Simulation Sabotage Malware May Have Preceded Stuxnet
FAST16 breaks a quiet assumption in engineering software: simulation outputs can be tampered with before anyone notices. That means a compromised model can feed false calculations into real-world decisions, and the usual response of checking the endpoint or rebuilding the system may miss the damage already baked into the results.
SentinelOne says the malware alters floating-point outputs and looks for precision tools used in civil engineering, physics, and physical process simulations. The sample was uploaded to VirusTotal in 2016, but the code suggests it may date to around 2005 and only runs on Windows XP-era systems, which is why the researchers think it predates Stuxnet by years.
If that assessment holds, older engineering analyses may contain attacker-induced errors that were never recognized as sabotage. The risk is not just active infection, but legacy calculations that may still shape infrastructure, design, or safety decisions today.
It’s almost certainly state-sponsored, probably US in origin, and was deployed against Iran years before Stuxnet: “…the Fast16 malware was designed to carry out the most subtle form of sabotage ever seen in an in-the-wild malware tool: By automatically spreading across networks and then silently manipulating computation processes in certain software applications that perform high-precision mathematical calculations and simulate physical phenomena, Fast16 can alter the results of those programs to cause failures that range from faulty research results to catastrophic damage to real-world equipment.”...
Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years
Targeting high-precision floating-point arithmetic operations in engineering modeling software, Fast16 may now be the earliest known state-linked cyber-sabotage framework.