Malware · 138 days ago
FAST16 breaks a quiet assumption in engineering software: simulation outputs can be tampered with before anyone notices. That means a compromised model can feed false calculations into real-world decisions, and the usual response of checking the endpoint or rebuilding the system may miss the damage already baked into the results.
SentinelOne says the malware alters floating-point outputs and looks for precision tools used in civil engineering, physics, and physical process simulations. The sample was uploaded to VirusTotal in 2016, but the code suggests it may date to around 2005 and only runs on Windows XP-era systems, which is why the researchers think it predates Stuxnet by years.
If that assessment holds, older engineering analyses may contain attacker-induced errors that were never recognized as sabotage. The risk is not just active infection, but legacy calculations that may still shape infrastructure, design, or safety decisions today.
7 sources covering this story
Fast16 Malware - Schneier on Security
It’s almost certainly state-sponsored, probably US in origin, and was deployed against Iran years before Stuxnet: “…the Fast16 malware was designed to carry out the most subtle form of sabotage ever seen in an in-the-wild malware tool: By automatically spreading across networks and then silently manipulating computation processes in certain software applications that perform high-precision mathematical calculations and simulate physical phenomena, Fast16 can alter the results of those programs to cause failures that range from faulty research results to catastrophic damage to real-world equipment.”...
Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years
Targeting high-precision floating-point arithmetic operations in engineering modeling software, Fast16 may now be the earliest known state-linked cyber-sabotage framework.
20-Year-Old Malware Rewrites History of Cyber Sabotage
Researchers have uncovered a malware framework dubbed "fast16" that predates Stuxnet by five years.
Researchers Identify Fast16 Sabotage Malware That Pre-Dates Stuxnet
The “fast16” malware may have been used to target Iran’s nuclear program prior to Stuxnet
Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
Fast16 malware from 2005 predates Stuxnet by five years, targeting engineering software to sabotage calculations and reshape cyberwar history.
Pre-Stuxnet Sabotage Malware ‘Fast16’ Linked to US-Iran Cyber Tensions
It targeted high-precision calculation software to tamper with results and packed a self-propagation mechanism.
Researchers find sabotage malware that may predate Stuxnet
Black Hat Asia: FAST16 could be the first cyberweapon, and its effects could be with us today
Researchers find sabotage malware that may predate Stuxnet
Black Hat Asia: FAST16 could be the first cyberweapon, and its effects could be with us today
Part of the PlainSec briefing for 2026-04-27