Blog
Fast16: The Malware that Could Topple a Building
SentinelOne researchers uncovered Fast16, malware that silently corrupted engineering and simulation software for over two decades—predating Stuxnet and capable of turning faulty calculations into real-world catastrophe.
Software has become critical to every branch of science as the complexity of our world exceeds our ability to do math in our heads. Whether you’re an engineer building a skyscraper or a rocket scientist trying to safely launch an astronaut into space, the right software can help us build highly accurate models and physics simulations that take into account every variable, something we would struggle to do with just our brains, paper, and a can-do attitude. This is the reason that discoveries like the one researchers at SentinelOne recently made about the Fast16 malware can be so disturbing, because this malware has been silently corrupting the accuracy of software like this for over two decades.
A Cryptic History
Researchers actually first became wise to Fast16’s existence all the way back in 2017, when a team of cybercriminals called Shadow Brokers leaked a sizable collection of software they had stolen from the US National Security Agency (NSA). Among the troves of files now available to the public, researchers found a passing reference to a software called “fast16” paired with the cryptic label “*** NOTHING TO SEE HERE - CARRY ON ***.” Unfortunately, the actual code for this tool was nowhere to be found among the leaked software, so researchers couldn’t solve the mystery of what Fast16 actually did.
But two years later, researcher Juan Andrés Guerrero-Saade from SentinelOne discovered the code for Fast16 on VirusTotal, a Google-owned repository of malware code, while he was looking for malware samples that contained a specific engine for running the Lua programming language. By happenstance, Guerro-Saade found a sample from way back in 2005 called “svcmgmt.exe” that contained a kernel driver called “fast.sys.” The code for the mysterious Fast16 malware had been found, and the kernel driver convinced researchers that it was rootkit used by the US for stealthy spying.
It would be years before the truth came out.
The Discovery
Earlier this year, 2026, Guerrero-Saade’s colleague Vitaly Kamluk started to reverse engineer the Fast16 malware as part of an experiment comparing his own skill in doing to those of different AI tools. Eventually, while the AI tools incorrectly identified Fast16 as a rootkit, Kamluk made the startling discovery that the malware was actually closer in function to the infamous Stuxnet malware.
Stuxnet was a malicious computer worm that was used by the United States in 2010 to sabotage the Iranian nuclear program. The malware physically damaged almost 1000 Iranian uranium-enriching centrifuges by manipulating their speeds to create enough stress to damage them, causing the media to sensationalize the malware as the “world’s first digital weapon.” Fast16, however, predates Stuxnet by about five years.
According to Kamluk and Guerrero-Saade, “fast16.sys selectively targets high-precision calculation software, patching code in memory to tamper with results,” meaning the malware is capable of tampering with research and engineering software to give scientists faulty results. The researchers found evidence for three types of physical simulation software Fast16 might have been designed to tamper with:
- Modelo Hidrodinamico, a Portuguese software used for modeling water systems
- PKPM, a Chinese construction engineering software
- LS-DYNA, a physical simulation software created by scientists who had worked at US Lawrence Livermore National Laboratory
Like we saw with Stuxnet, Fast16’s sabotage on the digital level could translate to real-world damage. As the researchers put it:
“By introducing small but systematic errors into physical-world calculations, the framework could undermine or slow scientific research programs, degrade engineered systems over time or even contribute to catastrophic damage.”
LS-DYNA in particular has been used by Iranian scientists to develop nuclear weapons, which has caused the two researchers to hypothesize that the US or one of their allies made Fast16 to interfere with Iran’s nuclear program years before Stuxnet. It’s also possible that the US used Fast16 against North Korea’s nuclear program, as they experienced a lot of unexplained failures around the time Fast16 was active.
To prevent its own discovery via double-checking the work of an infected machine on another device, Fast16 also had a “wormlet” functionality that allowed it to copy itself onto other computers in a network using Windows’ network share feature. This way, all computers could potentially become infected and give the same faulty results, ensuring sabotage and keeping the malware a secret.
Conclusion
It’s rather terrifying to think that for 21 years a malware has existed undetected with the potential to turn your computers from valuable scientific tools into machines aimed at ensuring your progression is doomed from the start. However, if you’re worried that this malware might have turned your calculation software against you, the very fact that it went undetected for so long should put your mind at ease. The farther a worm like Fast16 spreads, the easier it is to be found, so to remain under the radar for over 20 years, Fast16 was likely only ever used on a small number of targets. Unless you were a scientist for a US enemy sometime in the last two decades, it’s doubtful you’ve ever even seen a computer with Fast16 installed.
But Fast16 shows us that the right malware could literally topple buildings, making it all the more important for you to invest in your company’s cybersecurity. If you’re worried about your vulnerability to any kind of malware, Crimson Vista offers auditing and consultation services like Cyber-Bridge to help you strengthen your cybersecurity posture. In the meantime, it never hurts to triple-check your important calculations.
Sources
- https://www.wired.com/story/fast16-malware-stuxnet-precursor-iran-nuclear-attack/
- https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/
- https://thehackernews.com/2026/04/researchers-uncover-pre-stuxnet-fast16.html
- https://www.malwarebytes.com/stuxnet
Continue
Keep reading.
Psychology-Aware Security Design
Cybersecurity products need affordances that guide people toward the right actions under stress. Psychology-aware design is how defenders catch up with attackers who already use it.
AI: The New Face of Cybersecurity
OpenAI and Anthropic AI agents are escaping sandboxes and exploiting vulnerabilities at machine speed. Learn what the Hugging Face breach reveals about AI's growing role in offensive and defensive cybersecurity.
The Limitations of Hashing for Data Anonymization
Why using hashing alone is an incomplete anonymization process