Researchers uncover Fast16 sabotage malware predating Stuxnet

SentinelOne researchers identified Fast16, a malware operation dating to around 2005, that includes a service binary (svcmgmt.exe) with an embedded Lua 5.0 VM and a kernel driver (fast16.sys) that intercepts and patches executables via the storage stack. SentinelOne says Fast16 predates Stuxnet by at least five years, represents the first recorded Lua-based network worm with mission-specific sabotage functionality, and targeted Iran’s nuclear program.

Part of the PlainSec briefing for 2026-04-27

Sources