Simulation Sabotage Malware May Have Preceded Stuxnet

FAST16 breaks a quiet assumption in engineering software: simulation outputs can be tampered with before anyone notices. That means a compromised model can feed false calculations into real-world decisions, and the usual response of checking the endpoint or rebuilding the system may miss the damage already baked into the results. SentinelOne says the malware alters floating-point outputs and looks for precision tools used in civil engineering, physics, and physical process simulations. The sample was uploaded to VirusTotal in 2016, but the code suggests it may date to around 2005 and only runs on Windows XP-era systems, which is why the researchers think it predates Stuxnet by years. If that assessment holds, older engineering analyses may contain attacker-induced errors that were never recognized as sabotage. The risk is not just active infection, but legacy calculations that may still shape infrastructure, design, or safety decisions today.

Part of the PlainSec briefing for 2026-04-25

Every edition of this story: Simulation Sabotage Malware May Have Preceded Stuxnet

Sources