineering and physics modeling. The publication also included defensive guidance such as YARA rules and noted that affected software vendors had been notified.
At Black Hat Asia, SentinelOne researcher Vitaly Kamluk presented FAST16 as a previously undocumented sabotage malware framework that appears to predate Stuxnet. He said the malware was designed to tamper with floating-point calculations in specialized software such as LS-DYNA 970, PKPM, and MOHID.
Materials leaked by the Shadow Brokers in 2017 contained references to the name "fast16," including deconfliction-related material and a PDB path that researchers later used to connect the malware to the leaked corpus. These references helped establish historical linkage but did not provide definitive attribution.
Researchers traced their investigation to a FAST16-related malware sample uploaded to VirusTotal in 2016. That sample became a key starting point for later reverse engineering and identification of the framework.
Researchers assessed FAST16 was an operational, state-grade sabotage platform designed to spread within local Windows networks and silently alter outputs from specialized engineering and scientific software. Multiple reports say it was likely used against Iranian or Iran-linked high-precision modeling environments years before Stuxnet, though attribution remains unconfirmed.
SentinelOne assessed that core FAST16 components date to around 2005 based on compilation artifacts and platform assumptions. The framework was built for Windows 2000/XP-era environments and appears to predate Stuxnet by roughly five years.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
19 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceen.wikipedia.org
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcetheregister.com
Open sourcego.theregister.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.